Nixpkgs security tracker

Try the new UI
Login with GitHub

Published issues

All published security issues are tracked and resolved on GitHub.

NIXPKGS-2026-0377
published 6 months, 4 weeks ago
updated 6 months, 4 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

Wasmtime is vulnerable to panic when dropping a `[Typed]Func::call_async` future


wasmtime
  • ==>= 41.0.0, < 41.0.4
  • ==>= 39.0.0, < 40.0.4
Upstream advisory: https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-xjhv-v822-pf94
NIXPKGS-2026-0376
published 6 months, 4 weeks ago
updated 6 months, 4 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

Wasmtime can panic when adding excessive fields to a `wasi:http/types.fields` instance


wasmtime
  • ==>= 41.0.0, < 41.0.4
  • ==< 24.0.6
  • ==>= 25.0.0, < 36.0.6
  • ==>= 37.0.0, < 40.0.4
Upstream advisory: https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-243v-98vx-264h
NIXPKGS-2026-0375
published 6 months, 4 weeks ago
Permalink CVE-2026-3102
6.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): Low (L)
  • Exploit Code Maturity (E): Proof-of-Concept (P)
  • Remediation Level (RL): Official Fix (O)
  • Report Confidence (RC): Confirmed (C)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): Low (L)
updated 6 months, 4 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    8 packages
    • haskellPackages.exiftool
    • perlPackages.ImageExifTool
    • perl5Packages.ImageExifTool
    • python312Packages.pyexiftool
    • python313Packages.pyexiftool
    • python314Packages.pyexiftool
    • perl538Packages.ImageExifTool
    • perl540Packages.ImageExifTool
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

exiftool PNG File MacOS.pm SetMacOSTags os command injection


exiftool
  • ==13.17
  • ==13.43
  • ==13.42
  • ==13.41
  • ==13.19
  • ==13.22
  • ==13.36
  • ==13.4
  • ==13.30
  • ==13.11
  • ==13.44
  • ==13.10
  • ==13.40
  • ==13.13
  • ==13.47
  • ==13.29
  • ==13.14
  • ==13.46
  • ==13.20
  • ==13.48
  • ==13.15
  • ==13.5
  • ==13.28
  • ==13.3
  • ==13.16
  • ==13.35
  • ==13.27
  • ==13.50
  • ==13.24
  • ==13.49
  • ==13.21
  • ==13.2
  • ==13.34
  • ==13.6
  • ==13.7
  • ==13.8
  • ==13.0
  • ==13.31
  • ==13.1
  • ==13.12
  • ==13.32
  • ==13.45
  • ==13.33
  • ==13.26
  • ==13.18
  • ==13.9
  • ==13.23
  • ==13.25
  • ==13.37
  • ==13.38
  • ==13.39
Upstream patch: https://github.com/exiftool/exiftool/commit/e9609a9bcc0d32bd252a709a562fb822d6dd86f7
NIXPKGS-2026-0374
published 6 months, 4 weeks ago
Permalink CVE-2025-27555
6.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
updated 6 months, 4 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

Apache Airflow: Connection Secrets not masked in UI when Connection are added via Airflow cli


apache-airflow
  • <2.11.1
Upstream announcement: https://lists.apache.org/thread/nxovkp319jo8vg498gql1yswtb2frbkw
Upstream patch: https://github.com/apache/airflow/commit/3adfc6c40ef552608c9fc05e01b27ef3cac5006a
NIXPKGS-2026-0373
published 6 months, 4 weeks ago
Permalink CVE-2026-27951
5.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): Low (L)
updated 6 months, 4 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

FreeRDP has possible Integer overflow in Stream_EnsureCapacity


FreeRDP
  • ==< 3.23.0
Upstream advisory: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-qcfc-ghxr-h927
Upstream patch: https://github.com/FreeRDP/FreeRDP/commit/118afc0b954ba9d5632b7836ad24e454555ed113
NIXPKGS-2026-0372
published 6 months, 4 weeks ago
Permalink CVE-2026-27156
6.1 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Changed (C)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
updated 6 months, 4 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    3 packages
    • python312Packages.nicegui-highcharts
    • python313Packages.nicegui-highcharts
    • python314Packages.nicegui-highcharts
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

NiceGUI has XSS via Code Injection


nicegui
  • ==< 3.8.0
Upstream advisory: https://github.com/zauberzeug/nicegui/security/advisories/GHSA-78qv-3mpx-9cqq
Upstream patch: https://github.com/zauberzeug/nicegui/commit/1861f59cc374ca0dc9d970b157ef3774720f8dbf
NIXPKGS-2026-0371
published 6 months, 4 weeks ago
updated 6 months, 4 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

FreeRDP has heap-use-after-free in xf_clipboard_format_equal


FreeRDP
  • ==< 3.23.0
Upstream advisory: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-q5j3-m6jf-3jq4
Upstream patch: https://github.com/FreeRDP/FreeRDP/commit/58409406afe7c2a8a71ed2dc8e22075be4f41c0c
NIXPKGS-2026-0370
published 6 months, 4 weeks ago
updated 6 months, 4 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

FreeRDP: Smartcard NDR Alignment Padding Triggers Reachable WINPR_ASSERT Abort (Client DoS)


FreeRDP
  • ==< 3.23.0
Upstream advisory: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-7g72-39pq-4725
Upstream patch: https://github.com/FreeRDP/FreeRDP/commit/65d59d3b3c2f630f2ea862687ecf5f95f8115244
NIXPKGS-2026-0369
published 6 months, 4 weeks ago
updated 6 months, 4 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

FreeRDP has heap-use-after-free in rail_window_free


FreeRDP
  • ==< 3.23.0
Upstream advisory: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-crqx-g6x5-rx47
Upstream patch: https://github.com/FreeRDP/FreeRDP/commit/b4f0f0a18fe53aa8d47d062f91471f4e9c5e0d51
NIXPKGS-2026-0368
published 6 months, 4 weeks ago
updated 6 months, 4 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

FreeRDP has heap-use-after-free in xf_AppUpdateWindowFromSurface (freed appWindow)


FreeRDP
  • ==< 3.23.0
Upstream advisory: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-p6rq-rxpc-rh3p
Upstream patch: https://github.com/FreeRDP/FreeRDP/commit/1994e9844212a6dfe0ff12309fef520e888986b5