Nixpkgs security tracker

Try the new UI
Login with GitHub

Published issues

All published security issues are tracked and resolved on GitHub.

NIXPKGS-2026-0737
published 5 months, 3 weeks ago
updated 5 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    5 packages
    • discourse-mail-receiver
    • python312Packages.pydiscourse
    • python313Packages.pydiscourse
    • python314Packages.pydiscourse
    • grafanaPlugins.grafana-discourse-datasource
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

Discourse has Unauthorized Post Data Exposure in discourse-user-notes


discourse
  • ==>= 2026.2.0-latest, < 2026.2.1
  • === 2026.3.0-latest.1
  • ==>= 2026.1.0-latest, < 2026.1.2
Upstream advisory: https://github.com/discourse/discourse/security/advisories/GHSA-5qm9-r98f-g4mq
NIXPKGS-2026-0685
published 5 months, 3 weeks ago
updated 5 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

Halloy has insecure file permissions on credential files


halloy
  • ==<= 2026.4
Upstream advisory: https://github.com/squidowl/halloy/security/advisories/GHSA-x5j2-fr4h-9p7g
Upstream patch: https://github.com/squidowl/halloy/commit/f180e41061db393acf65bc99f5c5e7397586d9cb
NIXPKGS-2026-0689
published 5 months, 3 weeks ago
updated 5 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    26 packages
    • tests.hardeningFlags.glibcxxassertionsStdenvUnsupp
    • tests.hardeningFlags.glibcxxassertionsExplicitEnabled
    • tests.hardeningFlags-gcc.glibcxxassertionsStdenvUnsupp
    • tests.hardeningFlags.glibcxxassertionsExplicitDisabled
    • tests.hardeningFlags-clang.glibcxxassertionsStdenvUnsupp
    • tests.hardeningFlags-gcc.glibcxxassertionsExplicitEnabled
    • tests.hardeningFlags.allExplicitDisabledGlibcxxAssertions
    • tests.hardeningFlags-gcc.glibcxxassertionsExplicitDisabled
    • tests.hardeningFlags-clang.glibcxxassertionsExplicitEnabled
    • tests.hardeningFlags-clang.glibcxxassertionsExplicitDisabled
    • tests.hardeningFlags-gcc.allExplicitDisabledGlibcxxAssertions
    • tests.hardeningFlags-clang.allExplicitDisabledGlibcxxAssertions
    • iconv
    • getent
    • locale
    • mtrace
    • getconf
    • libiconv
    • glibcInfo
    • glibc_multi
    • glibcLocales
    • glibc_memusage
    • glibcLocalesUtf8
    • unixtools.getent
    • unixtools.locale
    • unixtools.getconf
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

gethostbyaddr and gethostbyaddr_r return invalid DNS hostnames


glibc
  • =<2.43
Proposed patch: https://inbox.sourceware.org/libc-alpha/20260320194250.1089143-1-carlos@redhat.com/
Proposed advisory: https://inbox.sourceware.org/libc-alpha/20260320194804.1089897-2-carlos@redhat.com/
NIXPKGS-2026-0693
published 5 months, 3 weeks ago
Permalink CVE-2026-4539
3.3 LOW
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): Low (L)
  • Exploit Code Maturity (E): Proof-of-Concept (P)
  • Remediation Level (RL): Not Defined (X)
  • Report Confidence (RC): Reasonable (R)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): Low (L)
updated 5 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    24 packages
    • python312Packages.fluent-pygments
    • python313Packages.fluent-pygments
    • python314Packages.fluent-pygments
    • python312Packages.xstatic-pygments
    • python313Packages.xstatic-pygments
    • python314Packages.xstatic-pygments
    • python312Packages.accessible-pygments
    • python312Packages.jupyterlab-pygments
    • python313Packages.accessible-pygments
    • python313Packages.jupyterlab-pygments
    • python314Packages.accessible-pygments
    • python314Packages.jupyterlab-pygments
    • python312Packages.pygments-better-html
    • python313Packages.pygments-better-html
    • python314Packages.pygments-better-html
    • python312Packages.pygments-style-github
    • python313Packages.pygments-style-github
    • python314Packages.pygments-style-github
    • python312Packages.ipython-pygments-lexers
    • python312Packages.pygments-markdown-lexer
    • python313Packages.ipython-pygments-lexers
    • python313Packages.pygments-markdown-lexer
    • python314Packages.ipython-pygments-lexers
    • python314Packages.pygments-markdown-lexer
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

pygments archetype.py AdlLexer redos


pygments
  • ==2.19.1
  • ==2.19.2
  • ==2.19.0
Upstream advisory: https://github.com/advisories/GHSA-5239-wwwm-4pmq
NIXPKGS-2026-0734
published 5 months, 3 weeks ago
updated 5 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

