Nixpkgs Security Tracker

Login with GitHub

Automatically generated suggestions

to queue a suggestion for refinement.

to remove a suggestion from the queue.

created an hour ago
pymumu SmartDNS SVBC Record dns.c _dns_decode_SVCB_HTTPS stack-based overflow

A security flaw has been discovered in pymumu SmartDNS up to 47.1. This vulnerability affects the function _dns_decode_rr_head/_dns_decode_SVCB_HTTPS of the file src/dns.c of the component SVBC Record Parser. The manipulation results in stack-based buffer overflow. It is possible to launch the attack remotely. A high complexity level is associated with this attack. It is stated that the exploitability is difficult. The patch is identified as 2d57c4b4e1add9b4537aeb403f794a084727e1c8. Applying a patch is advised to resolve this issue.

Affected products

SmartDNS
  • ==47.1
  • ==47.0

Matching in nixpkgs

pkgs.smartdns

A local DNS server to obtain the fastest website IP for the best Internet experience

Package maintainers: 1

created an hour ago
GPAC filedump.c dump_isom_rtp null pointer dereference

A weakness has been identified in GPAC up to 2.4.0. Affected by this issue is the function dump_isom_rtp of the file applications/mp4box/filedump.c. This manipulation causes null pointer dereference. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. Patch name: f96bd57c3ccdcde4335a0be28cd3e8fe296993de. Applying a patch is the recommended action to fix this issue.

Affected products

GPAC
  • ==2.1
  • ==2.2
  • ==2.3
  • ==2.0
  • ==2.4.0

Matching in nixpkgs

pkgs.gpac

Open Source multimedia framework for research and academic purposes

pkgs.msgpack

MessagePack implementation for C and C++

pkgs.msgpack-tools

Command-line tools for converting between MessagePack and JSON

pkgs.phpExtensions.msgpack

PHP extension for interfacing with MessagePack

pkgs.haskellPackages.msgpack

A Haskell implementation of MessagePack

pkgs.perlPackages.MsgPackRaw

Perl bindings to the msgpack C library

pkgs.php81Extensions.msgpack

PHP extension for interfacing with MessagePack

pkgs.php82Extensions.msgpack

PHP extension for interfacing with MessagePack

pkgs.php83Extensions.msgpack

PHP extension for interfacing with MessagePack

pkgs.php84Extensions.msgpack

PHP extension for interfacing with MessagePack

pkgs.rubyPackages_3_1.msgpack

None

pkgs.rubyPackages_3_2.msgpack

None

pkgs.rubyPackages_3_5.msgpack

None

pkgs.python312Packages.msgpack

MessagePack serializer implementation

pkgs.python313Packages.msgpack

MessagePack serializer implementation

pkgs.lua52Packages.lua-cmsgpack

MessagePack C implementation and bindings for Lua 5.1/5.2/5.3

pkgs.perl538Packages.MsgPackRaw

Perl bindings to the msgpack C library

pkgs.perl540Packages.MsgPackRaw

Perl bindings to the msgpack C library

pkgs.python312Packages.ormsgpack

Fast msgpack serialization library for Python derived from orjson

pkgs.python313Packages.ormsgpack

Fast msgpack serialization library for Python derived from orjson

pkgs.python312Packages.msgpack-numpy

Numpy data type serialization using msgpack

pkgs.python313Packages.msgpack-numpy

Numpy data type serialization using msgpack

pkgs.haskellPackages.data-msgpack-types

A Haskell implementation of MessagePack

pkgs.python312Packages.u-msgpack-python

Portable, lightweight MessagePack serializer and deserializer written in pure Python

pkgs.python313Packages.u-msgpack-python

Portable, lightweight MessagePack serializer and deserializer written in pure Python

pkgs.chickenPackages_5.chickenEggs.msgpack

MessagePack implementation for CHICKEN

Package maintainers: 12

created an hour ago
pnpm: Binary ZIP extraction allows arbitrary file write via path traversal (Zip Slip)

pnpm is a package manager. Prior to version 10.28.1, a path traversal vulnerability in pnpm's binary fetcher allows malicious packages to write files outside the intended extraction directory. The vulnerability has two attack vectors: (1) Malicious ZIP entries containing `../` or absolute paths that escape the extraction root via AdmZip's `extractAllTo`, and (2) The `BinaryResolution.prefix` field is concatenated into the extraction path without validation, allowing a crafted prefix like `../../evil` to redirect extracted files outside `targetDir`. The issue impacts all pnpm users who install packages with binary assets, users who configure custom Node.js binary locations and CI/CD pipelines that auto-install binary dependencies. It can lead to overwriting config files, scripts, or other sensitive files leading to RCE. Version 10.28.1 contains a patch.

