Nixpkgs security tracker

Try the new UI
Login with GitHub

Published issues

All published security issues are tracked and resolved on GitHub.

NIXPKGS-2026-0839
published 5 months, 2 weeks ago
Permalink CVE-2026-4948
5.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): High (H)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): None (N)
updated 5 months, 2 weeks ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt ignored package firewalld-gui
  • @mweinelt accepted
  • @mweinelt published on GitHub

Firewalld: firewalld: local unprivileged user can modify firewall state due to d-bus setter mis-authorization


rhcos
firewalld
https://access.redhat.com/security/cve/CVE-2026-4948
NIXPKGS-2026-0841
published 5 months, 2 weeks ago
Permalink CVE-2026-27877
6.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
updated 5 months, 2 weeks ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt ignored
    37 packages
    • python312Packages.grafanalib
    • terraform-providers.grafana
    • python313Packages.grafanalib
    • python314Packages.grafanalib
    • haskellPackages.amazonka-grafana
    • grafanaPlugins.grafana-oncall-app
    • grafanaPlugins.grafana-clock-panel
    • terraform-providers.grafana_grafana
    • grafanaPlugins.grafana-pyroscope-app
    • python312Packages.mypy-boto3-grafana
    • python313Packages.mypy-boto3-grafana
    • python314Packages.mypy-boto3-grafana
    • grafanaPlugins.grafana-piechart-panel
    • grafanaPlugins.grafana-polystat-panel
    • grafanaPlugins.grafana-worldmap-panel
    • grafanaPlugins.grafana-lokiexplore-app
    • grafanaPlugins.grafana-mqtt-datasource
    • grafanaPlugins.grafana-exploretraces-app
    • grafanaPlugins.grafana-github-datasource
    • grafanaPlugins.grafana-sentry-datasource
    • grafanaPlugins.grafana-discourse-datasource
    • grafanaPlugins.grafana-metricsdrilldown-app
    • python312Packages.types-aiobotocore-grafana
    • python313Packages.types-aiobotocore-grafana
    • grafanaPlugins.grafana-clickhouse-datasource
    • grafanaPlugins.grafana-opensearch-datasource
    • grafanaPlugins.grafana-googlesheets-datasource
    • grafanactl
    • mcp-grafana
    • grafana-loki
    • grafana-alloy
    • grafana-kiosk
    • garmin-grafana
    • grafana-to-ntfy
    • grafana-dash-n-grab
    • grafana-image-renderer
    • dhallPackages.dhall-grafana
  • @mweinelt accepted
  • @mweinelt published on GitHub

Public dashboards discloses all direct mode datasources


Grafana
  • <v12.4.2
  • <v11.6.14
  • <v12.1.10
  • <v12.3.6
  • <v12.2.8
https://grafana.com/security/security-advisories/cve-2026-27877
NIXPKGS-2026-0843
published 5 months, 2 weeks ago
updated 5 months, 2 weeks ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt accepted
  • @mweinelt published on GitHub

OpenBao has Reflected XSS in its OIDC authentication error message


openbao
  • ==< 2.5.2
https://github.com/openbao/openbao/security/advisories/GHSA-cpj3-3r2f-xj59
NIXPKGS-2026-0845
published 5 months, 2 weeks ago
Permalink CVE-2026-31951
6.8 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): Required (R)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
updated 5 months, 2 weeks ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt accepted
  • @mweinelt published on GitHub

LibreChat's MCP Server Header Injection Enables OAuth Token Theft


LibreChat
  • ==>= v0.8.2-rc1, <= v0.8.3-rc1
https://github.com/danny-avila/LibreChat/security/advisories/GHSA-pmw7-gqwj-f954
NIXPKGS-2026-0847
published 5 months, 2 weeks ago
Permalink CVE-2026-31945
7.7 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
updated 5 months, 2 weeks ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt accepted
  • @mweinelt published on GitHub

LibreChat Server-Side Request Forgery using DNS resolution


LibreChat
  • ==>= 0.8.2-rc2, < 0.8.3-rc1
https://github.com/danny-avila/LibreChat/security/advisories/GHSA-f92m-jpv7-55p2
NIXPKGS-2026-0849
published 5 months, 2 weeks ago
Permalink CVE-2026-33725
7.2 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 5 months, 2 weeks ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt accepted
  • @mweinelt published on GitHub

Metabase vulnerable to RCE and Arbitrary File Read via H2 JDBC INIT Injection in EE Serialization Import


metabase
  • ==>= 1.56.0, < 1.56.22
  • ==< 1.54.22
  • ==>= 1.57.0, < 1.57.16
  • ==>= 1.55.0, < 1.55.22
  • ==>= 1.58.0, < 1.58.10
  • ==>= 1.59.0, < 1.59.4
https://github.com/metabase/metabase/security/advisories/GHSA-fppj-vcm3-w229
likely only enterprise version only, please check
NIXPKGS-2026-0851
published 5 months, 2 weeks ago
Permalink CVE-2026-33757
9.6 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): Low (L)
updated 5 months, 2 weeks ago by @mweinelt Activity log
  • Created suggestion
  • @LeSuisse deleted
    2 maintainers
    • @emilylange
    • @brianmay
    maintainer.delete
  • @mweinelt added
    2 maintainers
    • @emilylange
    • @brianmay
    maintainer.add
  • @mweinelt accepted
  • @mweinelt published on GitHub

OpenBao lacks user confirmation for OIDC direct callback mode


openbao
  • ==< 2.5.2
https://github.com/openbao/openbao/security/advisories/GHSA-7q7g-x6vg-xpc3
NIXPKGS-2026-0853
published 5 months, 2 weeks ago
Permalink CVE-2026-5164
6.7 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 5 months, 2 weeks ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt accepted
  • @mweinelt published on GitHub

Virtio-win: virtio-win: denial of service via unvalidated descriptor count in unmap request


virtio-win
https://github.com/virtio-win/kvm-guest-drivers-windows/pull/1504
NIXPKGS-2026-0855
published 5 months, 2 weeks ago
Permalink CVE-2026-31799
4.9 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
updated 5 months, 2 weeks ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt ignored
    5 packages
    • python312Packages.pytautulli
    • python313Packages.pytautulli
    • python314Packages.pytautulli
    • home-assistant-component-tests.tautulli
    • tests.home-assistant-component-tests.tautulli
  • @mweinelt accepted
  • @mweinelt published on GitHub

Tautulli: SQL Injection in get_home_stats API endpoint via unsanitised filter parameters


Tautulli
  • ==>= 2.1.0-beta, < 2.17.0
https://github.com/Tautulli/Tautulli/security/advisories/GHSA-g47q-8j8w-m63q
NIXPKGS-2026-0857
published 5 months, 2 weeks ago
updated 5 months, 2 weeks ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt ignored
    5 packages
    • tests.home-assistant-component-tests.tautulli
    • python312Packages.pytautulli
    • python313Packages.pytautulli
    • python314Packages.pytautulli
    • home-assistant-component-tests.tautulli
  • @mweinelt accepted
  • @mweinelt published on GitHub

Tautulli: Unauthenticated Path Traversal in `/newsletter/image/images` endpoint


Tautulli
  • ==< 2.17.0
https://github.com/Tautulli/Tautulli/security/advisories/GHSA-xp55-2pf4-fv8m