Nixpkgs security tracker

Try the new UI
Login with GitHub

Published issues

All published security issues are tracked and resolved on GitHub.

NIXPKGS-2026-0601
published 6 months, 1 week ago
Permalink CVE-2026-28693
8.1 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 6 months, 1 week ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt ignored
    6 packages
    • imagemagick6
    • imagemagick6Big
    • imagemagick6_light
    • graphicsmagick-imagemagick-compat
    • tests.pkg-config.defaultPkgConfigPackages.MagickWand
    • tests.pkg-config.defaultPkgConfigPackages.ImageMagick
  • @mweinelt accepted
  • @mweinelt published on GitHub

ImageMagick has an integer overflow in DIB coder can result in out of bounds read or write


ImageMagick
  • ==< 6.9.13-41
  • ==>= 7.0.0, < 7.1.2-16
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-hffp-q43q-qq76
NIXPKGS-2026-0588
published 6 months, 1 week ago
updated 6 months, 1 week ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt ignored
    5 packages
    • python312Packages.glances-api
    • python313Packages.glances-api
    • python314Packages.glances-api
    • home-assistant-component-tests.glances
    • tests.home-assistant-component-tests.glances
  • @mweinelt accepted
  • @mweinelt published on GitHub

Glances has SQL Injection via Process Names in TimescaleDB Export


glances
  • ==< 4.5.1
https://github.com/nicolargo/glances/security/advisories/GHSA-x46r-mf5g-xpr6
https://github.com/nicolargo/glances/commit/39161f0d6fd723d83f534b48f24cdca722573336
NIXPKGS-2026-0581
published 6 months, 1 week ago
Permalink CVE-2026-3731
5.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): Low (L)
  • Exploit Code Maturity (E): Not Defined (X)
  • Remediation Level (RL): Official Fix (O)
  • Report Confidence (RC): Confirmed (C)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): Low (L)
updated 6 months, 1 week ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt ignored
    8 packages
    • libssh2
    • haskellPackages.libssh
    • haskellPackages.libssh2
    • haskellPackages.libssh2-conduit
    • python312Packages.ansible-pylibssh
    • python313Packages.ansible-pylibssh
    • python314Packages.ansible-pylibssh
    • tests.pkg-config.defaultPkgConfigPackages.libssh2
  • @mweinelt accepted
  • @mweinelt published on GitHub

libssh SFTP Extension Name sftp.c sftp_extensions_get_data out-of-bounds


libssh
  • ==0.11.2
  • ==0.12.0
  • ==0.11.0
  • ==0.11.4
  • ==0.11.3
  • ==0.11.1
https://www.libssh.org/security/advisories/libssh-2026-sftp-extensions.txt
NIXPKGS-2026-0582
published 6 months, 1 week ago
Permalink CVE-2026-3706
3.7 LOW
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Exploit Code Maturity (E): Proof-of-Concept (P)
  • Remediation Level (RL): Official Fix (O)
  • Report Confidence (RC): Confirmed (C)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
updated 6 months, 1 week ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt accepted
  • @mweinelt published on GitHub

mkj Dropbear S Range Check curve25519.c unpackneg signature verification


Dropbear
  • ==2025.3
  • ==2025.6
  • ==2025.11
  • ==2025.8
  • ==2025.53
  • ==2025.42
  • ==2025.86
  • ==2025.83
  • ==2025.80
  • ==2025.7
  • ==2025.32
  • ==2025.76
  • ==2025.5
  • ==2025.77
  • ==2025.24
  • ==2025.27
  • ==2025.28
  • ==2025.47
  • ==2025.78
  • ==2025.74
  • ==2025.61
  • ==2025.50
  • ==2025.38
  • ==2025.4
  • ==2025.65
  • ==2025.33
  • ==2025.25
  • ==2025.10
  • ==2025.81
  • ==2025.68
  • ==2025.87
  • ==2025.67
  • ==2025.2
  • ==2025.29
  • ==2025.15
  • ==2025.46
  • ==2025.30
  • ==2025.44
  • ==2025.17
  • ==2025.26
  • ==2025.23
  • ==2025.9
  • ==2025.35
  • ==2025.72
  • ==2025.88
  • ==2025.71
  • ==2025.79
  • ==2025.60
  • ==2025.14
  • ==2025.12
  • ==2025.18
  • ==2025.70
  • ==2025.57
  • ==2025.55
  • ==2025.59
  • ==2025.49
  • ==2025.20
  • ==2025.37
  • ==2025.43
  • ==2025.66
  • ==2025.40
  • ==2025.63
  • ==2025.56
  • ==2025.1
  • ==2025.62
  • ==2025.84
  • ==2025.82
  • ==2025.75
  • ==2025.16
  • ==2025.48
  • ==2025.13
  • ==2025.39
  • ==2025.54
  • ==2025.51
  • ==2025.52
  • ==2025.58
  • ==2025.64
  • ==2025.0
  • ==2025.31
  • ==2025.69
  • ==2025.73
  • ==2025.22
  • ==2025.89
  • ==2025.19
  • ==2025.45
  • ==2025.41
  • ==2025.85
  • ==2025.36
  • ==2025.21
  • ==2025.34
https://github.com/mkj/dropbear/issues/406#issue-3978907798
https://github.com/mkj/dropbear/pull/407
NIXPKGS-2026-0578
published 6 months, 1 week ago
updated 6 months, 1 week ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt accepted
  • @mweinelt published on GitHub