Affected products

pnpm
  • ==< 10.28.1

Matching in nixpkgs

Package maintainers: 3

created an hour ago
ping in iputils through 20240905 allows a denial of service …

ping in iputils through 20240905 allows a denial of service (application error or incorrect data collection) via a crafted ICMP Echo Reply packet, because of a signed 64-bit integer overflow in timestamp multiplication.

Affected products

iputils
  • <20250602
  • =<20240905

Matching in nixpkgs

Package maintainers: 1

created an hour ago
In Alinto SOPE SOGo 2.0.2 through 5.12.2, sope-core/NGExtensions/NGHashMap.m allows a …

In Alinto SOPE SOGo 2.0.2 through 5.12.2, sope-core/NGExtensions/NGHashMap.m allows a NULL pointer dereference and SOGo crash via a request in which a parameter in the query string is a duplicate of a parameter in the POST body.

Affected products

SOPE
  • =<5.12.2

Matching in nixpkgs

pkgs.sope

Extensive set of frameworks which form a complete Web application server environment

pkgs.mediastreamer-openh264

H.264 encoder/decoder plugin for mediastreamer2. Part of the Linphone project

pkgs.linphonePackages.msopenh264

H.264 encoder/decoder plugin for mediastreamer2. Part of the Linphone project

Package maintainers: 4

created an hour ago
pnpm has Windows-specific tarball Path Traversal

pnpm is a package manager. Prior to version 10.28.1, a path traversal vulnerability in pnpm's tarball extraction allows malicious packages to write files outside the package directory on Windows. The path normalization only checks for `./` but not `.\`. On Windows, backslashes are directory separators, enabling path traversal. This vulnerability is Windows-only. This issue impacts Windows pnpm users and Windows CI/CD pipelines (GitHub Actions Windows runners, Azure DevOps). It can lead to overwriting `.npmrc`, build configs, or other files. Version 10.28.1 contains a patch.

Affected products

pnpm
  • ==< 10.28.1

Matching in nixpkgs

Package maintainers: 3

created an hour ago
GPAC media_export.c gf_media_export_webvtt_metadata null pointer dereference

A vulnerability was identified in GPAC up to 2.4.0. Affected is the function gf_media_export_webvtt_metadata of the file src/media_tools/media_export.c. The manipulation of the argument Name leads to null pointer dereference. The attack must be carried out locally. The exploit is publicly available and might be used. The identifier of the patch is af951b892dfbaaa38336ba2eba6d6a42c25810fd. To fix this issue, it is recommended to deploy a patch.

Affected products

GPAC
  • ==2.1
  • ==2.2
  • ==2.3
  • ==2.0
  • ==2.4.0

Matching in nixpkgs

pkgs.gpac

Open Source multimedia framework for research and academic purposes

pkgs.msgpack

MessagePack implementation for C and C++

pkgs.msgpack-tools

Command-line tools for converting between MessagePack and JSON

pkgs.phpExtensions.msgpack

PHP extension for interfacing with MessagePack

pkgs.haskellPackages.msgpack

A Haskell implementation of MessagePack

pkgs.perlPackages.MsgPackRaw

Perl bindings to the msgpack C library

pkgs.php81Extensions.msgpack

PHP extension for interfacing with MessagePack

pkgs.php82Extensions.msgpack

PHP extension for interfacing with MessagePack

pkgs.php83Extensions.msgpack

PHP extension for interfacing with MessagePack

pkgs.php84Extensions.msgpack

PHP extension for interfacing with MessagePack

pkgs.rubyPackages_3_1.msgpack

None

pkgs.rubyPackages_3_2.msgpack

None

pkgs.rubyPackages_3_5.msgpack

None

pkgs.python312Packages.msgpack

MessagePack serializer implementation

pkgs.python313Packages.msgpack

MessagePack serializer implementation

pkgs.lua52Packages.lua-cmsgpack

MessagePack C implementation and bindings for Lua 5.1/5.2/5.3

pkgs.perl538Packages.MsgPackRaw

Perl bindings to the msgpack C library

pkgs.perl540Packages.MsgPackRaw

Perl bindings to the msgpack C library

pkgs.python312Packages.ormsgpack

Fast msgpack serialization library for Python derived from orjson

pkgs.python313Packages.ormsgpack

Fast msgpack serialization library for Python derived from orjson

pkgs.python312Packages.msgpack-numpy

Numpy data type serialization using msgpack

pkgs.python313Packages.msgpack-numpy

Numpy data type serialization using msgpack

pkgs.haskellPackages.data-msgpack-types

A Haskell implementation of MessagePack

pkgs.python312Packages.u-msgpack-python

Portable, lightweight MessagePack serializer and deserializer written in pure Python

pkgs.python313Packages.u-msgpack-python

Portable, lightweight MessagePack serializer and deserializer written in pure Python

pkgs.chickenPackages_5.chickenEggs.msgpack

MessagePack implementation for CHICKEN

Package maintainers: 12

created an hour ago
pnpm has Path Traversal via arbitrary file permission modification

pnpm is a package manager. Prior to version 10.28.2, when pnpm processes a package's `directories.bin` field, it uses `path.join()` without validating the result stays within the package root. A malicious npm package can specify `"directories": {"bin": "../../../../tmp"}` to escape the package directory, causing pnpm to chmod 755 files at arbitrary locations. This issue only affects Unix/Linux/macOS. Windows is not affected (`fixBin` gated by `EXECUTABLE_SHEBANG_SUPPORTED`). Version 10.28.2 contains a patch.

