Nixpkgs security tracker

Try the new UI
Login with GitHub

Published issues

All published security issues are tracked and resolved on GitHub.

NIXPKGS-2026-0459
published 7 months ago
Permalink CVE-2026-25967
7.4 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 7 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    3 packages
    • tests.pkg-config.defaultPkgConfigPackages.ImageMagick
    • tests.pkg-config.defaultPkgConfigPackages.MagickWand
    • graphicsmagick-imagemagick-compat
  • @LeSuisse deleted
    3 maintainers
    • @faukah
    • @rhendric
    • @dotlambda
    maintainer.delete
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

ImageMagick has stack buffer overflow in FTXT reader via oversized integer field


ImageMagick
  • ==< 7.1.2-15
NIXPKGS-2026-0460
published 7 months ago
Permalink CVE-2026-25968
7.4 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): High (H)
updated 7 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    3 packages
    • tests.pkg-config.defaultPkgConfigPackages.ImageMagick
    • tests.pkg-config.defaultPkgConfigPackages.MagickWand
    • graphicsmagick-imagemagick-compat
  • @LeSuisse deleted
    3 maintainers
    • @faukah
    • @rhendric
    • @dotlambda
    maintainer.delete
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

ImageMagick has MSL attribute stack buffer overflow that leads to out of bounds write.


ImageMagick
  • ==>= 7.0.0, < 7.1.2-15
  • ==< 6.9.13-40
NIXPKGS-2026-0461
published 7 months ago
Permalink CVE-2026-25798
5.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): Low (L)
updated 7 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    3 packages
    • tests.pkg-config.defaultPkgConfigPackages.ImageMagick
    • tests.pkg-config.defaultPkgConfigPackages.MagickWand
    • graphicsmagick-imagemagick-compat
  • @LeSuisse deleted
    3 maintainers
    • @faukah
    • @rhendric
    • @dotlambda
    maintainer.delete
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

ImageMagick has NULL Pointer Dereference in ClonePixelCacheRepository via crafted image


ImageMagick
  • ==>= 7.0.0, < 7.1.2-15
  • ==< 6.9.13-40
NIXPKGS-2026-0329
published 7 months ago
updated 7 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

LibreNMS affected by reflected XSS via email field


librenms
  • ==< 26.2.0
Upstream advisory: https://github.com/librenms/librenms/security/advisories/GHSA-gqx7-99jw-6fpr
Upstream patch: https://github.com/librenms/librenms/commit/8e626b38ef92e240532cdac2ac7e38706a71208b
NIXPKGS-2026-0321
published 7 months ago
updated 7 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    28 packages
    • zigimports
    • gimpPlugins.bimp
    • gimpPlugins.gimp
    • gimpPlugins.gmic
    • gimp-with-plugins
    • gimp2Plugins.bimp
    • gimp2Plugins.gimp
    • gimp2Plugins.gmic
    • gimp3Plugins.gimp
    • gimp3Plugins.gmic
    • gimp2-with-plugins
    • gimp3-with-plugins
    • gimpPlugins.fourier
    • gimp2Plugins.fourier
    • gimpPlugins.farbfeld
    • gimp2Plugins.farbfeld
    • gimpPlugins.lightning
    • gimpPlugins.lqrPlugin
    • gimpPlugins.texturize
    • gimp2Plugins.lightning
    • gimp2Plugins.lqrPlugin
    • gimp2Plugins.texturize
    • gimp3Plugins.lightning
    • gimpPlugins.gimplensfun
    • gimp2Plugins.gimplensfun
    • gimpPlugins.resynthesizer
    • gimpPlugins.waveletSharpen
    • gimp2Plugins.waveletSharpen
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