Netmaker: Denial of Service via Server Shutdown Endpoint


netmaker
  • ==< 1.2.0
Upstream advisory: https://github.com/gravitl/netmaker/security/advisories/GHSA-rhr9-hgcm-x289
NIXPKGS-2026-0577
published 6 months, 1 week ago
Permalink CVE-2026-30825
0.0 NONE
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
updated 6 months, 1 week ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt accepted
  • @mweinelt published on GitHub

hoppscotch: IDOR - Any authenticated user can revoke any other user's Personal Access Token


hoppscotch
  • ==< 2026.2.1
Upstream advisory: https://github.com/hoppscotch/hoppscotch/security/advisories/GHSA-7pfq-mwj3-xw9h
NIXPKGS-2026-0572
published 6 months, 1 week ago
updated 6 months, 1 week ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt accepted
  • @mweinelt published on GitHub

Netmaker: Service User with Network Access Can Access config files with WireGuard Private Keys


netmaker
  • ==< 1.5.0
Upstream advisory: https://github.com/gravitl/netmaker/security/advisories/GHSA-4hgg-c4rr-6h7f
NIXPKGS-2026-0567
published 6 months, 1 week ago
Permalink CVE-2026-29778
7.1 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): High (H)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): Low (L)
updated 6 months, 1 week ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt ignored
    5 packages
    • python312Packages.pyloadapi
    • python313Packages.pyloadapi
    • python314Packages.pyloadapi
    • home-assistant-component-tests.pyload
    • tests.home-assistant-component-tests.pyload
  • @mweinelt accepted
  • @mweinelt published on GitHub

pyLoad: Arbitrary File Write via Path Traversal in edit_package()


pyload
  • ==>= 0.5.0b3.dev13, < 0.5.0b3.dev97
Upstream advisory: https://github.com/pyload/pyload/security/advisories/GHSA-6px9-j4qr-xfjw
NIXPKGS-2026-0579
published 6 months, 1 week ago
updated 6 months, 1 week ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt accepted
  • @mweinelt published on GitHub

It was discovered that dpkg-deb (a component of dpkg, the …


dpkg
  • <1.23.6
Upstream issue: https://bugs.debian.org/challenge.html?original=%2f1129722
Patch: https://git.dpkg.org/cgit/dpkg/dpkg.git/commit/?id=6610297a62c0780dd0e80b0e302ef64fdcc9d313
NIXPKGS-2026-0565
published 6 months, 1 week ago
Permalink CVE-2026-29049
4.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): Low (L)
updated 6 months, 1 week ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt ignored
    6 packages
    • ocamlPackages.melange
    • ocamlPackages.melange-json
    • ocamlPackages_latest.melange
    • ocamlPackages.melange-json-native
    • ocamlPackages_latest.melange-json
    • ocamlPackages_latest.melange-json-native
  • @mweinelt accepted
  • @mweinelt published on GitHub

melange: unbounded HTTP download in `melange update-cache` can exhaust disk in CI


melange
  • ==<= 0.40.5
NixOS Unstable: https://github.com/NixOS/nixpkgs/commit/fc16741b0fa908e009f5ca0c3b8437a9095628ab
NixOS 25.11: requires patch or backport