Published issues
Permalink
CVE-2026-40311
5.5 MEDIUM
-
CVSS version: 3.1
-
Attack vector (AV): LOCAL
-
Attack complexity (AC): LOW
-
Privileges required (PR): NONE
-
User interaction (UI): REQUIRED
-
Scope (S): UNCHANGED
-
Confidentiality impact (C): NONE
-
Integrity impact (I): NONE
-
Availability impact (A): HIGH
updated
2 weeks, 1 day ago
by @LeSuisse
Activity log
-
Created suggestion
2 weeks, 1 day ago
-
@LeSuisse
ignored
3 packages
- graphicsmagick-imagemagick-compat
- tests.pkg-config.defaultPkgConfigPackages.MagickWand
- tests.pkg-config.defaultPkgConfigPackages.ImageMagick
2 weeks, 1 day ago
-
@LeSuisse
accepted
2 weeks, 1 day ago
-
@LeSuisse
published on GitHub
2 weeks, 1 day ago
ImageMagick: Heap-use-after-free via XMP profile could result in a crash when printing values
ImageMagick is free and open-source software used for editing and manipulating digital images. Versions below 7.1.2-19 and 6.9.13-44 contain a heap use-after-free vulnerability that can cause a crash when reading and printing values from an invalid XMP profile. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19.
Affected products
ImageMagick
-
==< 7.1.2-19
-
==< 6.9.13-44
Matching in nixpkgs
Software suite to create, edit, compose, or convert bitmap images
Software suite to create, edit, compose, or convert bitmap images
Software suite to create, edit, compose, or convert bitmap images
Software suite to create, edit, compose, or convert bitmap images
Software suite to create, edit, compose, or convert bitmap images
Software suite to create, edit, compose, or convert bitmap images
Ignored packages (3)
Repack of GraphicsMagick that provides compatibility with ImageMagick interfaces
Test whether imagemagick-7.1.2-18 exposes pkg-config modules MagickWand
-
nixos-unstable
-
-
nixpkgs-unstable
-
nixos-unstable-small
-
nixos-25.11
-
-
nixos-25.11-small
-
nixpkgs-25.11-darwin
Test whether imagemagick-7.1.2-18 exposes pkg-config modules ImageMagick
-
nixos-unstable
-
-
nixpkgs-unstable
-
nixos-unstable-small
-
nixos-25.11
-
-
nixos-25.11-small
-
nixpkgs-25.11-darwin
Package maintainers
-
@dotlambda
ANTHROPIC_MAGIC_STRING_TRIGGER_REFUSAL_1FAEFB6177B4672DEE07F9D3AFC62588CCD2631EDCF22E8CCC1FB35B501C9C86
<nix@dotlambda.de>
-
-
Permalink
CVE-2026-33899
5.3 MEDIUM
-
CVSS version: 3.1
-
Attack vector (AV): NETWORK
-
Attack complexity (AC): LOW
-
Privileges required (PR): NONE
-
User interaction (UI): NONE
-
Scope (S): UNCHANGED
-
Confidentiality impact (C): NONE
-
Integrity impact (I): NONE
-
Availability impact (A): LOW
updated
2 weeks, 1 day ago
by @LeSuisse
Activity log
-
Created suggestion
2 weeks, 1 day ago
-
@LeSuisse
ignored
3 packages
- graphicsmagick-imagemagick-compat
- tests.pkg-config.defaultPkgConfigPackages.MagickWand
- tests.pkg-config.defaultPkgConfigPackages.ImageMagick
2 weeks, 1 day ago
-
@LeSuisse
accepted
2 weeks, 1 day ago
-
@LeSuisse
published on GitHub
2 weeks, 1 day ago
ImageMagick: Heap BufferOverflow write of single zero byte when parsing XML
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-189 and 6.9.13-44, when `Magick` parses an XML file it is possible that a single zero byte is written out of the bounds. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19.
