Nixpkgs Security Tracker

Login with GitHub

Automatically generated suggestions

to queue a suggestion for refinement.

to remove a suggestion from the queue.

created 10 hours ago
PAN-OS: Firewall Denial of Service (DoS) in GlobalProtect Gateway and Portal

A vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to cause a denial of service (DoS) to the firewall. Repeated attempts to trigger this issue results in the firewall entering into maintenance mode.

Affected products

PAN-OS
  • <10.2.18-h1, 10.2.16-h6, 10.2.13-h18, 10.2.10-h30, 10.2.7-h32
  • <11.1.13, 11.1.10-h9, 11.1.6-h23, 11.1.4-h27
  • <12.1.4, 12.1.3-h3
  • <11.2.10-h2, 11.2.7-h8, 11.2.4-h15
  • <10.1.14-h20
Cloud NGFW
  • ==All
Prisma Access
  • <10.2.10-h29
  • <11.2.7-h8

Matching in nixpkgs

pkgs.python312Packages.pan-os-python

Palo Alto Networks PAN-OS SDK for Python

pkgs.python313Packages.pan-os-python

Palo Alto Networks PAN-OS SDK for Python

Package maintainers: 1

CVE-2026-0861
8.4 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): HIGH
created 10 hours ago
Integer overflow in memalign leads to heap corruption

Passing too large an alignment to the memalign suite of functions (memalign, posix_memalign, aligned_alloc, valloc, pvalloc) in the GNU C Library version 2.30 to 2.42 may result in an integer overflow, which could consequently result in a heap corruption.

Affected products

glibc
  • =<2.42

Matching in nixpkgs

pkgs.mtrace

Perl script used to interpret and provide human readable output of the trace log contained in the file mtracedata, whose contents were produced by mtrace(3)

pkgs.tests.hardeningFlags-gcc.glibcxxassertionsStdenvUnsupp

None

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small

pkgs.tests.hardeningFlags-clang.glibcxxassertionsStdenvUnsupp

None

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small

pkgs.tests.hardeningFlags-gcc.glibcxxassertionsExplicitEnabled

None

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small

pkgs.tests.hardeningFlags.allExplicitDisabledGlibcxxAssertions

None

  • nixos-unstable -
    • nixpkgs-unstable

pkgs.tests.hardeningFlags-gcc.glibcxxassertionsExplicitDisabled

None

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small

pkgs.tests.hardeningFlags-clang.glibcxxassertionsExplicitEnabled

None

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small

pkgs.tests.hardeningFlags-clang.glibcxxassertionsExplicitDisabled

None

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small

pkgs.tests.hardeningFlags-gcc.allExplicitDisabledGlibcxxAssertions

None

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small

pkgs.tests.hardeningFlags-clang.allExplicitDisabledGlibcxxAssertions

None

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small

Package maintainers: 2

CVE-2026-21281
7.8 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): REQUIRED
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): HIGH
created 10 hours ago
InCopy | Heap-based Buffer Overflow (CWE-122)

InCopy versions 21.0, 19.5.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Affected products

InCopy
  • =<19.5.5

Matching in nixpkgs

pkgs.python312Packages.bincopy

Mangling of various file formats that conveys binary information (Motorola S-Record, Intel HEX, TI-TXT, ELF and binary files)

pkgs.python313Packages.bincopy

Mangling of various file formats that conveys binary information (Motorola S-Record, Intel HEX, TI-TXT, ELF and binary files)

Package maintainers: 2

created 10 hours ago
Multiple vulnerabilities in Viafirma products

IDOR vulnerability has been found in Viafirma Inbox v4.5.13 that allows any authenticated user without privileges in the application to list all users, access and modify their data. This allows the user's email addresses to be modified and, subsequently, using the password recovery functionality to access the application by impersonating any user, including those with administrative permissions.

