Nixpkgs security tracker

Try the new UI
Login with GitHub

Published issues

All published security issues are tracked and resolved on GitHub.

NIXPKGS-2026-0361
published 7 months ago
Permalink CVE-2026-26955
8.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 7 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

FreeRDP has Out-of-bounds Write


FreeRDP
  • ==< 3.23.0
Upstream advisory: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-mr6w-ch7c-mqqj
Upstream patch: https://github.com/FreeRDP/FreeRDP/commit/7d8fdce2d0ef337cb86cb37fc0c436c905e04d77
NIXPKGS-2026-0359
published 7 months ago
updated 7 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

FreeRDP has global-buffer-overflow in xf_rail_server_execute_result


FreeRDP
  • ==< 3.23.0
Upstream advisory: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-78q6-67m7-wwf6
Upstream patch: https://github.com/FreeRDP/FreeRDP/commit/9362a0bf8dda04eedbca07d5dfaec1044e67cc6b
NIXPKGS-2026-0357
published 7 months ago
updated 7 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    7 packages
    • xcaddy
    • caddyfile-language-server
    • vimPlugins.nvim-treesitter-parsers.caddy
    • tree-sitter-grammars.tree-sitter-caddyfile
    • vscode-extensions.matthewpi.caddyfile-support
    • python313Packages.tree-sitter-grammars.tree-sitter-caddyfile
    • python314Packages.tree-sitter-grammars.tree-sitter-caddyfile
  • @LeSuisse accepted
  • @LeSuisse deleted
    4 maintainers
    • @ryan4yin
    • @techknowlogick
    • @Br1ght0ne
    • @stepbrobd
    maintainer.delete
  • @LeSuisse published on GitHub

Caddy: Unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FastCGI transport


caddy
  • ==< 2.11.1
Upstream advisory: https://github.com/caddyserver/caddy/security/advisories/GHSA-5r3v-vc8m-m96g
NIXPKGS-2026-0356
published 7 months ago
updated 7 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    7 packages
    • xcaddy
    • caddyfile-language-server
    • vimPlugins.nvim-treesitter-parsers.caddy
    • tree-sitter-grammars.tree-sitter-caddyfile
    • vscode-extensions.matthewpi.caddyfile-support
    • python313Packages.tree-sitter-grammars.tree-sitter-caddyfile
    • python314Packages.tree-sitter-grammars.tree-sitter-caddyfile
  • @LeSuisse accepted
  • @LeSuisse deleted
    4 maintainers
    • @ryan4yin
    • @techknowlogick
    • @Br1ght0ne
    • @stepbrobd
    maintainer.delete
  • @LeSuisse published on GitHub

Caddy: MatchHost becomes case-sensitive for large host lists (>100), enabling host-based route/auth bypass


caddy
  • ==< 2.11.1
Upstream advisory: https://github.com/caddyserver/caddy/security/advisories/GHSA-x76f-jf84-rqj8
NIXPKGS-2026-0355
published 7 months ago
updated 7 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    7 packages
    • xcaddy
    • caddyfile-language-server
    • vimPlugins.nvim-treesitter-parsers.caddy
    • tree-sitter-grammars.tree-sitter-caddyfile
    • vscode-extensions.matthewpi.caddyfile-support
    • python313Packages.tree-sitter-grammars.tree-sitter-caddyfile
    • python314Packages.tree-sitter-grammars.tree-sitter-caddyfile
  • @LeSuisse accepted
  • @LeSuisse deleted
    4 maintainers
    • @ryan4yin
    • @techknowlogick
    • @Br1ght0ne
    • @stepbrobd
    maintainer.delete
  • @LeSuisse published on GitHub

