Nixpkgs security tracker

Login with GitHub

Details of issue NIXPKGS-2026-0500

NIXPKGS-2026-0500
published on
updated 2 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    10 packages
    • python312Packages.affine
    • python313Packages.affine
    • python314Packages.affine
    • python312Packages.affinegap
    • python313Packages.affinegap
    • python314Packages.affinegap
    • python312Packages.affine-gaps
    • python313Packages.affine-gaps
    • haskellPackages.affinely-extended
    • haskellPackages.simple-affine-space
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
AFFiNE: Open Redirect via Regex Bypass in redirect-proxy

AFFiNE is an open-source, all-in-one workspace and an operating system. Prior to version 0.26.0, there is an Open Redirect vulnerability located at the /redirect-proxy endpoint. The flaw exists in the domain validation logic, where an improperly anchored Regular Expression allows an attacker to bypass the whitelist by using malicious domains that end with a trusted string. This issue has been patched in version 0.26.0.

Affected products

AFFiNE
  • ==< 0.26.0

Matching in nixpkgs

pkgs.affine

Workspace with fully merged docs, whiteboards and databases

Ignored packages (10)

pkgs.python313Packages.affinegap

Cython implementation of the affine gap string distance

  • nixos-unstable 2
    • nixpkgs-unstable 2
    • nixos-unstable-small 2
  • nixos-25.11 1.12
    • nixos-25.11-small 1.12
    • nixpkgs-25.11-darwin 1.12

Package maintainers

Upstream advisory: https://github.com/toeverything/AFFiNE/security/advisories/GHSA-wx9m-v7wq-g289