Nixpkgs security tracker

Try the new UI
Login with GitHub

Published issues

All published security issues are tracked and resolved on GitHub.

NIXPKGS-2026-0750
published 5 months, 3 weeks ago
updated 5 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    3 packages
    • n8n-nodes-carbonejs
    • n8n-nodes-evolution-api
    • n8n-task-runner-launcher
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

n8n Has Authorization Bypass in OAuth Callback via N8N_SKIP_AUTH_ON_OAUTH_CALLBACK


n8n
  • ==< 2.8.0
Upstream advisory: https://github.com/n8n-io/n8n/security/advisories/GHSA-vpgc-2f6g-7w7x
NIXPKGS-2026-0749
published 5 months, 3 weeks ago
updated 5 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    3 packages
    • n8n-nodes-carbonejs
    • n8n-nodes-evolution-api
    • n8n-task-runner-launcher
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

n8n Vulnerable to LDAP Filter Injection in LDAP Node


n8n
  • === 2.14.0
  • ==>= 2.0.0-rc.0, < 2.13.3
  • ==< 1.123.27
Upstream advisory: https://github.com/n8n-io/n8n/security/advisories/GHSA-w83q-mcmx-mh42
NIXPKGS-2026-0748
published 5 months, 3 weeks ago
updated 5 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

Domoticz < 2026.1 Stored XSS via Hardware Configuration Endpoint


Domoticz
  • <2026.1
3rd party "advisory": https://www.vulncheck.com/advisories/domoticz-stored-xss-via-hardware-configuration-endpoint
Apparently mentioned in upstream release notes https://www.domoticz.com/2026.1/ as "Better XSS prevention"
NIXPKGS-2026-0770
published 5 months, 3 weeks ago
Permalink CVE-2026-33248
4.2 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
updated 5 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

NATS has mTLS verify_and_map authentication bypass via incorrect Subject DN matching


nats-server
  • ==>= 2.12.0-RC.1, < 2.12.6
  • ==< 2.11.15
Upstream advisory: https://github.com/nats-io/nats-server/security/advisories/GHSA-3f24-pcvm-5jqc
NIXPKGS-2026-0772
published 5 months, 3 weeks ago
updated 5 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    3 packages
    • n8n-nodes-carbonejs
    • n8n-nodes-evolution-api
    • n8n-task-runner-launcher
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

n8n Has Multiple Remote Code Execution Vulnerabilities in Merge Node AlaSQL SQL Mode


n8n
  • === 2.14.0
  • ==>= 2.0.0-rc.0, < 2.13.3
  • ==< 1.123.27
Upstream advisory: https://github.com/n8n-io/n8n/security/advisories/GHSA-58qr-rcgv-642v
NIXPKGS-2026-0773
published 5 months, 3 weeks ago
updated 5 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    3 packages
    • n8n-nodes-carbonejs
    • n8n-nodes-evolution-api
    • n8n-task-runner-launcher
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

n8n Vulnerable to Prototype Pollution in XML & GSuiteAdmin node parameters lead to RCE


n8n
  • ==>= 2.0.0-rc.0, < 2.13.3
  • ==< 1.123.27
  • === 2.14.0
Upstream advisory: https://github.com/n8n-io/n8n/security/advisories/GHSA-mxrg-77hm-89hv
NIXPKGS-2026-0756
published 5 months, 3 weeks ago
updated 5 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    3 packages
    • n8n-nodes-carbonejs
    • n8n-nodes-evolution-api
    • n8n-task-runner-launcher
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

n8n: LDAP Email-Based Account Linking Allows Privilege Escalation and Account Takeover


n8n
  • ==< 1.121.0
  • ==>= 2.0.0-rc.0, < 2.4.0
Upstream advisory: https://github.com/n8n-io/n8n/security/advisories/GHSA-c545-x2rh-82fc
NIXPKGS-2026-0765
published 5 months, 3 weeks ago
Permalink CVE-2026-33222
4.9 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): High (H)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): None (N)
updated 5 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

NATS JetStream has an authorization bypass through its Management API


nats-server
  • ==>= 2.12.0-RC.1, < 2.12.6
  • ==< 2.11.15
Upstream advisory: https://github.com/nats-io/nats-server/security/advisories/GHSA-9983-vrx2-fg9c
NIXPKGS-2026-0769
published 5 months, 3 weeks ago
updated 5 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    3 packages
    • n8n-nodes-carbonejs
    • n8n-nodes-evolution-api
    • n8n-task-runner-launcher
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

n8n has In-Process Memory Disclosure in its Task Runner


n8n
  • ==< 1.123.22
  • ==>= 2.10.0, < 2.10.1
  • ==>= 2.0.0-rc.0, < 2.9.3
Upstream advisory: https://github.com/n8n-io/n8n/security/advisories/GHSA-xvh5-5qg4-x9qp
NIXPKGS-2026-0747
published 5 months, 3 weeks ago
Permalink CVE-2026-3608
7.5 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): High (H)
updated 5 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    4 packages
    • keama
    • speakeasy-cli
    • elmPackages.elm-graphql
    • prometheus-kea-exporter
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

Stack overflow in Kea daemons


Kea
  • =<3.0.2
  • =<2.6.4
Upstream advisory: https://kb.isc.org/docs/cve-2026-3608
https://downloads.isc.org/isc/kea/3.0.3