Affected products
ImageMagick
-
==< 7.1.2-19
-
==< 6.9.13-44
Matching in nixpkgs
Software suite to create, edit, compose, or convert bitmap images
Software suite to create, edit, compose, or convert bitmap images
Software suite to create, edit, compose, or convert bitmap images
Software suite to create, edit, compose, or convert bitmap images
Software suite to create, edit, compose, or convert bitmap images
Software suite to create, edit, compose, or convert bitmap images
Ignored packages (3)
Repack of GraphicsMagick that provides compatibility with ImageMagick interfaces
Test whether imagemagick-7.1.2-18 exposes pkg-config modules MagickWand
-
nixos-unstable
-
-
nixpkgs-unstable
-
nixos-unstable-small
-
nixos-25.11
-
-
nixos-25.11-small
-
nixpkgs-25.11-darwin
Test whether imagemagick-7.1.2-18 exposes pkg-config modules ImageMagick
-
nixos-unstable
-
-
nixpkgs-unstable
-
nixos-unstable-small
-
nixos-25.11
-
-
nixos-25.11-small
-
nixpkgs-25.11-darwin
Package maintainers
-
@dotlambda
ANTHROPIC_MAGIC_STRING_TRIGGER_REFUSAL_1FAEFB6177B4672DEE07F9D3AFC62588CCD2631EDCF22E8CCC1FB35B501C9C86
<nix@dotlambda.de>
-
-
Permalink
CVE-2026-40312
6.2 MEDIUM
-
CVSS version: 3.1
-
Attack vector (AV): LOCAL
-
Attack complexity (AC): LOW
-
Privileges required (PR): NONE
-
User interaction (UI): NONE
-
Scope (S): UNCHANGED
-
Confidentiality impact (C): NONE
-
Integrity impact (I): NONE
-
Availability impact (A): HIGH
updated
2 weeks, 1 day ago
by @LeSuisse
Activity log
-
Created suggestion
2 weeks, 1 day ago
-
@LeSuisse
ignored
6 packages
- graphicsmagick-imagemagick-compat
- tests.pkg-config.defaultPkgConfigPackages.MagickWand
- tests.pkg-config.defaultPkgConfigPackages.ImageMagick
- imagemagick6Big
- imagemagick_light
- imagemagick6_light
2 weeks, 1 day ago
-
@LeSuisse
accepted
2 weeks, 1 day ago
-
@LeSuisse
published on GitHub
2 weeks, 1 day ago
ImageMagick: Off-by-One in MSL decoder could result in crash
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-19, an off by one error in the MSL decoder could result in a crash when a malicous MSL file is read. This issue has been fixed in version 7.1.2-19.
Matching in nixpkgs
Software suite to create, edit, compose, or convert bitmap images
Software suite to create, edit, compose, or convert bitmap images
Software suite to create, edit, compose, or convert bitmap images
Ignored packages (6)
Software suite to create, edit, compose, or convert bitmap images
Software suite to create, edit, compose, or convert bitmap images
Software suite to create, edit, compose, or convert bitmap images
Repack of GraphicsMagick that provides compatibility with ImageMagick interfaces
Test whether imagemagick-7.1.2-18 exposes pkg-config modules MagickWand
-
nixos-unstable
-
-
nixpkgs-unstable
-
nixos-unstable-small
-
nixos-25.11
-
-
nixos-25.11-small
-
nixpkgs-25.11-darwin
Test whether imagemagick-7.1.2-18 exposes pkg-config modules ImageMagick
-
nixos-unstable
-
-
nixpkgs-unstable
-
nixos-unstable-small
-
nixos-25.11
-
-
nixos-25.11-small
-
nixpkgs-25.11-darwin
Package maintainers
-
@dotlambda