Affected products

pnpm
  • ==< 10.28.2

Matching in nixpkgs

Package maintainers: 3

created an hour ago
Github.com/go-viper/mapstructure/v2: go-viper's mapstructure may leak sensitive information in logs in github.com/go-viper/mapstructure

A flaw was found in github.com/go-viper/mapstructure/v2, in the field processing component using mapstructure.WeakDecode. This vulnerability allows information disclosure through detailed error messages that may leak sensitive input values via malformed user-supplied data processed in security-critical contexts.

Affected products

podman
toolbox
openshift
microshift
gvisor-tap-vsock
rhtas/cosign-rhel9
rhtas/fulcio-rhel9
devspaces/udi-rhel9
rhtas/gitsign-rhel9
rhtas/rekor-cli-rhel9
devspaces/traefik-rhel9
opentelemetry-collector
devspaces/udi-base-rhel9
rhacm2/acm-grafana-rhel9
rhoai/odh-rhel9-operator
rhtas/rekor-server-rhel9
openshift-pipelines-client
openshift4/ose-helm-operator
redhat-certification-preflight
rhoai/odh-model-registry-rhel9
openshift-gitops-1/argocd-rhel8
openshift-gitops-1/argocd-rhel9
rhtas/timestamp-authority-rhel9
rhacm2/submariner-rhel9-operator
rhtas/rekor-backfill-redis-rhel9
openshift4/ose-helm-rhel9-operator
github.com/go-viper/mapstructure/v2
  • <2.4.0
rhosdt/opentelemetry-collector-rhel8
rhtap-task-runner/rhtap-task-runner-rhel9
advanced-cluster-security/rhacs-main-rhel8
advanced-cluster-security/rhacs-roxctl-rhel8
advanced-cluster-security/rhacs-rhel8-operator
advanced-cluster-security/rhacs-central-db-rhel8
advanced-cluster-security/rhacs-scanner-v4-rhel8
advanced-cluster-security/rhacs-scanner-v4-db-rhel8
zero-trust-workload-identity-manager/spiffe-spire-agent-rhel9
zero-trust-workload-identity-manager/spiffe-spire-server-rhel9
zero-trust-workload-identity-manager/spiffe-spire-oidc-discovery-provider-rhel9
zero-trust-workload-identity-manager/zero-trust-workload-identity-manager-rhel9

Matching in nixpkgs

pkgs.podman

Program for managing pods, containers and container images

pkgs.lttoolbox

Finite state compiler, processor and helper tools used by apertium

pkgs.podman-compose

Implementation of docker-compose with podman backend

pkgs.perlPackages.TestToolbox

Test::Toolbox - tools for testing

pkgs.linphonePackages.bctoolbox

Utilities library for Linphone

pkgs.perl538Packages.TestToolbox

Test::Toolbox - tools for testing

pkgs.perl540Packages.TestToolbox

Test::Toolbox - tools for testing

pkgs.python312Packages.mpltoolbox

Interactive tools for Matplotlib

pkgs.python313Packages.mpltoolbox

Interactive tools for Matplotlib

pkgs.haskellPackages.pdf-toolbox-core

A collection of tools for processing PDF files

pkgs.python312Packages.sphinx-toolbox

Box of handy tools for Sphinx

  • nixos-unstable -

pkgs.python313Packages.sphinx-toolbox

Box of handy tools for Sphinx

  • nixos-unstable -

pkgs.haskellPackages.pdf-toolbox-content

A collection of tools for processing PDF files

pkgs.haskellPackages.pdf-toolbox-document

A collection of tools for processing PDF files

pkgs.python312Packages.azure-mgmt-redhatopenshift

Microsoft Azure Red Hat Openshift Management Client Library for Python

pkgs.python313Packages.azure-mgmt-redhatopenshift

Microsoft Azure Red Hat Openshift Management Client Library for Python

Package maintainers: 26

created an hour ago
Connection pool exhaustion in hackney

Hackney fails to properly release HTTP connections to the pool after handling 307 Temporary Redirect responses. Remote attackers can exploit this to exhaust connection pools, causing denial of service in applications using the library. Fix for this issue has been included in 1.24.0 release.

Affected products

hackney
  • <1.24.0

Matching in nixpkgs

pkgs.hackneyed

Scalable cursor theme that resembles Windows 3.x/NT 3.x cursors

Package maintainers: 1