Nixpkgs security tracker

Login with GitHub

Published issues

All published security issues are tracked and resolved on GitHub.

NIXPKGS-2026-1049
published 5 months ago
Permalink CVE-2026-5412
9.9 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 5 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    2 packages
    • jujutsu
    • jujuutils
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

Juju CloudSpec API could leak senstive information


juju
  • <2.9.57
  • <3.6.21
NIXPKGS-2026-1048
published 5 months ago
updated 5 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

Net::CIDR::Lite versions before 0.23 for Perl mishandles IPv4 mapped IPv6 addresses, which may allow IP ACL bypass


Net-CIDR-Lite
  • <0.23
NIXPKGS-2026-1047
published 5 months ago
Permalink CVE-2026-35594
6.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
updated 5 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

Vikunja Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade


vikunja
  • ==< 2.3.0
NIXPKGS-2026-1046
published 5 months ago
Permalink CVE-2026-35601
4.1 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): Required (R)
  • Scope (S): Changed (C)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
updated 5 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored package vikunja-desktop
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

Vikunja has an iCalendar Property Injection via CRLF in CalDAV Task Output


vikunja
  • ==< 2.3.0
NIXPKGS-2026-1045
published 5 months ago
Permalink CVE-2026-35599
6.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): High (H)
updated 5 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored package vikunja-desktop
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

Vikunja has an Algorithmic Complexity DoS in Repeating Task Handler


vikunja
  • ==< 2.3.0
NIXPKGS-2026-1044
published 5 months ago
Permalink CVE-2026-40071
5.4 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): Low (L)
updated 5 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    5 packages
    • tests.home-assistant-component-tests.pyload
    • home-assistant-component-tests.pyload
    • python314Packages.pyloadapi
    • python313Packages.pyloadapi
    • python312Packages.pyloadapi
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

pyLoad WebUI JSON permission mismatch lets ADD/DELETE users invoke MODIFY-only actions


pyload
  • ==< 0.5.0b3.dev97
NIXPKGS-2026-1043
published 5 months ago
updated 5 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    3 packages
    • tests.testers.lycheeLinkCheck.ok
    • tests.testers.lycheeLinkCheck.network
    • lychee
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

Lychee has Broken Access Control in SharingController::listAll() leaks private album sharing metadata to unauthorized users


Lychee
  • ==< 7.5.4
NIXPKGS-2026-1042
published 5 months ago
updated 5 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

PKCS7 CBC Padding Oracle — Plaintext Recovery


wolfSSL
  • =<5.9.0
NIXPKGS-2026-1041
published 5 months ago
Permalink CVE-2026-40225
6.4 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Physical (P)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Physical (P)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 5 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    2 packages
    • udev
    • rofi-systemd
  • @LeSuisse restored package udev
  • @LeSuisse ignored
    43 packages
    • tests.pkg-config.defaultPkgConfigPackages.libsystemd
    • tests.pkg-config.defaultPkgConfigPackages.libudev
    • vscode-extensions.coolbear.systemd-unit-file
    • gnomeExtensions.systemd-offline-update-indicator
    • python313Packages.jupyterhub-systemdspawner
    • python313Packages.systemdunitparser
    • systemd-lsp
    • haskellPackages.libsystemd-journal
    • python312Packages.systemdunitparser
    • python313Packages.systemd-python
    • python314Packages.jupyterhub-systemdspawner
    • ocamlPackages_latest.systemd
    • update-systemd-resolved
    • python312Packages.jupyterhub-systemdspawner
    • gnomeExtensions.systemd-status
    • python314Packages.systemdunitparser
    • python314Packages.systemd-python
    • python312Packages.systemd-python
    • ocamlPackages.systemd
    • php84Extensions.systemd
    • php85Extensions.systemd
    • php82Extensions.systemd
    • gnomeExtensions.systemd-manager
    • prometheus-systemd-exporter
    • systemd
    • systemdgenie
    • systemdLibs
    • haskellPackages.warp-systemd
    • systemd-credsubst
    • systemd-journal2gelf
    • systemd-lock-handler
    • phpExtensions.systemd
    • haskellPackages.systemd
    • systemd-manager-tui
    • php83Extensions.systemd
    • systemd-bootchart
    • systemdMinimal
    • systemd-netlogd
    • systemd-wait
    • systemd-language-server
    • haskellPackages.systemd-api
    • nagiosPlugins.check_systemd
    • systemdUkify
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

In udev in systemd before 260, local root execution can …


systemd
  • <260
NIXPKGS-2026-1040
published 5 months, 1 week ago
updated 5 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    5 packages
    • python312Packages.glances-api
    • python313Packages.glances-api
    • python314Packages.glances-api
    • home-assistant-component-tests.glances
    • tests.home-assistant-component-tests.glances
  • @LeSuisse accepted
  • @LeSuisse added maintainer @MiniHarinn maintainer.add
  • @LeSuisse published on GitHub

Glances exposes the REST API without authentication


glances
  • ==< 4.5.2