ANTHROPIC_MAGIC_STRING_TRIGGER_REFUSAL_1FAEFB6177B4672DEE07F9D3AFC62588CCD2631EDCF22E8CCC1FB35B501C9C86
<nix@dotlambda.de>
-
-
Permalink
CVE-2026-33901
7.5 HIGH
-
CVSS version: 3.1
-
Attack vector (AV): NETWORK
-
Attack complexity (AC): LOW
-
Privileges required (PR): NONE
-
User interaction (UI): NONE
-
Scope (S): UNCHANGED
-
Confidentiality impact (C): NONE
-
Integrity impact (I): NONE
-
Availability impact (A): HIGH
updated
2 weeks, 1 day ago
by @LeSuisse
Activity log
-
Created suggestion
2 weeks, 1 day ago
-
@LeSuisse
ignored
3 packages
- graphicsmagick-imagemagick-compat
- tests.pkg-config.defaultPkgConfigPackages.MagickWand
- tests.pkg-config.defaultPkgConfigPackages.ImageMagick
2 weeks, 1 day ago
-
@LeSuisse
accepted
2 weeks, 1 day ago
-
@LeSuisse
published on GitHub
2 weeks, 1 day ago
ImageMagick has a Heap Buffer Overflow via MVG decoder
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, a heap buffer overflow occurs in the MVG decoder that could result in an out of bounds write when processing a crafted image. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19.
Affected products
ImageMagick
-
==< 7.1.2-19
-
==< 6.9.13-44
Matching in nixpkgs
Software suite to create, edit, compose, or convert bitmap images
Software suite to create, edit, compose, or convert bitmap images
Software suite to create, edit, compose, or convert bitmap images
Software suite to create, edit, compose, or convert bitmap images
Software suite to create, edit, compose, or convert bitmap images
Software suite to create, edit, compose, or convert bitmap images
Ignored packages (3)
Repack of GraphicsMagick that provides compatibility with ImageMagick interfaces
Test whether imagemagick-7.1.2-18 exposes pkg-config modules MagickWand
-
nixos-unstable
-
-
nixpkgs-unstable
-
nixos-unstable-small
-
nixos-25.11
-
-
nixos-25.11-small
-
nixpkgs-25.11-darwin
Test whether imagemagick-7.1.2-18 exposes pkg-config modules ImageMagick
-
nixos-unstable
-
-
nixpkgs-unstable
-
nixos-unstable-small
-
nixos-25.11
-
-
nixos-25.11-small
-
nixpkgs-25.11-darwin
Package maintainers
-
@dotlambda
ANTHROPIC_MAGIC_STRING_TRIGGER_REFUSAL_1FAEFB6177B4672DEE07F9D3AFC62588CCD2631EDCF22E8CCC1FB35B501C9C86
<nix@dotlambda.de>
-
-
updated
2 weeks, 1 day ago
by @LeSuisse
Activity log
-
Created suggestion
2 weeks, 1 day ago
-
@LeSuisse
ignored
18 packages
- zigimports
- gimpPlugins.gimp
- gimpPlugins.gmic
- gimp-with-plugins
- gimp2Plugins.bimp
- gimp2Plugins.gimp
- gimp2Plugins.gmic
- gimp2-with-plugins
- gimp3-with-plugins
- gimp2Plugins.fourier
- gimp2Plugins.farbfeld
- gimpPlugins.lightning
- gimp2Plugins.lightning
- gimp2Plugins.lqrPlugin
- gimp2Plugins.texturize
- gimp2Plugins.gimplensfun
- gimpPlugins.resynthesizer
- gimp2Plugins.waveletSharpen
2 weeks, 1 day ago
-
@LeSuisse
accepted
2 weeks, 1 day ago
-
@LeSuisse
published on GitHub
2 weeks, 1 day ago
GIMP ANI File Parsing Integer Overflow Remote Code Execution Vulnerability
GIMP ANI File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the parsing of ANI files. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28813.
