Nixpkgs security tracker

Login with GitHub

Published issues

All published security issues are tracked and resolved on GitHub.

NIXPKGS-2026-0042
published 5 months, 3 weeks ago
Permalink CVE-2025-62398
5.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
updated 5 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored package moodle-dl
  • @LeSuisse deleted maintainer @freezeboy maintainer.delete
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

Moodle: possible to bypass mfa


moodle
  • <4.5.7
  • <5.0.3
  • <4.4.11
NIXPKGS-2026-0041
published 5 months, 3 weeks ago
Permalink CVE-2025-62399
7.5 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): High (H)
updated 5 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored package moodle-dl
  • @LeSuisse deleted maintainer @freezeboy maintainer.delete
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

Moodle: password brute force risk when mobile/web services enabled


moodle
  • <4.5.7
  • <5.0.3
  • <4.4.11
  • <4.1.21
NIXPKGS-2026-0040
published 5 months, 3 weeks ago
Permalink CVE-2025-62397
5.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
updated 5 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored package moodle-dl
  • @LeSuisse deleted
    2 maintainers
    • @kmein
    • @freezeboy
    maintainer.delete
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

Moodle: router produces json instead of 404 error for invalid course id


moodle
  • <5.0.3
NIXPKGS-2026-0039
published 5 months, 3 weeks ago
Permalink CVE-2025-62393
4.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
updated 5 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored package moodle-dl
  • @LeSuisse deleted maintainer @freezeboy maintainer.delete
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

Moodle: course access permissions not properly checked in course_output_fragment_course_overview


moodle
  • <5.0.3
NIXPKGS-2026-0038
published 5 months, 3 weeks ago
Permalink CVE-2025-62400
4.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
updated 5 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored package moodle-dl
  • @LeSuisse deleted
    2 maintainers
    • @kmein
    • @freezeboy
    maintainer.delete
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

Moodle: hidden group names visible to event creators


moodle
  • <4.5.7
  • <5.0.3
  • <4.4.11
  • <4.1.21
NIXPKGS-2026-0031
published 5 months, 3 weeks ago
Permalink CVE-2025-14017
6.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): None (N)
updated 5 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    11 packages
    • wcurl
    • curlie
    • curlpp
    • phpExtensions.curl
    • curl-impersonate
    • curlWithGnuTls
    • curlMinimal
    • guile-curl
    • curlftpfs
    • curlHTTP3
    • grpcurl
  • @LeSuisse restored package curlMinimal
  • @LeSuisse ignored
    33 packages
    • curl-impersonate-ff
    • ocamlPackages.curly
    • ocamlPackages.ocurl
    • tclPackages.tclcurl
    • haskellPackages.curl
    • luaPackages.lua-curl
    • perlPackages.WWWCurl
    • php81Extensions.curl
    • php82Extensions.curl
    • php83Extensions.curl
    • haskellPackages.curlhs
    • php84Extensions.curl
    • lua51Packages.lua-curl
    • lua52Packages.lua-curl
    • lua53Packages.lua-curl
    • lua54Packages.lua-curl
    • curl-impersonate-chrome
    • luajitPackages.lua-curl
    • perl538Packages.WWWCurl
    • perl540Packages.WWWCurl
    • haskellPackages.hxt-curl
    • python312Packages.pycurl
    • python313Packages.pycurl
    • python312Packages.curlify
    • python313Packages.curlify
    • tests.pkg-config.defaultPkgConfigPackages.libcurl
    • haskellPackages.recurly-client
    • haskellPackages.curly-expander
    • haskellPackages.curl-cookiejar
    • haskellPackages.download-curl
    • python313Packages.curl-cffi
    • python312Packages.curl-cffi
    • typstPackages.curli_0_1_0
  • @LeSuisse deleted
    2 maintainers
    • @Scrumplex
    • @lovek323
    maintainer.delete
  • @LeSuisse added
    14 maintainers
    • @GGG-KILLER
    • @deliciouslytyped
    • @Ma27
    • @CrazedProgrammer
    • @knl
    • @ethancedwards8
    • @piotrkwiecinski
    • @aanderse
    • @talyz
    • @chuangzhu
    • @fgaz
    • @bennofs
    • @D4ndellion
    • @sternenseemann
    maintainer.add
  • @LeSuisse deleted
    14 maintainers
    • @GGG-KILLER
    • @deliciouslytyped
    • @Ma27
    • @CrazedProgrammer
    • @knl
    • @ethancedwards8
    • @piotrkwiecinski
    • @aanderse
    • @talyz
    • @chuangzhu
    • @fgaz
    • @bennofs
    • @D4ndellion
    • @sternenseemann
    maintainer.delete
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

