Nixpkgs Security Tracker

Login with GitHub

Automatically generated suggestions

to queue a suggestion for refinement.

to remove a suggestion from the queue.

created 15 hours ago
a memory leak in ydb-platform/ydb with use of yajl_tree_parse function from src/yail module, which will cause out-of-memory in server and cause crash.

Missing Release of Memory after Effective Lifetime vulnerability in ydb-platform ydb (contrib/libs/yajl modules). This vulnerability is associated with program files yail_tree.C. This issue affects ydb: through 24.4.4.2.

Affected products

ydb
  • =<24.4.4.2

Matching in nixpkgs

pkgs.keydb

Multithreaded Fork of Redis

pkgs.pgcopydb

Copy a Postgres database to a target Postgres server (pg_dump | pg_restore on steroids

pkgs.perlPackages.BerkeleyDB

Perl extension for Berkeley DB version 2, 3, 4, 5 or 6

pkgs.python312Packages.tinydb

Lightweight document oriented database written in Python

pkgs.python313Packages.tinydb

Lightweight document oriented database written in Python

pkgs.perl538Packages.BerkeleyDB

Perl extension for Berkeley DB version 2, 3, 4, 5 or 6

pkgs.perl540Packages.BerkeleyDB

Perl extension for Berkeley DB version 2, 3, 4, 5 or 6

created 15 hours ago
Inappropriate implementation in Background Fetch API in Google Chrome prior …

Inappropriate implementation in Background Fetch API in Google Chrome prior to 144.0.7559.110 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

Affected products

Chrome
  • <144.0.7559.110

Matching in nixpkgs

pkgs.netflix

Open Netflix in Google Chrome app mode

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small
  • nixos-25.05 -
    • nixos-25.05-small
    • nixpkgs-25.05-darwin

pkgs.chrome-export

Scripts to save Google Chrome's bookmarks and history as HTML bookmarks files

pkgs.go-chromecast

CLI for Google Chromecast, Home devices and Cast Groups

pkgs.chrome-token-signing

Chrome and Firefox extension for signing with your eID on the web

pkgs.curl-impersonate-chrome

Special build of curl that can impersonate Chrome & Firefox

pkgs.electron-chromedriver_33

WebDriver server for running Selenium tests on Chrome

pkgs.electron-chromedriver_34

WebDriver server for running Selenium tests on Chrome

pkgs.electron-chromedriver_35

WebDriver server for running Selenium tests on Chrome

pkgs.ocamlPackages.chrome-trace

Chrome trace event generation library

pkgs.python312Packages.pychromecast

Library for Python to communicate with the Google Chromecast

pkgs.python313Packages.pychromecast

Library for Python to communicate with the Google Chromecast

pkgs.python312Packages.undetected-chromedriver

Python library for the custom Selenium ChromeDriver that passes all bot mitigation systems

pkgs.python313Packages.undetected-chromedriver

Python library for the custom Selenium ChromeDriver that passes all bot mitigation systems

pkgs.grafanaPlugins.ventura-psychrometric-panel

Grafana plugin to display air conditions on a psychrometric chart

created 15 hours ago
LibreNMS 1.46 - MAC Accounting Graph Authenticated SQL Injection

LibreNMS 1.46 contains an authenticated SQL injection vulnerability in the MAC accounting graph endpoint that allows remote attackers to extract database information. Attackers can exploit the vulnerability by manipulating the 'sort' parameter with crafted SQL injection techniques to retrieve sensitive database contents through time-based blind SQL injection.

Affected products

LibreNMS
  • ==1.46

Matching in nixpkgs

Package maintainers: 5

created 15 hours ago
Hono's IPv4 address validation bypass in IP Restriction Middleware allows IP spoofing

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.11.7, IP Restriction Middleware in Hono is vulnerable to an IP address validation bypass. The `IPV4_REGEX` pattern and `convertIPv4ToBinary` function in `src/utils/ipaddr.ts` do not properly validate that IPv4 octet values are within the valid range of 0-255, allowing attackers to craft malformed IP addresses that bypass IP-based access controls. Version 4.11.7 contains a patch for the issue.

