Nixpkgs security tracker

Try the new UI
Login with GitHub

Published issues

All published security issues are tracked and resolved on GitHub.

NIXPKGS-2026-0408
published 6 months, 4 weeks ago
updated 6 months, 4 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    7 packages
    • capypdf
    • python314Packages.pypdfium2
    • python313Packages.pypdfium2
    • python312Packages.pypdfium2
    • python314Packages.pypdf3
    • python313Packages.pypdf3
    • python312Packages.pypdf3
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

pypdf has a possible infinite loop when loading circular /Prev entries in cross-reference streams


pypdf
  • ==< 6.7.2
Upstream advisory: https://github.com/py-pdf/pypdf/security/advisories/GHSA-2rw7-x74f-jg35
Upstream patch: https://github.com/py-pdf/pypdf/commit/0fbd95938724ad2d72688d4112207c0590f0483f
NIXPKGS-2026-0373
published 6 months, 4 weeks ago
Permalink CVE-2026-27951
5.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): Low (L)
updated 6 months, 4 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

FreeRDP has possible Integer overflow in Stream_EnsureCapacity


FreeRDP
  • ==< 3.23.0
Upstream advisory: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-qcfc-ghxr-h927
Upstream patch: https://github.com/FreeRDP/FreeRDP/commit/118afc0b954ba9d5632b7836ad24e454555ed113
NIXPKGS-2026-0372
published 6 months, 4 weeks ago
Permalink CVE-2026-27156
6.1 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Changed (C)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
updated 6 months, 4 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    3 packages
    • python312Packages.nicegui-highcharts
    • python313Packages.nicegui-highcharts
    • python314Packages.nicegui-highcharts
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

NiceGUI has XSS via Code Injection


nicegui
  • ==< 3.8.0
Upstream advisory: https://github.com/zauberzeug/nicegui/security/advisories/GHSA-78qv-3mpx-9cqq
Upstream patch: https://github.com/zauberzeug/nicegui/commit/1861f59cc374ca0dc9d970b157ef3774720f8dbf
NIXPKGS-2026-0371
published 6 months, 4 weeks ago
updated 6 months, 4 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

FreeRDP has heap-use-after-free in xf_clipboard_format_equal


FreeRDP
  • ==< 3.23.0
Upstream advisory: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-q5j3-m6jf-3jq4
Upstream patch: https://github.com/FreeRDP/FreeRDP/commit/58409406afe7c2a8a71ed2dc8e22075be4f41c0c
NIXPKGS-2026-0409
published 6 months, 4 weeks ago
updated 6 months, 4 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    7 packages
    • capypdf
    • python314Packages.pypdfium2
    • python313Packages.pypdfium2
    • python312Packages.pypdfium2
    • python313Packages.pypdf3
    • python314Packages.pypdf3
    • python312Packages.pypdf3
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

pypdf: Manipulated FlateDecode XFA streams can exhaust RAM


pypdf
  • ==< 6.7.3
Upstream advisory: https://github.com/py-pdf/pypdf/security/advisories/GHSA-x7hp-r3qg-r3cj
Upstream patch: https://github.com/py-pdf/pypdf/commit/7a4c8246ed48d9d328fb596942271da47b6d109c
NIXPKGS-2026-0370
published 6 months, 4 weeks ago
updated 6 months, 4 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

FreeRDP: Smartcard NDR Alignment Padding Triggers Reachable WINPR_ASSERT Abort (Client DoS)


FreeRDP
  • ==< 3.23.0
Upstream advisory: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-7g72-39pq-4725
Upstream patch: https://github.com/FreeRDP/FreeRDP/commit/65d59d3b3c2f630f2ea862687ecf5f95f8115244
NIXPKGS-2026-0410
published 6 months, 4 weeks ago
Permalink CVE-2026-28295
4.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
updated 6 months, 4 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

Gvfs: gvfs ftp backend: information disclosure via untrusted pasv responses


gvfs
Upstream issue: https://gitlab.gnome.org/GNOME/gvfs/-/issues/832
Upstream patch: https://gitlab.gnome.org/GNOME/gvfs/-/commit/20db8173252ea88a4af05dc9a24aad6f29b807ad
NIXPKGS-2026-0369
published 6 months, 4 weeks ago
updated 6 months, 4 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

FreeRDP has heap-use-after-free in rail_window_free


FreeRDP
  • ==< 3.23.0
Upstream advisory: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-crqx-g6x5-rx47
Upstream patch: https://github.com/FreeRDP/FreeRDP/commit/b4f0f0a18fe53aa8d47d062f91471f4e9c5e0d51
NIXPKGS-2026-0368
published 6 months, 4 weeks ago
updated 6 months, 4 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

FreeRDP has heap-use-after-free in xf_AppUpdateWindowFromSurface (freed appWindow)


FreeRDP
  • ==< 3.23.0
Upstream advisory: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-p6rq-rxpc-rh3p
Upstream patch: https://github.com/FreeRDP/FreeRDP/commit/1994e9844212a6dfe0ff12309fef520e888986b5
NIXPKGS-2026-0411
published 6 months, 4 weeks ago
Permalink CVE-2026-27900
5.0 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): Low (L)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
updated 6 months, 4 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

Terraform Provider Debug Logs Vulnerable to Sensitive Information Exposure


terraform-provider-linode
  • ==< 3.9.0
Upstream advisory: https://github.com/linode/terraform-provider-linode/security/advisories/GHSA-5rc7-2jj6-mp64
Upstream patch: https://github.com/linode/terraform-provider-linode/commit/43a925d826b999f0355de3dc7330c55f496824c0