Nixpkgs security tracker

Try the new UI
Login with GitHub

Published issues

All published security issues are tracked and resolved on GitHub.

NIXPKGS-2026-0743
published 5 months, 3 weeks ago
updated 5 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

Rails has a possible XSS vulnerability in its Action View tag helpers


actionview
  • ==>= 8.0.0.beta1, < 8.0.4.1
  • ==< 7.2.3.1
  • ==>= 8.1.0.beta1, < 8.1.2.1
Upstream advisory: https://github.com/rails/rails/security/advisories/GHSA-v55j-83pf-r9cq
NIXPKGS-2026-0744
published 5 months, 3 weeks ago
updated 5 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    4 packages
    • rubyPackages.yard-activesupport-concern
    • rubyPackages_3_3.yard-activesupport-concern
    • rubyPackages_3_4.yard-activesupport-concern
    • rubyPackages_4_0.yard-activesupport-concern
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

Rails Active Support has a possible XSS vulnerability in SafeBuffer#%


activesupport
  • ==>= 8.0.0.beta1, < 8.0.4.1
  • ==< 7.2.3.1
  • ==>= 8.1.0.beta1, < 8.1.2.1
Upstream advisory: https://github.com/rails/rails/security/advisories/GHSA-89vf-4333-qx8v
NIXPKGS-2026-0684
published 5 months, 3 weeks ago
updated 5 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

NULL Pointer Dereference in libde265


libde265
  • ==< 1.0.17
Upstream advisory: https://github.com/strukturag/libde265/security/advisories/GHSA-wqrf-6rf5-v78r
NIXPKGS-2026-0733
published 5 months, 3 weeks ago
Permalink CVE-2026-33203
7.5 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): High (H)
updated 5 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

SiYuan has an Unauthenticated WebSocket DoS via Auth Keepalive Bypass


siyuan
  • ==< 3.6.2
Upstream advisory: https://github.com/siyuan-note/siyuan/security/advisories/GHSA-3g9h-9hp4-654v
NIXPKGS-2026-0729
published 5 months, 3 weeks ago
Permalink CVE-2026-4541
2.5 LOW
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Exploit Code Maturity (E): Proof-of-Concept (P)
  • Remediation Level (RL): Official Fix (O)
  • Report Confidence (RC): Confirmed (C)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
updated 5 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

janmojzis tinyssh Ed25519 Signature crypto_sign_ed25519_tinyssh.c signature verification


tinyssh
  • ==20260301
  • ==20250501
Issue: https://github.com/janmojzis/tinyssh/issues/101#issue-3983586116
Patch: https://github.com/janmojzis/tinyssh/commit/9c87269607e0d7d20174df742accc49c042cff17
NIXPKGS-2026-0725
published 5 months, 3 weeks ago
Permalink CVE-2026-32310
4.1 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): Required (R)
  • Scope (S): Changed (C)
  • Confidentiality (C): Low (L)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
updated 5 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored package cryptomator-cli
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

Cryptomator: Unverified masterkeyfile key IDs can access arbitrary local or UNC paths


cryptomator
  • ==>= 1.6.0, <= 1.19.0
Upstream advisory: https://github.com/cryptomator/cryptomator/security/advisories/GHSA-5phc-5pfx-hr52
Upstream patch: https://github.com/cryptomator/cryptomator/commit/1e3dfe3de1623b1b85d24db91e49d31d1ea11f40
NIXPKGS-2026-0697
published 5 months, 3 weeks ago
updated 5 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

Fault injection attack with ML-DSA and ML-KEM on ARM


wolfssl
  • <5.9.0
Upstream patch: https://github.com/wolfSSL/wolfssl/commit/65a1a6887747949ed148d8be3350b86ecff24fbc
NIXPKGS-2026-0721
published 5 months, 3 weeks ago
Permalink CVE-2026-32767
9.8 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 5 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

SiYuan: Authorization Bypass Allows Arbitrary SQL Execution via Search API


siyuan
  • ==< 3.6.1
Upstream advisory: https://github.com/siyuan-note/siyuan/security/advisories/GHSA-j7wh-x834-p3r7
Upstream patch: https://github.com/siyuan-note/siyuan/commit/d5e2d0bce0dffef5f61bd8066954bc2d41181fc5
NIXPKGS-2026-0701
published 5 months, 3 weeks ago
Permalink CVE-2026-32747
6.8 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
updated 5 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

SiYuan: Incomplete sensitive path blocklist in globalCopyFiles allows reading /proc and Docker secrets


siyuan
  • ==< 3.6.1
Upstream advisory: https://github.com/siyuan-note/siyuan/security/advisories/GHSA-h5vh-m7fg-w5h6
Upstream patch: https://github.com/siyuan-note/siyuan/commit/9914fd1d39e5f0a8dcc9fb587e1c0b46f31490a1
NIXPKGS-2026-0705
published 5 months, 3 weeks ago
updated 5 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    5 packages
    • discourse-mail-receiver
    • python312Packages.pydiscourse
    • python313Packages.pydiscourse
    • python314Packages.pydiscourse
    • grafanaPlugins.grafana-discourse-datasource
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

Discourse staff can modify any user's group notification level


discourse
  • ==>= 2026.2.0-latest, < 2026.2.1
  • === 2026.3.0-latest
  • ==>= 2026.1.0-latest, < 2026.1.2
Upstream advisory: https://github.com/discourse/discourse/security/advisories/GHSA-qggq-wr6h-vhrg