Affected products

hono
  • ==< 4.11.7

Matching in nixpkgs

pkgs.python312Packages.phonopy

Modulefor phonon calculations at harmonic and quasi-harmonic levels

pkgs.python313Packages.phonopy

Modulefor phonon calculations at harmonic and quasi-harmonic levels

Package maintainers: 14

created 15 hours ago
In GnuPG before 2.5.17, a long signature packet length causes …

In GnuPG before 2.5.17, a long signature packet length causes parse_signature to return success with sig->data[] set to a NULL value, leading to a denial of service (application crash).

Affected products

GnuPG
  • <2.5.17

Matching in nixpkgs

pkgs.gnupg24

Modern release of the GNU Privacy Guard, a GPL OpenPGP implementation

pkgs.pam_gnupg

Unlock GnuPG keys on login

pkgs.gnupg1compat

Modern release of the GNU Privacy Guard, a GPL OpenPGP implementation with symbolic links for gpg and gpgv

pkgs.phpExtensions.gnupg

PHP wrapper for GpgME library that provides access to GnuPG

pkgs.php81Extensions.gnupg

PHP wrapper for GpgME library that provides access to GnuPG

pkgs.php82Extensions.gnupg

PHP wrapper for GpgME library that provides access to GnuPG

pkgs.php83Extensions.gnupg

PHP wrapper for GpgME library that provides access to GnuPG

pkgs.php84Extensions.gnupg

PHP wrapper for GpgME library that provides access to GnuPG

pkgs.perlPackages.GnuPGInterface

Supply object methods for interacting with GnuPG

pkgs.perl538Packages.GnuPGInterface

Supply object methods for interacting with GnuPG

pkgs.perl540Packages.GnuPGInterface

Supply object methods for interacting with GnuPG

pkgs.python312Packages.python-gnupg

API for the GNU Privacy Guard (GnuPG)

pkgs.python313Packages.python-gnupg

API for the GNU Privacy Guard (GnuPG)

created 15 hours ago
dirsearch 0.4.1 - CSV Injection

Dirsearch 0.4.1 contains a CSV injection vulnerability when using the --csv-report flag that allows attackers to inject formulas through redirected endpoints. Attackers can craft malicious server redirects with comma-separated paths containing Excel formulas to manipulate the generated CSV report.

Affected products

dirsearch
  • ==0.4.1

Matching in nixpkgs

pkgs.python312Packages.dirsearch

Command-line tool for brute-forcing directories and files in webservers, AKA a web path scanner

pkgs.python313Packages.dirsearch

Command-line tool for brute-forcing directories and files in webservers, AKA a web path scanner

Package maintainers: 1

created 15 hours ago
Hono has an Arbitrary Key Read in Serve static Middleware (Cloudflare Workers Adapter)

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.11.7, Serve static Middleware for the Cloudflare Workers adapter contains an information disclosure vulnerability that may allow attackers to read arbitrary keys from the Workers environment. Improper validation of user-controlled paths can result in unintended access to internal asset keys. Version 4.11.7 contains a patch for the issue.

Affected products

hono
  • ==< 4.11.7

Matching in nixpkgs

pkgs.python312Packages.phonopy

Modulefor phonon calculations at harmonic and quasi-harmonic levels

pkgs.python313Packages.phonopy

Modulefor phonon calculations at harmonic and quasi-harmonic levels

Package maintainers: 14

created 15 hours ago
QGIS had validated RCE and Repository Takeover via GitHub Actions

QGIS is a free, open source, cross platform geographical information system (GIS) The repository contains a GitHub Actions workflow called "pre-commit checks" that, before commit 76a693cd91650f9b4e83edac525e5e4f90d954e9, was vulnerable to remote code execution and repository compromise because it used the `pull_request_target` trigger and then checked out and executed untrusted pull request code in a privileged context. Workflows triggered by `pull_request_target` ran with the base repository's credentials and access to secrets. If these workflows then checked out and executed code from the head of an external pull request (which could have been attacker controlled), the attacker could have executed arbitrary commands with elevated privileges. This insecure pattern has been documented as a security risk by GitHub and security researchers. Commit 76a693cd91650f9b4e83edac525e5e4f90d954e9 removed the vulnerable code.

