Nixpkgs security tracker

Try the new UI
Login with GitHub

Published issues

All published security issues are tracked and resolved on GitHub.

NIXPKGS-2026-0615
published 6 months, 1 week ago
updated 6 months, 1 week ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt added
    5 maintainers
    • @wegank
    • @Prince213
    • @phanirithvij
    • @ethancedwards8
    • @eljamm
    maintainer.add
  • @mweinelt accepted
  • @mweinelt published on GitHub

Misskey lacks proper authorization checks and input validation


misskey
  • ==>= 8.45.0, < 2026.3.1
https://github.com/misskey-dev/misskey/security/advisories/GHSA-r33c-qg3g-v9cr
NIXPKGS-2026-0609
published 6 months, 1 week ago
Permalink CVE-2026-30937
6.8 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): High (H)
updated 6 months, 1 week ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt ignored
    6 packages
    • imagemagick6
    • imagemagick6Big
    • imagemagick6_light
    • graphicsmagick-imagemagick-compat
    • tests.pkg-config.defaultPkgConfigPackages.MagickWand
    • tests.pkg-config.defaultPkgConfigPackages.ImageMagick
  • @mweinelt accepted
  • @mweinelt published on GitHub

ImageMagick has a heap buffer overflow in WriteXWDImage due to CARD32 arithmetic overflow in bytes_per_line calculation


ImageMagick
  • ==>= 7.0.0, < 7.1.2-16
  • ==< 6.9.13-41
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-qpg4-j99f-8xcg
NIXPKGS-2026-0614
published 6 months, 1 week ago
updated 6 months, 1 week ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt added
    5 maintainers
    • @wegank
    • @Prince213
    • @phanirithvij
    • @ethancedwards8
    • @eljamm
    maintainer.add
  • @mweinelt accepted
  • @mweinelt published on GitHub

Misskey lacks resource ownership validation


misskey
  • ==>= 10.93.0, < 2026.3.1
https://github.com/misskey-dev/misskey/security/advisories/GHSA-g6hj-33h7-6fq8
NIXPKGS-2026-0602
published 6 months, 1 week ago
Permalink CVE-2026-28689
6.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): None (N)
updated 6 months, 1 week ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt ignored
    6 packages
    • imagemagick6
    • imagemagick6Big
    • imagemagick6_light
    • graphicsmagick-imagemagick-compat
    • tests.pkg-config.defaultPkgConfigPackages.MagickWand
    • tests.pkg-config.defaultPkgConfigPackages.ImageMagick
  • @mweinelt accepted
  • @mweinelt published on GitHub

ImageMagick has a Path Policy TOCTOU symlink race bypass


ImageMagick
  • ==>= 7.0.0, < 7.1.2-16
  • ==< 6.9.13-41
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-493f-jh8w-qhx3
NIXPKGS-2026-0584
published 6 months, 1 week ago
Permalink CVE-2026-26330
5.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): High (H)
updated 6 months, 1 week ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt ignored
    11 packages
    • opa-envoy-plugin
    • python312Packages.envoy-utils
    • python313Packages.envoy-utils
    • python314Packages.envoy-utils
    • python312Packages.envoy-reader
    • python313Packages.envoy-reader
    • python314Packages.envoy-reader
    • python313Packages.envoy-data-plane
    • python314Packages.envoy-data-plane
    • home-assistant-component-tests.enphase_envoy
    • tests.home-assistant-component-tests.enphase_envoy
  • @mweinelt accepted
  • @mweinelt published on GitHub

Envoy global rate limit may crash when the response phase limit is enabled and the response phase request is failed directly


envoy
  • ==< 1.34.13
  • ==>= 1.36.0, < 1.36.5
  • ==>= 1.37.0, < 1.37.1
  • ==>= 1.35.0, < 1.35.9
https://github.com/envoyproxy/envoy/security/advisories/GHSA-c23c-rp3m-vpg3
NIXPKGS-2026-0623
published 6 months, 1 week ago
Permalink CVE-2026-31817
8.5 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): None (N)
  • Integrity (I): High (H)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): Low (L)
updated 6 months, 1 week ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt accepted
  • @mweinelt published on GitHub

OliveTin has unsafe parsing of UniqueTrackingId can be used to write files


OliveTin
  • ==< 3000.11.2
https://github.com/OliveTin/OliveTin/security/advisories/GHSA-364q-w7vh-vhpc
NIXPKGS-2026-0583
published 6 months, 1 week ago
updated 6 months, 1 week ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt ignored
    5 packages
    • python312Packages.glances-api
    • python313Packages.glances-api
    • python314Packages.glances-api
    • home-assistant-component-tests.glances
    • tests.home-assistant-component-tests.glances
  • @mweinelt accepted
  • @mweinelt published on GitHub

Glances Exposes Unauthenticated Configuration Secrets


glances
  • ==< 4.5.1
https://github.com/nicolargo/glances/security/advisories/GHSA-gh4x-f7cq-wwx6
https://github.com/nicolargo/glances/commit/306a7136154ba5c1531489c99f8306d84eae37da
NIXPKGS-2026-0606
published 6 months, 1 week ago
Permalink CVE-2025-62166
7.5 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
updated 6 months, 1 week ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt ignored
    7 packages
    • freshrss-extensions.demo
    • freshrss-extensions.youtube
    • freshrss-extensions.auto-ttl
    • freshrss-extensions.title-wrap
    • freshrss-extensions.reading-time
    • freshrss-extensions.reddit-image
    • freshrss-extensions.unsafe-auto-login
  • @mweinelt accepted
  • @mweinelt published on GitHub

FreshRSS has an IDOR which allows for viewing feeds of any user and leaking tokens


FreshRSS
  • ==< 1.28.0
https://github.com/NixOS/nixpkgs/pull/473921

Patch not backported
NIXPKGS-2026-0600
published 6 months, 1 week ago
Permalink CVE-2026-28513
8.5 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
updated 6 months, 1 week ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt accepted
  • @mweinelt published on GitHub

Pocket ID: OIDC authorization code validation uses AND instead of OR, allowing cross-client token exchange


pocket-id
  • ==< 2.4.0
https://github.com/pocket-id/pocket-id/security/advisories/GHSA-qh6q-598w-w6m2

NixOS Unstable: https://github.com/NixOS/nixpkgs/pull/497928
NixOS 25.11: Unfixed
NIXPKGS-2026-0618
published 6 months, 1 week ago
updated 6 months, 1 week ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt accepted
  • @mweinelt published on GitHub

Giflib contains a double-free vulnerability that is the result of …


giflib
  • =<6.1.1
https://www.facebook.com/security/advisories/cve-2026-23868
https://sourceforge.net/p/giflib/code/ci/f5b7267aed3665ef025c13823e454170d031c106/tree/gifalloc.c?diff=5146815377b7395944cb683a08c43eee3f631eb7