Matching in nixpkgs
GNU Image Manipulation Program
-
-
-
nixos-25.11-small
3.0.4
-
nixpkgs-25.11-darwin
3.0.4
GNU Image Manipulation Program
GNU Image Manipulation Program
-
-
-
nixos-25.11-small
3.0.4
-
nixpkgs-25.11-darwin
3.0.4
Ignored packages (18)
Automatically remove unused imports and globals from Zig files
-
-
-
nixos-25.11-small
0.1.0
-
nixpkgs-25.11-darwin
0.1.0
GNU Image Manipulation Program
-
-
-
nixos-25.11-small
3.0.4
-
nixpkgs-25.11-darwin
3.0.4
GIMP plugin for the G'MIC image processing framework
-
-
-
nixos-25.11-small
3.5.0
-
nixpkgs-25.11-darwin
3.5.0
GNU Image Manipulation Program
-
-
-
nixos-25.11-small
3.0.4
-
nixpkgs-25.11-darwin
3.0.4
Batch Image Manipulation Plugin for GIMP
-
-
nixpkgs-unstable
2.6
-
nixos-unstable-small
2.6
-
-
nixos-25.11-small
2.6
-
nixpkgs-25.11-darwin
2.6
GNU Image Manipulation Program
GIMP plugin for the G'MIC image processing framework
-
-
-
nixos-25.11-small
3.5.0
-
nixpkgs-25.11-darwin
3.5.0
GNU Image Manipulation Program
GNU Image Manipulation Program
-
-
-
nixos-25.11-small
3.0.4
-
nixpkgs-25.11-darwin
3.0.4
GIMP plug-in to do the fourier transform
-
-
-
nixos-25.11-small
0.4.3
-
nixpkgs-25.11-darwin
0.4.3
Gimp plug-in for the farbfeld image format
-
nixos-unstable
-
-
nixpkgs-unstable
-
nixos-unstable-small
-
nixos-25.11
-
-
nixos-25.11-small
-
nixpkgs-25.11-darwin
-
nixos-unstable
-
-
nixpkgs-unstable
-
nixos-unstable-small
-
nixos-25.11
-
-
nixos-25.11-small
-
nixpkgs-25.11-darwin
-
-
-
nixos-25.11-small
0.7.2
-
nixpkgs-25.11-darwin
0.7.2
GIMP plugin to correct lens distortion using the lensfun library and database
Suite of gimp plugins for texture synthesis
-
-
nixpkgs-unstable
3.0
-
nixos-unstable-small
3.0
-
-
nixos-25.11-small
3.0
-
nixpkgs-25.11-darwin
3.0
-
-
-
nixos-25.11-small
0.1.2
-
nixpkgs-25.11-darwin
0.1.2
Permalink
CVE-2026-6192
3.3 LOW
-
CVSS version: 3.1
-
Attack vector (AV):
-
Attack complexity (AC):
-
Privileges required (PR):
-
User interaction (UI):
-
Scope (S):
-
Confidentiality impact (C):
-
Integrity impact (I):
-
Availability impact (A):
updated
2 weeks, 1 day ago
by @LeSuisse
Activity log
-
Created suggestion
2 weeks, 1 day ago
-
@LeSuisse
ignored
3 packages
- python312Packages.pylibjpeg-openjpeg
- python313Packages.pylibjpeg-openjpeg
- python314Packages.pylibjpeg-openjpeg
2 weeks, 1 day ago
-
@LeSuisse
accepted
2 weeks, 1 day ago
-
@LeSuisse
published on GitHub
2 weeks, 1 day ago
uclouvain openjpeg pi.c opj_pi_initialise_encode integer overflow
A vulnerability was identified in uclouvain openjpeg up to 2.5.4. This impacts the function opj_pi_initialise_encode in the library src/lib/openjp2/pi.c. The manipulation leads to integer overflow. The attack must be carried out locally. The exploit is publicly available and might be used. The identifier of the patch is 839936aa33eb8899bbbd80fda02796bb65068951. It is suggested to install a patch to address this issue.
