Nixpkgs Security Tracker

Login with GitHub

Details of issue NIXPKGS-2026-0659

NIXPKGS-2026-0659
published on 16 Mar 2026
updated 5 days, 12 hours ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
telnet in GNU inetutils through 2.7 allows servers to read …

telnet in GNU inetutils through 2.7 allows servers to read arbitrary environment variables from clients via NEW_ENVIRON SEND USERVAR.

Affected products

inetutils
  • =<2.7

Matching in nixpkgs

Package maintainers

Upstream discussion: https://lists.gnu.org/archive/html/bug-inetutils/2026-03/msg00038.html
OSS Sec thread: https://www.openwall.com/lists/oss-security/2026/03/13/1