Nixpkgs security tracker

Try the new UI
Login with GitHub

Published issues

All published security issues are tracked and resolved on GitHub.

NIXPKGS-2026-0570
published 6 months, 1 week ago
Permalink CVE-2026-30832
9.1 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): Low (L)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): Low (L)
updated 6 months, 1 week ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt accepted
  • @mweinelt published on GitHub

Soft Serve: SSRF via unvalidated LFS endpoint in repo import


soft-serve
  • ==>= 0.6.0, < 0.11.4
https://github.com/charmbracelet/soft-serve/security/advisories/GHSA-3fvx-xrxq-8jvv

NixOS Unstable: https://github.com/NixOS/nixpkgs/pull/497054
NIXPKGS-2026-0575
published 6 months, 1 week ago
updated 6 months, 1 week ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt accepted
  • @mweinelt published on GitHub

Netmaker: Privilege Escalation from Admin to Super-Admin via User Update


netmaker
  • ==< 1.5.0
Upstream advisory: https://github.com/gravitl/netmaker/security/advisories/GHSA-ch3w-9456-38v3
NIXPKGS-2026-0566
published 6 months, 1 week ago
Permalink CVE-2025-15602
8.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 6 months, 1 week ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt accepted
  • @mweinelt published on GitHub

Snipe-IT < 8.3.7 Mass Assignment Vulnerability Leading to Privilege Escalation


Snipe-IT
  • <8.3.7
NixOS Unstable: https://github.com/NixOS/nixpkgs/commit/ab0b678bb6d6b564079108ff431e6fb01d1b492e
NixOS 25.11: https://github.com/NixOS/nixpkgs/pull/486331 (unmerged)
NIXPKGS-2026-0571
published 6 months, 1 week ago
Permalink CVE-2026-29193
8.2 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
updated 6 months, 1 week ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt ignored package zitadel-tools
  • @mweinelt accepted
  • @mweinelt published on GitHub

ZITADEL: Bypassing Zitadel Login Behavior and Security Policy in Login V2


zitadel
  • ==>= 4.0.0, < 4.12.1
Upstream advisory: https://github.com/zitadel/zitadel/security/advisories/GHSA-25rw-g6ff-fmg8
NIXPKGS-2026-0576
published 6 months, 1 week ago
updated 6 months, 1 week ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt ignored
    33 packages
    • rubyPackages_4_0.jekyll-commonmark-ghpages
    • rubyPackages_3_4.jekyll-commonmark-ghpages
    • rubyPackages_3_3.jekyll-commonmark-ghpages
    • guile-commonmark
    • rubyPackages.commonmarker
    • haskellPackages.commonmark
    • python312Packages.commonmark
    • python313Packages.commonmark
    • python314Packages.commonmark
    • rubyPackages_3_1.commonmarker
    • rubyPackages_3_2.commonmarker
    • rubyPackages_3_3.commonmarker
    • rubyPackages_3_4.commonmarker
    • rubyPackages_4_0.commonmarker
    • haskellPackages.commonmark-cli
    • python312Packages.recommonmark
    • python313Packages.recommonmark
    • python314Packages.recommonmark
    • rubyPackages.jekyll-commonmark
    • tests.nixosOptionsDoc.commonMark
    • haskellPackages.commonmark-pandoc
    • haskellPackages.commonmark-simple
    • haskellPackages.commonmark-initial
    • rubyPackages_3_1.jekyll-commonmark
    • rubyPackages_3_2.jekyll-commonmark
    • rubyPackages_3_3.jekyll-commonmark
    • rubyPackages_3_4.jekyll-commonmark
    • rubyPackages_4_0.jekyll-commonmark
    • haskellPackages.commonmark-wikilink
    • haskellPackages.commonmark-extensions
    • rubyPackages.jekyll-commonmark-ghpages
    • rubyPackages_3_1.jekyll-commonmark-ghpages
    • rubyPackages_3_2.jekyll-commonmark-ghpages
  • @mweinelt accepted
  • @mweinelt published on GitHub

league/commonmark: DisallowedRawHtml extension bypass via whitespace in HTML tag names


commonmark
  • ==< 2.8.1
Affects flarum per composer.lock file
@jasondoom @fsagbuya
NIXPKGS-2026-0580
published 6 months, 1 week ago
Permalink CVE-2026-29192
7.7 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): None (N)
updated 6 months, 1 week ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt accepted
  • @mweinelt published on GitHub

ZITADEL: Stored XSS via Default URI Redirect Leads to Account Takeover


zitadel
  • ==>= 4.0.0, < 4.12.0
Upstream advisory: https://github.com/zitadel/zitadel/security/advisories/GHSA-6rx5-m2rc-hmf7
NIXPKGS-2026-0573
published 6 months, 1 week ago
updated 6 months, 1 week ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt accepted
  • @mweinelt published on GitHub

Netmaker: Insufficient Authorization in Host Token Verification


netmaker
  • ==< 1.5.0
Upstream advisory: https://github.com/gravitl/netmaker/security/advisories/GHSA-hmqr-wjmj-376c
NIXPKGS-2026-0568
published 6 months, 1 week ago
updated 6 months, 1 week ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt accepted
  • @mweinelt published on GitHub

Defuddle: XSS via unescaped string interpolation in _findContentBySchemaText image tag


defuddle
  • ==< 0.9.0
Upstream advisory: https://github.com/kepano/defuddle/security/advisories/GHSA-5mq8-78gm-pjmq
NIXPKGS-2026-0574
published 6 months, 1 week ago
Permalink CVE-2026-29067
8.1 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): None (N)
updated 6 months, 1 week ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt ignored package zitadel-tools
  • @mweinelt accepted
  • @mweinelt published on GitHub

ZITADEL: Account Takeover Due to Improper Instance Validation in V2 Login


zitadel
  • ==>= 4.0.0-rc.1, < 4.7.1
Upstream advisory: https://github.com/zitadel/zitadel/security/advisories/GHSA-pfrf-9r5f-73f5
NIXPKGS-2026-0569
published 6 months, 1 week ago
Permalink CVE-2026-29191
9.3 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): None (N)
updated 6 months, 1 week ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt ignored package zitadel-tools
  • @mweinelt accepted
  • @mweinelt published on GitHub

ZITADEL: 1-Click Account Takeover via XSS in /saml-post Endpoint


zitadel
  • ==>= 4.0.0, < 4.12.0
Upstream advisory: https://github.com/zitadel/zitadel/security/advisories/GHSA-pr34-2v5x-6qjq