Nixpkgs Security Tracker

Login with GitHub

Suggestion detail

Dismissed
Permalink CVE-2026-2435
6.3 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV):
  • Attack complexity (AC):
  • Privileges required (PR):
  • User interaction (UI):
  • Scope (S):
  • Confidentiality impact (C):
  • Integrity impact (I):
  • Availability impact (A):
updated 1 month ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed
    28 packages
    • cassette
    • assetfinder
    • assetripper
    • taproot-assets
    • etlegacy-assets
    • retroarch-assets
    • go-bindata-assetfs
    • haskellPackages.cassette
    • python312Packages.webassets
    • python313Packages.webassets
    • python314Packages.webassets
    • haskellPackages.asset-bundle
    • python312Packages.flask-assets
    • python313Packages.flask-assets
    • python314Packages.flask-assets
    • haskellPackages.wai-make-assets
    • haskellPackages.gogol-cloudasset
    • python312Packages.django-js-asset
    • python313Packages.django-js-asset
    • python314Packages.django-js-asset
    • python312Packages.google-cloud-asset
    • python313Packages.google-cloud-asset
    • python314Packages.google-cloud-asset
    • haskellPackages.gogol-digitalassetlinks
    • perlPackages.MojoliciousPluginAssetPack
    • perl5Packages.MojoliciousPluginAssetPack
    • perl538Packages.MojoliciousPluginAssetPack
    • perl540Packages.MojoliciousPluginAssetPack
  • @LeSuisse dismissed
ASSET-7706

Tanium addressed a SQL injection vulnerability in Asset.

References

Affected products

Asset
  • <1.36.108
  • <1.32.179
  • <1.33.269
Ignored packages (28)
Not present in nixpkgs