Affected products

QGIS
  • ==< 76a693cd91650f9b4e83edac525e5e4f90d954e9

Matching in nixpkgs

Package maintainers: 8

created 15 hours ago
Glib: integer overflow leading to buffer underflow and out-of-bounds write in glib g_base64_encode()

A flaw was found in the GLib Base64 encoding routine when processing very large input data. Due to incorrect use of integer types during length calculation, the library may miscalculate buffer boundaries. This can cause memory writes outside the allocated buffer. Applications that process untrusted or extremely large Base64 input using GLib may crash or behave unpredictably.

Affected products

bootc
glib2
loupe
papers
librsvg2
rpm-ostree
mingw-glib2
glycin-loaders

Matching in nixpkgs

pkgs.loupe

Simple image viewer application written with GTK4 and Rust

pkgs.qbootctl

Qualcomm bootctl HAL for Linux

pkgs.rpm-ostree

Hybrid image/package system. It uses OSTree as an image format, and uses RPM as a component model

pkgs.systemd-bootchart

Boot performance graphing tool from systemd

pkgs.deepin.deepin-wallpapers

deepin-wallpapers provides wallpapers of dde

pkgs.lomiri.lomiri-wallpapers

Wallpapers for the Lomiri Operating Environment, gathered from people of the Ubuntu Touch / UBports community

pkgs.perlPackages.Apppapersway

PaperWM-like scrollable tiling window management for Sway/i3wm

pkgs.perl538Packages.Apppapersway

PaperWM-like scrollable tiling window management for Sway/i3wm

pkgs.perl540Packages.Apppapersway

PaperWM-like scrollable tiling window management for Sway/i3wm

pkgs.pantheon.elementary-wallpapers

Collection of wallpapers for elementary

pkgs.kdePackages.plasma-workspace-wallpapers

Wallpapers for Plasma Workspaces

Package maintainers: 37

created 15 hours ago
Use-after-free in the Layout: Scrolling and Overflow component

Use-after-free in the Layout: Scrolling and Overflow component. This vulnerability affects Firefox < 147.0.2.

Affected products

Firefox
  • <147.0.2

Matching in nixpkgs

pkgs.firefoxpwa

Tool to install, manage and use Progressive Web Apps (PWAs) in Mozilla Firefox (native component)

pkgs.faust2firefox

The faust2firefox script, part of faust functional programming language for realtime audio signal processing

pkgs.firefox_decrypt

Tool to extract passwords from profiles of Mozilla Firefox and derivates

pkgs.pkgsRocm.firefox

Web browser built from Firefox source tree

pkgs.firefox-gnome-theme

GNOME theme for Firefox

pkgs.firefox-sync-client

Commandline-utility to list/view/edit/delete entries in a firefox-sync account.

pkgs.pkgsRocm.firefoxpwa

Tool to install, manage and use Progressive Web Apps (PWAs) in Mozilla Firefox (native component)

pkgs.pkgsRocm.firefox-beta

Web browser built from Firefox Beta Release source tree

pkgs.pkgsRocm.firefox-mobile

Web browser built from Firefox source tree

pkgs.pkgsRocm.firefox-unwrapped

Web browser built from Firefox source tree

pkgs.pkgsRocm.firefox-devedition

Web browser built from Firefox Developer Edition source tree

pkgs.pkgsRocm.firefox-beta-unwrapped

Web browser built from Firefox Beta Release source tree

pkgs.gnomeExtensions.firefox-profiles

Easily launch Firefox with your favorite profile right from the indicator menu!

  • nixos-unstable 5
    • nixpkgs-unstable 5
    • nixos-unstable-small 5
  • nixos-25.05 4
    • nixos-25.05-small 4
    • nixpkgs-25.05-darwin 4

pkgs.pkgsRocm.firefox-devedition-unwrapped

Web browser built from Firefox Developer Edition source tree

pkgs.vscode-extensions.firefox-devtools.vscode-firefox-debug

Visual Studio Code extension for debugging web applications and browser extensions in Firefox

Package maintainers: 14