broken TLS options for threaded LDAPS


curl
  • =<7.42.0
  • =<7.43.0
  • =<7.21.1
  • =<7.73.0
  • =<7.50.2
  • =<7.19.5
  • =<7.82.0
  • =<7.22.0
  • =<8.0.0
  • =<8.1.1
  • =<8.4.0
  • =<7.88.1
  • =<7.88.0
  • =<7.18.2
  • =<7.23.1
  • =<7.70.0
  • =<7.78.0
  • =<7.69.0
  • =<7.35.0
  • =<7.47.0
  • =<7.55.0
  • =<7.32.0
  • =<7.66.0
  • =<8.8.0
  • =<7.24.0
  • =<7.83.0
  • =<7.76.1
  • =<7.19.7
  • =<7.47.1
  • =<8.1.0
  • =<7.58.0
  • =<7.18.0
  • =<7.79.0
  • =<7.50.3
  • =<7.17.0
  • =<8.5.0
  • =<8.9.0
  • =<7.54.1
  • =<7.52.0
  • =<7.19.2
  • =<8.7.1
  • =<7.81.0
  • =<7.61.0
  • =<7.84.0
  • =<7.21.7
  • =<7.28.0
  • =<7.72.0
  • =<7.26.0
  • =<7.53.1
  • =<8.11.0
  • =<7.19.1
  • =<7.83.1
  • =<7.40.0
  • =<7.21.5
  • =<7.23.0
  • =<8.10.0
  • =<7.85.0
  • =<7.67.0
  • =<7.39.0
  • =<7.45.0
  • =<7.71.0
  • =<7.20.1
  • =<7.65.0
  • =<7.46.0
  • =<7.25.0
  • =<8.13.0
  • =<7.61.1
  • =<7.21.6
  • =<7.19.6
  • =<7.21.4
  • =<7.65.2
  • =<8.0.1
  • =<7.36.0
  • =<7.76.0
  • =<8.2.1
  • =<8.17.0
  • =<7.33.0
  • =<7.19.4
  • =<7.49.1
  • =<7.42.1
  • =<7.50.0
  • =<7.21.3
  • =<7.62.0
  • =<7.29.0
  • =<8.15.0
  • =<7.56.1
  • =<7.34.0
  • =<7.59.0
  • =<7.77.0
  • =<7.56.0
  • =<7.41.0
  • =<7.74.0
  • =<7.19.3
  • =<8.12.0
  • =<8.10.1
  • =<7.86.0
  • =<8.11.1
  • =<8.14.0
  • =<7.54.0
  • =<7.55.1
  • =<8.2.0
  • =<8.9.1
  • =<7.17.1
  • =<7.53.0
  • =<7.65.3
  • =<7.50.1
  • =<7.75.0
  • =<7.52.1
  • =<7.30.0
  • =<7.31.0
  • =<8.14.1
  • =<7.38.0
  • =<7.65.1
  • =<8.16.0
  • =<7.19.0
  • =<7.68.0
  • =<7.48.0
  • =<7.20.0
  • =<8.1.2
  • =<7.69.1
  • =<7.28.1
  • =<8.7.0
  • =<7.57.0
  • =<7.71.1
  • =<7.79.1
  • =<7.60.0
  • =<7.21.2
  • =<8.6.0
  • =<7.27.0
  • =<7.64.0
  • =<7.80.0
  • =<7.21.0
  • =<7.49.0
  • =<8.12.1
  • =<8.3.0
  • =<7.64.1
  • =<7.44.0
  • =<7.63.0
  • =<7.51.0
  • =<7.18.1
  • =<7.37.0
  • =<7.87.0
  • =<7.37.1
NIXPKGS-2026-0028
published 5 months, 3 weeks ago
updated 5 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse deleted maintainer @peterhoeg maintainer.delete
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

FreeRDP has a heap-buffer-overflow in drive_process_irp_read


FreeRDP
  • ==< 3.20.1
NIXPKGS-2026-0037
published 5 months, 3 weeks ago
Permalink CVE-2025-62394
4.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
updated 5 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored package moodle-dl
  • @LeSuisse deleted maintainer @freezeboy maintainer.delete
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

Moodle: quiz notifications sent to suspended participants


moodle
  • <4.5.7
  • <5.0.3
NIXPKGS-2026-0036
published 5 months, 3 weeks ago
Permalink CVE-2025-62401
5.4 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): Low (L)
updated 5 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored package moodle-dl
  • @LeSuisse deleted maintainer @freezeboy maintainer.delete
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

Moodle: possible to bypass timer in timed assignments


moodle
  • <4.5.7
  • <5.0.3
  • <4.4.11
  • <4.1.21
NIXPKGS-2026-0034
published 5 months, 3 weeks ago
Permalink CVE-2025-12105
7.5 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): High (H)
updated 5 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    2 packages
    • tests.pkg-config.defaultPkgConfigPackages."libsoup-gnome-2.4"
    • libsoup_2_4
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

Libsoup: heap use-after-free in libsoup message queue handling during http/2 read completion


libsoup
  • =<3.6.5
libsoup3
  • *
Upstream fix: https://gitlab.gnome.org/GNOME/libsoup/-/commit/9ba1243a24e442fa5ec44684617a4480027da960