Nixpkgs security tracker

Try the new UI
Login with GitHub

Published issues

All published security issues are tracked and resolved on GitHub.

NIXPKGS-2026-0407
published 6 months, 4 weeks ago
Permalink CVE-2026-27948
5.4 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
updated 6 months, 4 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

Copyparty vulnerable to eflected cross-site scripting via setck parameter


copyparty
  • ==< 1.20.9
Upstream advisory: https://github.com/9001/copyparty/security/advisories/GHSA-62cr-6wp5-q43h
Upstream patch: https://github.com/9001/copyparty/commit/31b2801fd041f803f4a3d5c12c7d7cb5419048bc
NIXPKGS-2026-0406
published 6 months, 4 weeks ago
updated 6 months, 4 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

psd-tools: Compression module has unguarded zlib decompression, missing dimension validation, and hardening gaps


psd-tools
  • ==< 1.12.2
Upstream advisory: https://github.com/psd-tools/psd-tools/security/advisories/GHSA-24p2-j2jr-386w
Upstream patch: https://github.com/psd-tools/psd-tools/commit/6c0a78f195b5942757886a1863793fd5946c1fb1
NIXPKGS-2026-0405
published 6 months, 4 weeks ago
updated 6 months, 4 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    3 packages
    • n8n-nodes-carbonejs
    • n8n-task-runner-launcher
    • tests.fetchpatch2.relative
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

n8n has a Sandbox Escape in its JavaScript Task Runner


n8n
  • ==>= 2.0.0, < 2.9.3
  • ==< 1.123.22
  • ==>= 2.10.0, < 2.10.1
Upstream advisory: https://github.com/n8n-io/n8n/security/advisories/GHSA-jjpj-p2wh-qf23
NIXPKGS-2026-0404
published 6 months, 4 weeks ago
Permalink CVE-2025-67601
8.3 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 6 months, 4 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    2 packages
    • terraform-providers.rancher2
    • terraform-providers.rancher_rancher2
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

Rancher CLI skips TLS verification on Rancher CLI login command


github.com/rancher/rancher
  • <2.13.2
  • <2.11.10
  • <2.12.6
  • <2.10.11
  • <0.0.0-20260129092249-bb0625fd1896
Upstream advisory: https://github.com/rancher/rancher/security/advisories/GHSA-mc24-7m59-4q5p
NIXPKGS-2026-0403
published 6 months, 4 weeks ago
Permalink CVE-2026-3172
8.1 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): High (H)
updated 6 months, 4 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    10 packages
    • python312Packages.pgvector
    • python313Packages.pgvector
    • python314Packages.pgvector
    • postgresqlPackages.pgvectorscale
    • postgresql13Packages.pgvectorscale
    • postgresql14Packages.pgvectorscale
    • postgresql15Packages.pgvectorscale
    • postgresql16Packages.pgvectorscale
    • postgresql17Packages.pgvectorscale
    • postgresql18Packages.pgvectorscale
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

pgvector buffer overflow in parallel HNSW index build


pgvector
  • ==0.7.0
  • ==0.6.0
  • <0.8.2
Upstream advisory/issue: https://github.com/pgvector/pgvector/issues/959
NIXPKGS-2026-0401
published 6 months, 4 weeks ago
Permalink CVE-2026-25735
6.1 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): None (N)
updated 6 months, 4 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

Rucio WebUI has a Stored Cross-site Scripting (XSS) vulnerability its Identity Name


rucio
  • ==>= 39.0.0rc1, < 39.3.1
  • ==>= 36.0.0rc1, < 38.5.4
  • ==< 35.8.3
Upstream advisory: https://github.com/rucio/rucio/security/advisories/GHSA-8wpv-6x3f-3rm5
NIXPKGS-2026-0400
published 6 months, 4 weeks ago
Permalink CVE-2026-25736
6.1 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): None (N)
updated 6 months, 4 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

Rucio WebUI has a Stored Cross-site Scripting (XSS) Vulnerability in its Custom RSE Attribute


rucio
  • ==>= 39.0.0rc1, < 39.3.1
  • ==>= 36.0.0rc1, < 38.5.4
  • ==< 35.8.3
Upstream advisory: https://github.com/rucio/rucio/security/advisories/GHSA-fq4f-4738-rqxm
NIXPKGS-2026-0399
published 6 months, 4 weeks ago
Permalink CVE-2026-25734
6.1 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): None (N)
updated 6 months, 4 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

Rucio WebUI has Stored Cross-site Scripting (XSS) in RSE Metadata


rucio
  • ==>= 39.0.0rc1, < 39.3.1
  • ==>= 36.0.0rc1, < 38.5.4
  • ==< 35.8.3
Upstream advisory: https://github.com/rucio/rucio/security/advisories/GHSA-h9fp-p2p9-873q
NIXPKGS-2026-0398
published 6 months, 4 weeks ago
Permalink CVE-2026-25136
8.1 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): None (N)
updated 6 months, 4 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

Rucio WebUI has a Reflected Cross-site Scripting Vulnerability


rucio
  • ==>= 39.0.0rc1, < 39.3.1
  • ==>= 36.0.0rc1, < 38.5.4
  • ==< 35.8.3
Upstream advisory: https://github.com/rucio/rucio/security/advisories/GHSA-h79m-5jjm-jm4q
NIXPKGS-2026-0397
published 6 months, 4 weeks ago
Permalink CVE-2026-25733
7.3 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): None (N)
updated 6 months, 4 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

Rucio WebUI Vulnerable to Stored Cross-site Scripting (XSS) through Custom Rule Function


rucio
  • ==>= 39.0.0rc1, < 39.3.1
  • ==>= 36.0.0rc1, < 38.5.4
  • ==< 35.8.3
Upstream advisory: https://github.com/rucio/rucio/security/advisories/GHSA-rwj9-7j48-9f7q