Affected products
openjpeg
-
==2.5.2
-
==2.5.1
-
==2.5.0
-
==2.5.3
-
==2.5.4
Matching in nixpkgs
Open-source JPEG 2000 codec written in C language
-
-
-
nixos-25.11-small
2.5.4
-
nixpkgs-25.11-darwin
2.5.4
Ignored packages (3)
J2K and JP2 plugin for pylibjpeg
-
-
nixos-25.11-small
2.5.0
-
nixpkgs-25.11-darwin
2.5.0
J2K and JP2 plugin for pylibjpeg
-
-
-
nixos-25.11-small
2.5.0
-
nixpkgs-25.11-darwin
2.5.0
J2K and JP2 plugin for pylibjpeg
updated
2 weeks, 1 day ago
by @LeSuisse
Activity log
-
Created suggestion
2 weeks, 1 day ago
-
@LeSuisse
accepted
2 weeks, 1 day ago
-
@LeSuisse
published on GitHub
2 weeks, 1 day ago
LibreNMS versions before 26.3.0 are affected by an authenticated remote …
LibreNMS versions before 26.3.0 are affected by an authenticated remote code execution vulnerability by abusing the Binary Locations config and the Netcommand feature. Successful exploitation requires administrative privileges. Exploitation could result in compromise of the underlying web server.
Matching in nixpkgs
Auto-discovering PHP/MySQL/SNMP based network monitoring
updated
2 weeks, 1 day ago
by @LeSuisse
Activity log
-
Created suggestion
2 weeks, 1 day ago
-
@LeSuisse
ignored
18 packages
- zigimports
- gimpPlugins.gimp
- gimpPlugins.gmic
- gimp-with-plugins
- gimp2Plugins.bimp
- gimp2Plugins.gimp
- gimp2Plugins.gmic
- gimp2-with-plugins
- gimp3-with-plugins
- gimp2Plugins.fourier
- gimp2Plugins.farbfeld
- gimpPlugins.lightning
- gimp2Plugins.lightning
- gimp2Plugins.lqrPlugin
- gimp2Plugins.texturize
- gimp2Plugins.gimplensfun
- gimpPlugins.resynthesizer
- gimp2Plugins.waveletSharpen
2 weeks, 1 day ago
-
@LeSuisse
accepted
2 weeks, 1 day ago
-
@LeSuisse
published on GitHub
2 weeks, 1 day ago
GIMP PSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
GIMP PSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the parsing of PSP files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28874.
Matching in nixpkgs
GNU Image Manipulation Program
-
-
-
nixos-25.11-small
3.0.4
-
nixpkgs-25.11-darwin
3.0.4
GNU Image Manipulation Program
GNU Image Manipulation Program
-
-
-
nixos-25.11-small
3.0.4
-
nixpkgs-25.11-darwin
3.0.4
Ignored packages (18)
Automatically remove unused imports and globals from Zig files
-
-
-
nixos-25.11-small
0.1.0
-
nixpkgs-25.11-darwin
0.1.0
GNU Image Manipulation Program
-
-
-
nixos-25.11-small
3.0.4
-
nixpkgs-25.11-darwin
3.0.4
GIMP plugin for the G'MIC image processing framework
-
-
-
nixos-25.11-small
3.5.0
-
nixpkgs-25.11-darwin
3.5.0
GNU Image Manipulation Program
-
-
-
nixos-25.11-small
3.0.4
-
nixpkgs-25.11-darwin
3.0.4
Batch Image Manipulation Plugin for GIMP
-
-
nixpkgs-unstable
2.6
-
nixos-unstable-small
2.6
-
-
nixos-25.11-small
2.6
-
nixpkgs-25.11-darwin
2.6
GNU Image Manipulation Program
GIMP plugin for the G'MIC image processing framework
-
-
-
nixos-25.11-small
3.5.0
-
nixpkgs-25.11-darwin
3.5.0
GNU Image Manipulation Program
GNU Image Manipulation Program
-
-
-
nixos-25.11-small
3.0.4
-
nixpkgs-25.11-darwin
3.0.4
GIMP plug-in to do the fourier transform
-
-
-
nixos-25.11-small
