Nixpkgs security tracker

Try the new UI
Login with GitHub

Published issues

All published security issues are tracked and resolved on GitHub.

NIXPKGS-2026-0891
published 5 months, 2 weeks ago
updated 5 months, 2 weeks ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt accepted
  • @mweinelt published on GitHub

Incomplete privilege drop for com.system76.CosmicGreeter.GetUserData


cosmic-greeter
  • <https://github.com/pop-os/cosmic-greeter/pull/426
https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-25704
NIXPKGS-2026-0890
published 5 months, 2 weeks ago
Permalink CVE-2026-5107
4.2 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): Low (L)
  • Exploit Code Maturity (E): Not Defined (X)
  • Remediation Level (RL): Official Fix (O)
  • Report Confidence (RC): Confirmed (C)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): Low (L)
updated 5 months, 2 weeks ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt ignored
    2 packages
    • prometheus-frr-exporter
    • tests.prefer-remote-fetch.fetchgit
  • @mweinelt accepted
  • @mweinelt published on GitHub

FRRouting FRR EVPN Type-2 Route bgp_evpn.c process_type2_route access control


FRR
  • ==10.5.1
  • ==10.5.0
https://github.com/FRRouting/frr/commit/7676cad65114aa23adde583d91d9d29e2debd045
NIXPKGS-2026-0889
published 5 months, 2 weeks ago
updated 5 months, 2 weeks ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt ignored
    3 packages
    • python312Packages.gotenberg-client
    • python313Packages.gotenberg-client
    • python314Packages.gotenberg-client
  • @mweinelt accepted
  • @mweinelt published on GitHub

Gotenberg: Chromium deny-list bypass via case-insensitive URL scheme


gotenberg
  • ==< 8.29.0
https://github.com/gotenberg/gotenberg/security/advisories/GHSA-jjwv-57xh-xr6r
NIXPKGS-2026-0888
published 5 months, 2 weeks ago
updated 5 months, 2 weeks ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt ignored
    28 packages
    • libarchive-qt
    • haskellPackages.libarchive
    • kodiPackages.vfs-libarchive
    • perlPackages.ArchiveLibarchive
    • python312Packages.libarchive-c
    • python313Packages.libarchive-c
    • python314Packages.libarchive-c
    • haskellPackages.libarchive-clib
    • perl5Packages.ArchiveLibarchive
    • perl538Packages.ArchiveLibarchive
    • perl540Packages.ArchiveLibarchive
    • haskellPackages.archive-libarchive
    • haskellPackages.libarchive-conduit
    • perlPackages.ArchiveLibarchivePeek
    • perlPackages.TestArchiveLibarchive
    • perl5Packages.ArchiveLibarchivePeek
    • perl5Packages.TestArchiveLibarchive
    • perl538Packages.ArchiveLibarchivePeek
    • perl538Packages.TestArchiveLibarchive
    • perl540Packages.ArchiveLibarchivePeek
    • perl540Packages.TestArchiveLibarchive
    • perlPackages.ArchiveLibarchiveExtract
    • perl5Packages.ArchiveLibarchiveExtract
    • perl538Packages.ArchiveLibarchiveExtract
    • perl540Packages.ArchiveLibarchiveExtract
    • python312Packages.extractcode-libarchive
    • python313Packages.extractcode-libarchive
    • python314Packages.extractcode-libarchive
  • @mweinelt accepted
  • @mweinelt published on GitHub

Libarchive: libarchive: arbitrary code execution via integer overflow in iso9660 image processing


rhcos
libarchive
https://github.com/libarchive/libarchive/pull/2934
NIXPKGS-2026-0887
published 5 months, 2 weeks ago
updated 5 months, 2 weeks ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt ignored package kyverno-chainsaw
  • @mweinelt accepted
  • @mweinelt published on GitHub

CVE-2026-4789


Kyverno
  • ==1.16.0
https://github.com/kyverno/kyverno/pull/15729
NIXPKGS-2026-0886
published 5 months, 2 weeks ago
updated 5 months, 2 weeks ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt accepted
  • @mweinelt published on GitHub

FreeRDP: DoS via WINPR_ASSERT in rts_read_auth_verifier_no_checks


FreeRDP
  • ==< 3.24.2
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-4v4p-9v5x-hc93
NIXPKGS-2026-0885
published 5 months, 2 weeks ago
Permalink CVE-2026-33984
7.5 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 5 months, 2 weeks ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt accepted
  • @mweinelt published on GitHub

FreeRDP: ClearCodec resize_vbar_entry() Heap OOB Write


FreeRDP
  • ==< 3.24.2
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-8469-2xcx-frf6
NIXPKGS-2026-0884
published 5 months, 2 weeks ago
updated 5 months, 2 weeks ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt ignored
    5 packages
    • python312Packages.pytautulli
    • python313Packages.pytautulli
    • python314Packages.pytautulli
    • home-assistant-component-tests.tautulli
    • tests.home-assistant-component-tests.tautulli
  • @mweinelt accepted
  • @mweinelt published on GitHub

Tautulli: RCE via eval() sandbox bypass using lambda nested scope to escape co_names whitelist check


Tautulli
  • ==< 2.17.0
https://github.com/Tautulli/Tautulli/security/advisories/GHSA-m62j-gwm9-7p8m
NIXPKGS-2026-0880
published 5 months, 2 weeks ago
Permalink CVE-2026-31804
4.0 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): Low (L)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
updated 5 months, 2 weeks ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt ignored
    5 packages
    • python312Packages.pytautulli
    • python313Packages.pytautulli
    • python314Packages.pytautulli
    • home-assistant-component-tests.tautulli
    • tests.home-assistant-component-tests.tautulli
  • @mweinelt accepted
  • @mweinelt published on GitHub

Tautulli: Unauthenticated pms_image_proxy endpoint proxies arbitrary HTTP requests through the Plex Media Server


Tautulli
  • ==< 2.17.0
https://github.com/Tautulli/Tautulli/security/advisories/GHSA-qj2f-4c4p-wv97
NIXPKGS-2026-0878
published 5 months, 2 weeks ago
Permalink CVE-2026-33982
7.1 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): High (H)
updated 5 months, 2 weeks ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt accepted
  • @mweinelt published on GitHub

FreeRDP: Persistent Cache Allocator Mismatch - Heap OOB Read


FreeRDP
  • ==< 3.24.2
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-8jm9-2925-g4v2