Affected products

Inbox
  • ==v4.5.13

Matching in nixpkgs

pkgs.winbox

Graphical configuration utility for RouterOS-based devices

pkgs.winbox3

Graphical configuration utility for RouterOS-based devices

pkgs.python312Packages.pywinbox

Cross-Platform and multi-monitor toolkit to handle rectangular areas and windows box

pkgs.python313Packages.pywinbox

Cross-Platform and multi-monitor toolkit to handle rectangular areas and windows box

pkgs.python312Packages.beanhub-inbox

Email processing engine for archiving and extracting financial data with LLM

pkgs.python313Packages.beanhub-inbox

Email processing engine for archiving and extracting financial data with LLM

Package maintainers: 11

CVE-2026-0992
2.9 LOW
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): HIGH
  • Privileges required (PR): NONE
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): NONE
  • Integrity impact (I): NONE
  • Availability impact (A): LOW
created 12 hours ago
Libxml2: libxml2: denial of service via crafted xml catalogs

A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs when processing XML catalogs that contain repeated <nextCatalog> elements pointing to the same downstream catalog. A remote attacker can exploit this by supplying crafted catalogs, causing the parser to redundantly traverse catalog chains. This leads to excessive CPU consumption and degrades application availability, resulting in a denial-of-service condition.

Affected products

rhcos
libxml2

Matching in nixpkgs

pkgs.tests.pkg-config.defaultPkgConfigPackages."libxml-2.0"

Test whether libxml2-2.13.8 exposes pkg-config modules libxml-2.0

Package maintainers: 7

CVE-2026-0989
3.7 LOW
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): HIGH
  • Privileges required (PR): NONE
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): NONE
  • Integrity impact (I): NONE
  • Availability impact (A): LOW
created 12 hours ago
Libxml2: unbounded relaxng include recursion leading to stack overflow

A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving nested <include> directives. Specially crafted or overly complex schemas can cause excessive recursion during parsing. This may lead to stack exhaustion and application crashes, creating a denial-of-service risk.

Affected products

rhcos
libxml2

Matching in nixpkgs

pkgs.tests.pkg-config.defaultPkgConfigPackages."libxml-2.0"

Test whether libxml2-2.13.8 exposes pkg-config modules libxml-2.0

Package maintainers: 7

CVE-2026-0990
5.9 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): HIGH
  • Privileges required (PR): NONE
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): NONE
  • Integrity impact (I): NONE
  • Availability impact (A): HIGH
created 12 hours ago
Libxml2: libxml2: denial of service via uncontrolled recursion in xml catalog processing

A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogXMLResolveURI function when an XML catalog contains a delegate URI entry that references itself. A remote attacker could exploit this configuration-dependent issue by providing a specially crafted XML catalog, leading to infinite recursion and call stack exhaustion. This ultimately results in a segmentation fault, causing a Denial of Service (DoS) by crashing affected applications.

Affected products

rhcos
libxml2

Matching in nixpkgs

pkgs.tests.pkg-config.defaultPkgConfigPackages."libxml-2.0"

Test whether libxml2-2.13.8 exposes pkg-config modules libxml-2.0

Package maintainers: 7

created 1 day, 17 hours ago
Polkit authentication dis isabled by default in inputplumber

Polkit authentication dis isabled by default and a race condition in the Polkit authorization check in versions before v0.69.0 can lead to the same issues as in CVE-2025-66005.

Affected products

inputplumber
  • <0.63.0

Matching in nixpkgs

Package maintainers: 1

created 1 day, 17 hours ago
Lack of Authentication in the InputManager D-Bus interface

Lack of authorization of the InputManager D-Bus interface in InputPlumber versions before v0.63.0 can lead to local Denial-of-Service, information leak or even privilege escalation in the context of the currently active user session.

Affected products

inputplumber
  • <0.63.0

Matching in nixpkgs

Package maintainers: 1

CVE-2025-14242
6.5 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): NONE
  • Integrity impact (I): NONE
  • Availability impact (A): HIGH
created 1 day, 17 hours ago
Vsftpd: vsftpd: denial of service via integer overflow in ls command parameter parsing

A flaw was found in vsftpd. This vulnerability allows a denial of service (DoS) via an integer overflow in the ls command parameter parsing, triggered by a remote, authenticated attacker sending a crafted STAT command with a specific byte sequence.

Affected products

vsftpd
  • *

Matching in nixpkgs

Package maintainers: 1