Nixpkgs security tracker

Try the new UI
Login with GitHub

Published issues

All published security issues are tracked and resolved on GitHub.

NIXPKGS-2026-0881
published 5 months, 2 weeks ago
Permalink CVE-2026-32883
5.9 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): High (H)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): None (N)
updated 5 months, 2 weeks ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt ignored
    9 packages
    • botan2
    • botanEsdm
    • emiluaPlugins.botan
    • python312Packages.botan3
    • python313Packages.botan3
    • python314Packages.botan3
    • haskellPackages.botan-low
    • haskellPackages.botan-bindings
    • chickenPackages_5.chickenEggs.botan
  • @mweinelt accepted
  • @mweinelt published on GitHub

Botan: Missing OCSP Response Signature Verification Allows MitM Certificate Revocation Bypass


botan
  • ==>= 3.0.0, < 3.11.0
https://github.com/randombit/botan/security/advisories/GHSA-9j2j-hqmc-hf5x
NIXPKGS-2026-0879
published 5 months, 2 weeks ago
Permalink CVE-2026-32877
8.2 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): None (N)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): High (H)
updated 5 months, 2 weeks ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt ignored
    9 packages
    • botan2
    • botanEsdm
    • emiluaPlugins.botan
    • python312Packages.botan3
    • python313Packages.botan3
    • chickenPackages_5.chickenEggs.botan
    • haskellPackages.botan-bindings
    • haskellPackages.botan-low
    • python314Packages.botan3
  • @mweinelt accepted
  • @mweinelt published on GitHub

Botan: Heap Buffer Over-read in SM2 Decryption via Undersized C3 Hash Field


botan
  • ==>= 2.3.0, < 3.11.0
https://github.com/randombit/botan/security/advisories/GHSA-7jj6-4r42-w9h6
NIXPKGS-2026-0877
published 5 months, 2 weeks ago
Permalink CVE-2026-32884
5.9 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): High (H)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): None (N)
updated 5 months, 2 weeks ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt ignored
    9 packages
    • botan2
    • botanEsdm
    • emiluaPlugins.botan
    • python312Packages.botan3
    • python313Packages.botan3
    • python314Packages.botan3
    • haskellPackages.botan-low
    • haskellPackages.botan-bindings
    • chickenPackages_5.chickenEggs.botan
  • @mweinelt accepted
  • @mweinelt published on GitHub

Botan: Case-Insensitive CN Values Bypass DNS excludedSubtrees Name Constraints (RFC 5280 Violation)


botan
  • ==< 3.11.0
https://github.com/randombit/botan/security/advisories/GHSA-7c3g-7763-ggj5
NIXPKGS-2026-0875
published 5 months, 2 weeks ago
Permalink CVE-2026-33721
5.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): Low (L)
updated 5 months, 2 weeks ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt ignored package mapserver
  • @mweinelt accepted
  • @mweinelt published on GitHub

MapServer has heap buffer overflow in SLD `Categorize` Threshold parsing


MapServer
  • ==>= 4.2, < 8.6.1
https://github.com/MapServer/MapServer/security/advisories/GHSA-cv4m-mr84-fgjp
NIXPKGS-2026-0873
published 5 months, 2 weeks ago
Permalink CVE-2026-5124
3.7 LOW
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Exploit Code Maturity (E): Not Defined (X)
  • Remediation Level (RL): Official Fix (O)
  • Report Confidence (RC): Confirmed (C)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
updated 5 months, 2 weeks ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt accepted
  • @mweinelt published on GitHub

osrg GoBGP BGP Header bgp.go BGPHeader.DecodeFromBytes access control


GoBGP
  • ==4.0
  • ==4.1
  • ==4.3.0
  • ==4.2
https://github.com/osrg/gobgp/commit/f0f24a2a901cbf159260698211ab15c583ced131
https://github.com/osrg/gobgp/pull/3340
NIXPKGS-2026-0871
published 5 months, 2 weeks ago
updated 5 months, 2 weeks ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt ignored
    5 packages
    • python312Packages.pytautulli
    • python313Packages.pytautulli
    • python314Packages.pytautulli
    • home-assistant-component-tests.tautulli
    • tests.home-assistant-component-tests.tautulli
  • @mweinelt accepted
  • @mweinelt published on GitHub

Tautulli: Unsanitized JSONP callback parameter allows cross-origin script injection and API key theft


Tautulli
  • ==>= 1.3.10, < 2.17.0
https://github.com/Tautulli/Tautulli/security/advisories/GHSA-95mg-wpqw-9qxh
NIXPKGS-2026-0869
published 5 months, 2 weeks ago
Permalink CVE-2026-5165
6.7 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 5 months, 2 weeks ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt accepted
  • @mweinelt published on GitHub

Virtio-win: virtio-win: memory corruption via use-after-free in virtio blk device reset


virtio-win
https://github.com/virtio-win/kvm-guest-drivers-windows/pull/1493
NIXPKGS-2026-0867
published 5 months, 2 weeks ago
updated 5 months, 2 weeks ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt ignored
    5 packages
    • pkgsRocm.crewai
    • python312Packages.crewai
    • python313Packages.crewai
    • python314Packages.crewai
    • pkgsRocm.python3Packages.crewai
  • @mweinelt accepted
  • @mweinelt published on GitHub

CVE-2026-2286


CrewAI
  • ==1.0
https://www.kb.cert.org/vuls/id/221883
NIXPKGS-2026-0861
published 5 months, 2 weeks ago
updated 5 months, 2 weeks ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt ignored
    5 packages
    • pkgsRocm.python3Packages.crewai
    • python314Packages.crewai
    • python313Packages.crewai
    • python312Packages.crewai
    • pkgsRocm.crewai
  • @mweinelt accepted
  • @mweinelt published on GitHub

CVE-2026-2275


CrewAI
  • ==1.0
https://www.kb.cert.org/vuls/id/221883
NIXPKGS-2026-0863
published 5 months, 2 weeks ago
Permalink CVE-2025-49010
3.8 LOW
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Physical (P)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Physical (P)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): Low (L)
updated 5 months, 2 weeks ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt ignored
    12 packages
    • python313Packages.tree-sitter-grammars.tree-sitter-openscad
    • python314Packages.tree-sitter-grammars.tree-sitter-openscad
    • openscad
    • openscap
    • openscreen
    • openscad-lsp
    • openscenegraph
    • openscad-unstable
    • opensc
    • tree-sitter-grammars.tree-sitter-openscad
    • vscode-extensions.antyos.openscad
    • kakounePlugins.openscad-kak
  • @mweinelt restored package opensc
  • @mweinelt accepted
  • @mweinelt published on GitHub

OpenSC: Stack-buffer-overflow WRITE in GET RESPONSE


OpenSC
  • ==< 0.27.0
https://github.com/OpenSC/OpenSC/security/advisories/GHSA-q5cf-5wmx-9wh4