GIMP ICNS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability


GIMP
  • ==3.0.6
Upstream issue: https://gitlab.gnome.org/GNOME/gimp/-/issues/15437
Upstream patches:
* https://gitlab.gnome.org/GNOME/gimp/-/commit/dd2faac351f1ff2588529fedc606e6a5f815577c (master)
* https://gitlab.gnome.org/GNOME/gimp/-/commit/5873e16f80cf4152d25a4c86b08553008a331e90 (gimp-3-0)
NIXPKGS-2026-0324
published 7 months ago
Permalink CVE-2026-26045
7.2 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 7 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored package moodle-dl
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

Moodle: moodle: improper validation in file restore functionality leading to remote code execution


moodle
  • <4.5.9
  • <5.0.5
  • <5.1.2
Upstream advisory: https://moodle.org/mod/forum/discuss.php?d=473314#p1896305
NIXPKGS-2026-0320
published 7 months ago
updated 7 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    28 packages
    • gimp2Plugins.waveletSharpen
    • gimpPlugins.waveletSharpen
    • gimpPlugins.resynthesizer
    • gimp2Plugins.gimplensfun
    • gimpPlugins.gimplensfun
    • gimp3Plugins.lightning
    • gimp2Plugins.texturize
    • gimp2Plugins.lqrPlugin
    • gimp2Plugins.lightning
    • gimpPlugins.texturize
    • gimpPlugins.lqrPlugin
    • gimpPlugins.lightning
    • gimp2Plugins.farbfeld
    • gimpPlugins.farbfeld
    • gimpPlugins.fourier
    • gimp3-with-plugins
    • gimp2-with-plugins
    • gimp3Plugins.gmic
    • gimp3Plugins.gimp
    • gimp2Plugins.gmic
    • gimp2Plugins.gimp
    • gimp2Plugins.fourier
    • gimp2Plugins.bimp
    • gimp-with-plugins
    • gimpPlugins.gmic
    • gimpPlugins.gimp
    • gimpPlugins.bimp
    • zigimports
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

GIMP ICO File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability


GIMP
  • ==3.2.0-RC1
Upstream issue: https://gitlab.gnome.org/GNOME/gimp/-/issues/15555
Upstream patches:
* master:
  - https://gitlab.gnome.org/GNOME/gimp/-/commit/c54bf22acb04b83ae38ed50add58f300e898dd81
  - https://gitlab.gnome.org/GNOME/gimp/-/commit/905ce4b48782c5e71c79714b7ba7f6ebe4d0329d
* gimp-3-0:
  - https://gitlab.gnome.org/GNOME/gimp/-/commit/ca449c745d58daa3f4b1ed4c2030d35d401a009d
  - https://gitlab.gnome.org/GNOME/gimp/-/commit/13849c5a9a65c2366c47f703d9d075e4bfb83525
NIXPKGS-2026-0331
published 7 months ago
updated 7 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

LibreNMS vulnerable to Stored Cross-site Scripting through unsanitized /device-groups name


librenms
  • ==< 26.2.0
Upstream advisory: https://github.com/librenms/librenms/security/advisories/GHSA-5pqf-54qp-32wx
Upstream patch: https://github.com/librenms/librenms/commit/64b31da444369213eb4559ec1c304ebfaa0ba12c
NIXPKGS-2026-0332
published 7 months ago
updated 7 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

LibreNMS has Stored Cross-Site Scripting via unsanitized /port-groups name


librenms
  • ==< 26.2.0
Upstream advisory: https://github.com/librenms/librenms/security/advisories/GHSA-93fx-g747-695x
Upstream patch: https://github.com/librenms/librenms/commit/882fe6f90ea504a3732f83caf89bba7850a5699f
NIXPKGS-2026-0333
published 7 months ago
Permalink CVE-2026-27016
5.4 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): Required (R)
  • Scope (S): Changed (C)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
updated 7 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

LibreNMS has Stored XSS in Custom OID - unit parameter missing strip_tags()


librenms
  • ==>= 24.10.0, < 26.2.0
Upstream advisory: https://github.com/librenms/librenms/security/advisories/GHSA-fqx6-693c-f55g
Upstream patch: https://github.com/librenms/librenms/commit/3bea263e02441690c01dea7fa3fe6ffec94af335