Kargo: SSRF in Promotion http/http-download Steps Enables Internal Network Access and Data Exfiltration


kargo
  • ==>= 1.9.0-rc.1, < 1.9.5
  • ==>= 1.7.0-rc.1, < 1.7.9
  • ==>= 1.4.0, < 1.6.4
  • ==>= 1.8.0-rc.1, < 1.8.12
Upstream advisory: https://github.com/akuity/kargo/security/advisories/GHSA-j94x-8wcp-x7hm
Upstream patch: https://github.com/akuity/kargo/commit/fd25620c2473ed19bec4be4d0f181287ef0f0391
NIXPKGS-2026-0730
published 5 months, 3 weeks ago
Permalink CVE-2026-33179
5.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): High (H)
updated 5 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored package haskellPackages.libfuse3
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

libfuse: NULL Pointer Dereference and Memory Leak in io_uring Queue Initialization


libfuse
  • ==>= 3.18.0, < 3.18.2
Upstream advisory: https://github.com/libfuse/libfuse/security/advisories/GHSA-x669-v3mq-r358
Upstream patch: https://github.com/libfuse/libfuse/commit/7beb86c09b6ec5aab14dc25256ed8a5ad18554d7
NIXPKGS-2026-0726
published 5 months, 3 weeks ago
updated 5 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    5 packages
    • discourse-mail-receiver
    • python312Packages.pydiscourse
    • python313Packages.pydiscourse
    • python314Packages.pydiscourse
    • grafanaPlugins.grafana-discourse-datasource
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

Discourse Authorization Page Displays Unvalidated Redirect Domain


discourse
  • ==>= 2026.2.0-latest, < 2026.2.1
  • === 2026.3.0-latest
  • ==>= 2026.1.0-latest, < 2026.1.2
Advisory: https://github.com/discourse/discourse/security/advisories/GHSA-9vhg-2mx3-mqfr
NIXPKGS-2026-0722
published 5 months, 3 weeks ago
Permalink CVE-2026-33251
5.4 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
updated 5 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    5 packages
    • discourse-mail-receiver
    • python312Packages.pydiscourse
    • python313Packages.pydiscourse
    • python314Packages.pydiscourse
    • grafanaPlugins.grafana-discourse-datasource
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

Discourse has a Hidden Solved topics permission bypass


discourse
  • ==>= 2026.2.0-latest, < 2026.2.1
  • === 2026.3.0-latest
  • ==>= 2026.1.0-latest, < 2026.1.2
Upstream advisory: https://github.com/discourse/discourse/security/advisories/GHSA-vm2x-9h8x-7jxm
NIXPKGS-2026-0718
published 5 months, 3 weeks ago
Permalink CVE-2026-31805
5.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
updated 5 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    5 packages
    • discourse-mail-receiver
    • python312Packages.pydiscourse
    • python313Packages.pydiscourse
    • python314Packages.pydiscourse
    • grafanaPlugins.grafana-discourse-datasource
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

Discourse has a poll authorization bypass via post_id array parameter


discourse
  • ==>= 2026.2.0-latest, < 2026.2.1
  • === 2026.3.0-latest.1
  • ==>= 2026.1.0-latest, < 2026.1.2
Upstream advisory: https://github.com/discourse/discourse/security/advisories/GHSA-fgxm-prjv-g823
NIXPKGS-2026-0714
published 5 months, 3 weeks ago
updated 5 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

SiYuan has Stored XSS to RCE via Unsanitized Bazaar README Rendering


siyuan
  • ==< 3.6.1
Upstream advisory: https://github.com/siyuan-note/siyuan/security/advisories/GHSA-4663-4mpg-879v
Upstream patch: https://github.com/siyuan-note/siyuan/commit/b382f50e1880ed996364509de5a10a72d7409428