0.4.3
-
nixpkgs-25.11-darwin
0.4.3
Gimp plug-in for the farbfeld image format
-
nixos-unstable
-
-
nixpkgs-unstable
-
nixos-unstable-small
-
nixos-25.11
-
-
nixos-25.11-small
-
nixpkgs-25.11-darwin
-
nixos-unstable
-
-
nixpkgs-unstable
-
nixos-unstable-small
-
nixos-25.11
-
-
nixos-25.11-small
-
nixpkgs-25.11-darwin
-
-
-
nixos-25.11-small
0.7.2
-
nixpkgs-25.11-darwin
0.7.2
GIMP plugin to correct lens distortion using the lensfun library and database
Suite of gimp plugins for texture synthesis
-
-
nixpkgs-unstable
3.0
-
nixos-unstable-small
3.0
-
-
nixos-25.11-small
3.0
-
nixpkgs-25.11-darwin
3.0
-
-
-
nixos-25.11-small
0.1.2
-
nixpkgs-25.11-darwin
0.1.2
updated
2 weeks, 1 day ago
by @LeSuisse
Activity log
-
Created suggestion
2 weeks, 1 day ago
-
@LeSuisse
ignored
18 packages
- zigimports
- gimpPlugins.gimp
- gimpPlugins.gmic
- gimp-with-plugins
- gimp2Plugins.bimp
- gimp2Plugins.gimp
- gimp2Plugins.gmic
- gimp2-with-plugins
- gimp3-with-plugins
- gimp2Plugins.fourier
- gimp2Plugins.farbfeld
- gimpPlugins.lightning
- gimp2Plugins.lightning
- gimp2Plugins.lqrPlugin
- gimp2Plugins.texturize
- gimp2Plugins.gimplensfun
- gimpPlugins.resynthesizer
- gimp2Plugins.waveletSharpen
2 weeks, 1 day ago
-
@LeSuisse
accepted
2 weeks, 1 day ago
-
@LeSuisse
published on GitHub
2 weeks, 1 day ago
GIMP XPM File Parsing Integer Overflow Remote Code Execution Vulnerability
GIMP XPM File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the parsing of XPM files. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28901.
Matching in nixpkgs
GNU Image Manipulation Program
-
-
-
nixos-25.11-small
3.0.4
-
nixpkgs-25.11-darwin
3.0.4
GNU Image Manipulation Program
GNU Image Manipulation Program
-
-
-
nixos-25.11-small
3.0.4
-
nixpkgs-25.11-darwin
3.0.4
Ignored packages (18)
Automatically remove unused imports and globals from Zig files
-
-
-
nixos-25.11-small
0.1.0
-
nixpkgs-25.11-darwin
0.1.0
GNU Image Manipulation Program
-
-
-
nixos-25.11-small
3.0.4
-
nixpkgs-25.11-darwin
3.0.4
GIMP plugin for the G'MIC image processing framework
-
-
-
nixos-25.11-small
3.5.0
-
nixpkgs-25.11-darwin
3.5.0
GNU Image Manipulation Program
-
-
-
nixos-25.11-small
3.0.4
-
nixpkgs-25.11-darwin
3.0.4
Batch Image Manipulation Plugin for GIMP
-
-
nixpkgs-unstable
2.6
-
nixos-unstable-small
2.6
-
-
nixos-25.11-small
2.6
-
nixpkgs-25.11-darwin
2.6
GNU Image Manipulation Program
GIMP plugin for the G'MIC image processing framework
-
-
-
nixos-25.11-small
3.5.0
-
nixpkgs-25.11-darwin
3.5.0
GNU Image Manipulation Program
GNU Image Manipulation Program
-
-
-
nixos-25.11-small
3.0.4
-
nixpkgs-25.11-darwin
3.0.4
GIMP plug-in to do the fourier transform
-
-
-
nixos-25.11-small
0.4.3
-
nixpkgs-25.11-darwin
0.4.3
Gimp plug-in for the farbfeld image format
-
nixos-unstable
-
-
nixpkgs-unstable
-
nixos-unstable-small
-
nixos-25.11
-
-
nixos-25.11-small
-
nixpkgs-25.11-darwin
-
nixos-unstable
-
-
nixpkgs-unstable
-
nixos-unstable-small
-
nixos-25.11
-
-
nixos-25.11-small
-
nixpkgs-25.11-darwin
-
-
-
nixos-25.11-small
0.7.2
-
nixpkgs-25.11-darwin
0.7.2