Caddy's mTLS client authentication silently fails open when CA certificate file is missing or malformed


caddy
  • ==< 2.11.1
Upstream advisory: https://github.com/caddyserver/caddy/security/advisories/GHSA-hffm-g8v7-wrv7
NIXPKGS-2026-0354
published 7 months ago
updated 7 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    7 packages
    • xcaddy
    • caddyfile-language-server
    • vimPlugins.nvim-treesitter-parsers.caddy
    • tree-sitter-grammars.tree-sitter-caddyfile
    • vscode-extensions.matthewpi.caddyfile-support
    • python313Packages.tree-sitter-grammars.tree-sitter-caddyfile
    • python314Packages.tree-sitter-grammars.tree-sitter-caddyfile
  • @LeSuisse accepted
  • @LeSuisse deleted
    4 maintainers
    • @ryan4yin
    • @techknowlogick
    • @Br1ght0ne
    • @stepbrobd
    maintainer.delete
  • @LeSuisse published on GitHub

Caddy's improper sanitization of glob characters in file matcher may lead to bypassing security protections


caddy
  • ==< 2.11.1
Upstream advisory: https://github.com/caddyserver/caddy/security/advisories/GHSA-4xrr-hq4w-6vf4
NIXPKGS-2026-0353
published 7 months ago
updated 7 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    7 packages
    • xcaddy
    • caddyfile-language-server
    • vimPlugins.nvim-treesitter-parsers.caddy
    • tree-sitter-grammars.tree-sitter-caddyfile
    • vscode-extensions.matthewpi.caddyfile-support
    • python313Packages.tree-sitter-grammars.tree-sitter-caddyfile
    • python314Packages.tree-sitter-grammars.tree-sitter-caddyfile
  • @LeSuisse accepted
  • @LeSuisse deleted
    4 maintainers
    • @ryan4yin
    • @techknowlogick
    • @Br1ght0ne
    • @stepbrobd
    maintainer.delete
  • @LeSuisse published on GitHub

Caddy vulnerable to cross-origin config application via local admin API /load (caddy)


caddy
  • ==< 2.11.1
Upstream advisory: https://github.com/caddyserver/caddy/security/advisories/GHSA-879p-475x-rqh2
NIXPKGS-2026-0352
published 7 months ago
updated 7 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    7 packages
    • python314Packages.tree-sitter-grammars.tree-sitter-caddyfile
    • python313Packages.tree-sitter-grammars.tree-sitter-caddyfile
    • vscode-extensions.matthewpi.caddyfile-support
    • tree-sitter-grammars.tree-sitter-caddyfile
    • vimPlugins.nvim-treesitter-parsers.caddy
    • caddyfile-language-server
    • xcaddy
  • @LeSuisse accepted
  • @LeSuisse deleted
    4 maintainers
    • @ryan4yin
    • @Br1ght0ne
    • @techknowlogick
    • @stepbrobd
    maintainer.delete
  • @LeSuisse published on GitHub

Caddy: MatchPath %xx (escaped-path) branch skips case normalization, enabling path-based route/auth bypass


caddy
  • ==< 2.11.1
Upstream advisory: https://github.com/caddyserver/caddy/security/advisories/GHSA-g7pc-pc7g-h8jh
NIXPKGS-2026-0351
published 7 months ago
Permalink CVE-2026-27624
7.2 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
updated 7 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse accepted
  • @LeSuisse deleted maintainer @0x4A6F maintainer.delete
  • @LeSuisse published on GitHub

Coturn: IPv4-mapped IPv6 (::ffff:0:0/96) bypasses denied-peer-ip ACL


coturn
  • ==< 4.9.0
Upstream advisory: https://github.com/coturn/coturn/security/advisories/GHSA-j8mm-mpf8-gvjg
NIXPKGS-2026-0350
published 7 months ago
Permalink CVE-2026-3209
6.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): Low (L)
  • Exploit Code Maturity (E): Proof-of-Concept (P)
  • Remediation Level (RL): Official Fix (O)
  • Report Confidence (RC): Confirmed (C)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): Low (L)
updated 7 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    2 packages
    • pangolin
    • pangolin-cli
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

fosrl Pangolin Role verifyApiKeyRoleAccess access control


Pangolin
  • ==1.15.4-s.1
  • ==1.15.4-s.3
  • ==1.15.4-s.0
  • ==1.15.4-s.2
  • ==1.15.4-s.4
Upstream patch: https://github.com/fosrl/pangolin/commit/5e37c4e85fae68e756be5019a28ca903b161fdd5