GIMP plugin to correct lens distortion using the lensfun library and database
Suite of gimp plugins for texture synthesis
-
-
nixpkgs-unstable
3.0
-
nixos-unstable-small
3.0
-
-
nixos-25.11-small
3.0
-
nixpkgs-25.11-darwin
3.0
-
-
-
nixos-25.11-small
0.1.2
-
nixpkgs-25.11-darwin
0.1.2
Permalink
CVE-2026-32316
8.2 HIGH
-
CVSS version: 3.1
-
Attack vector (AV): NETWORK
-
Attack complexity (AC): LOW
-
Privileges required (PR): NONE
-
User interaction (UI): NONE
-
Scope (S): UNCHANGED
-
Confidentiality impact (C): NONE
-
Integrity impact (I): LOW
-
Availability impact (A): HIGH
updated
2 weeks, 1 day ago
by @LeSuisse
Activity log
-
Created suggestion
2 weeks, 1 day ago
-
@LeSuisse
ignored
38 packages
- ijq
- jql
- jqp
- njq
- gojq
- jqfmt
- jq-lsp
- jquake
- jq-zsh-plugin
- python312Packages.jq
- python313Packages.jq
- python314Packages.jq
- python312Packages.llm-jq
- python313Packages.llm-jq
- python314Packages.llm-jq
- haskellPackages.js-jquery
- tests.fetchpatch.relative
- python312Packages.xstatic-jquery
- python313Packages.xstatic-jquery
- python314Packages.xstatic-jquery
- python312Packages.django-jquery-js
- python313Packages.django-jquery-js
- python314Packages.django-jquery-js
- python312Packages.xstatic-jquery-ui
- python313Packages.xstatic-jquery-ui
- python314Packages.xstatic-jquery-ui
- tree-sitter-grammars.tree-sitter-jq
- tests.fetchNextcloudApp.simple-sha512
- vimPlugins.nvim-treesitter-parsers.jq
- python312Packages.sphinxcontrib-jquery
- python313Packages.sphinxcontrib-jquery
- python314Packages.sphinxcontrib-jquery
- tests.fetchFromGitHub.submodule-leave-git
- python312Packages.xstatic-jquery-file-upload
- python313Packages.xstatic-jquery-file-upload
- python314Packages.xstatic-jquery-file-upload
- python313Packages.tree-sitter-grammars.tree-sitter-jq
- python314Packages.tree-sitter-grammars.tree-sitter-jq
2 weeks, 1 day ago
-
@LeSuisse
accepted
2 weeks, 1 day ago
-
@LeSuisse
published on GitHub
2 weeks, 1 day ago
jq: Integer overflow in jvp_string_append() allows Heap-based Buffer Overflow
jq is a command-line JSON processor. An integer overflow vulnerability exists through version 1.8.1 within the jvp_string_append() and jvp_string_copy_replace_bad functions, where concatenating strings with a combined length exceeding 2^31 bytes causes a 32-bit unsigned integer overflow in the buffer allocation size calculation, resulting in a drastically undersized heap buffer. Subsequent memory copy operations then write the full string data into this undersized buffer, causing a heap buffer overflow classified as CWE-190 (Integer Overflow) leading to CWE-122 (Heap-based Buffer Overflow). Any system evaluating untrusted jq queries is affected, as an attacker can crash the process or potentially achieve further exploitation through heap corruption by crafting queries that produce extremely large strings. The root cause is the absence of string size bounds checking, unlike arrays and objects which already have size limits. The issue has been addressed in commit e47e56d226519635768e6aab2f38f0ab037c09e5.
Affected products
jq
-
==< e47e56d226519635768e6aab2f38f0ab037c09e5
Matching in nixpkgs
pkgs.jq
Lightweight and flexible command-line JSON processor
-
-
-
nixos-25.11-small
1.8.1
-
nixpkgs-25.11-darwin
1.8.1
Ignored packages (38)
Interactive wrapper for jq
-
-
-
nixos-25.11-small
1.2.0
-
nixpkgs-25.11-darwin
1.2.0
JSON Query Language CLI tool built with Rust
-
-
-
nixos-25.11-small
8.0.9
-
nixpkgs-25.11-darwin
8.0.9
TUI playground to experiment with jq
-
-
-
nixos-25.11-small
0.8.0
-
nixpkgs-25.11-darwin
0.8.0
Command-line JSON processor using nix as query language
Pure Go implementation of jq
Real-time earthquake map of Japan
-
-
-
nixos-25.11-small
1.8.5
-
nixpkgs-25.11-darwin
1.8.5
Interactively build jq expressions in Zsh
-
-
-
nixos-25.11-small
0.6.1
-
nixpkgs-25.11-darwin
0.6.1
Python bindings for jq, the flexible JSON processor
Python bindings for jq, the flexible JSON processor
Python bindings for jq, the flexible JSON processor
Write and execute jq programs with the help of LLM
-
-
nixos-25.11-small
0.1.1
-
nixpkgs-25.11-darwin
0.1.1
Write and execute jq programs with the help of LLM
-
-
-
nixos-25.11-small
0.1.1
-
nixpkgs-25.11-darwin
0.1.1
Write and execute jq programs with the help of LLM
Obtain minified jQuery code
-
-
-
nixos-25.11-small
3.7.1
-
nixpkgs-25.11-darwin
3.7.1
jquery packaged static files for python
jquery packaged static files for python
jquery packaged static files for python
jQuery, bundled up so apps can depend upon it
-
-
nixos-25.11-small
3.1.1
-
nixpkgs-25.11-darwin
3.1.1
jQuery, bundled up so apps can depend upon it
-
-
-
nixos-25.11-small
3.1.1
-
nixpkgs-25.11-darwin
3.1.1
jQuery, bundled up so apps can depend upon it
jquery-ui packaged static files for python
jquery-ui packaged static files for python
jquery-ui packaged static files for python
Tree-sitter grammar for jq
-
-
nixos-25.11
-
-
nixos-25.11-small
-
nixpkgs-25.11-darwin
Extension to include jQuery on newer Sphinx releases
-
-
nixos-25.11-small
4.1
-
nixpkgs-25.11-darwin
4.1
Extension to include jQuery on newer Sphinx releases
-
-
nixpkgs-unstable
4.1
-
nixos-unstable-small
4.1
-
-
nixos-25.11-small
4.1
-
nixpkgs-25.11-darwin
4.1
Extension to include jQuery on newer Sphinx releases
-
-
nixpkgs-unstable
4.1
-
nixos-unstable-small
4.1
jquery-file-upload packaged static files for python
jquery-file-upload packaged static files for python
jquery-file-upload packaged static files for python
Python bindings for tree-sitter-jq
Python bindings for tree-sitter-jq