Nixpkgs security tracker

Login with GitHub

Suggestions search

With package: androidenv.androidPkgs.all.extras.extras-google-m2repository

Found 9 matching suggestions

View:
Compact
Detailed
Untriaged
Permalink CVE-2026-49883
10.0 CRITICAL
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): High (H)
  • Vulnerable System Impact Integrity (VI): High (H)
  • Vulnerable System Impact Availability (VA): High (H)
  • Subsequent System Impact Confidentiality (SC): High (H)
  • Subsequent System Impact Integrity (SI): High (H)
  • Subsequent System Impact Availability (SA): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): High (H)
  • Modified Vulnerable System Impact Integrity (MVI): High (H)
  • Modified Vulnerable System Impact Availability (MVA): High (H)
  • Modified Subsequent System Impact Confidentiality (MSC): High (H)
  • Modified Subsequent System Impact Integrity (MSI): High (H)
  • Modified Subsequent System Impact Availability (MSA): High (H)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 14 hours ago Activity log
  • Created suggestion
In checkReadPermission of PermissionsManager.java, there is a possible way to …

In checkReadPermission of PermissionsManager.java, there is a possible way to monitor sensitive device state data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

Affected products

Wear
  • ==16
  • ==14
  • ==17

Matching in nixpkgs

Package maintainers

Untriaged
Permalink CVE-2026-19586
9.3 CRITICAL
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): High (H)
  • Vulnerable System Impact Integrity (VI): High (H)
  • Vulnerable System Impact Availability (VA): High (H)
  • Subsequent System Impact Confidentiality (SC): Low (L)
  • Subsequent System Impact Integrity (SI): Low (L)
  • Subsequent System Impact Availability (SA): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): High (H)
  • Modified Vulnerable System Impact Integrity (MVI): High (H)
  • Modified Vulnerable System Impact Availability (MVA): High (H)
  • Modified Subsequent System Impact Confidentiality (MSC): Low (L)
  • Modified Subsequent System Impact Integrity (MSI): Low (L)
  • Modified Subsequent System Impact Availability (MSA): Low (L)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 2 weeks, 5 days ago Activity log
  • Created suggestion
Pre-Authentication OS Command Injection in Omada Gateways on OpenVPN Server in Omada Gateways

A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as an OpenVPN Server due to insufficient validation of client-supplied data during OpenVPN connection establishment. An unauthenticated remote attacker may provide specially crafted input influencing backend command execution logic before authentication completes. Exploitation requires the OpenVPN Server feature to be enabled, VPN service reachable by the attacker and attacker to be able to initiate an OpenVPN connection attempt.  Successful exploitation may allow arbitrary command execution, potentially leading to full compromise of the affected device.

Affected products

v1
  • <1.2.6 Build 20260723 Rel.41321
ER605 v2
  • <2.4.4 Build 20260630 Rel.14398
DR3150 v1
  • <1.0.1 Build 20260722 Rel.16854
ER605W v2
  • <2.0.4 Build 20260723 Rel.43763
ER706W v1
  • <1.2.11 Build 20260723 Rel.41567
ER7206 v2
  • <2.3.5 Build 20260625 Rel.43136
ER7406 v1
  • <1.3.4 Build 20260625 Rel.43136
ER8411 v1
  • <1.4.1 Build 20260708 Rel.64832
DR3650v v1
  • <1.2.0 Build 20260630 Rel.83311
ER707-M2 v1
  • <1.4.4 Build 20260625 Rel.43063
ER7212PC v2
  • <2.4.3 Build 20260722 Rel.40250
ER706W-4G v2
  • <2.1.11 Build 20260723 Rel.41624
ER7412-M2 v1
  • <1.2.0 Build 20260630 Rel.82947
DR3220v-4G v1
  • <1.2.0 Build 20260630 Rel.82652
DR3650v-4G v1
  • <1.2.0 Build 20260630 Rel.83347
ER706WP-4G v1
  • <1.1.11 Build 20260723 Rel.41624
ER701-5G-Outdoor v1
  • <1.0.3 Build 20260723 Rel.40931
ER603WP-4G-Outdoor v1
  • <1.0.2 Build 20260723 Rel.43271
ER703WP-4G-Outdoor v1
  • <1.1.7 Build 20260723 Rel.41712

Matching in nixpkgs

pkgs.av1an

Cross-platform command-line encoding framework

pkgs.dav1d

Cross-platform AV1 decoder focused on speed and correctness

pkgs.rav1d

AV1 cross-platform decoder, Rust port of dav1d

pkgs.rav1e

Fastest and safest AV1 encoder

pkgs.drumkv1

Old-school drum-kit sampler synthesizer with stereo fx

pkgs.padthv1

Polyphonic additive synthesizer

pkgs.samplv1

Old-school all-digital polyphonic sampler synthesizer with stereo fx

pkgs.svt-av1

AV1-compliant encoder/decoder library core

pkgs.synthv1

Old-school 4-oscillator subtractive polyphonic synthesizer with stereo fx

pkgs.svt-av1-hdr

Scalable Video Technology AV1 Encoder and Decoder

pkgs.sbclPackages.jzon

None

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small
  • nixos-26.05 -
    • nixos-26.05-small
    • nixpkgs-26.05-darwin

pkgs.luaPackages.sqlite

SQLite/LuaJIT binding and a highly opinionated wrapper for storing, retrieving, caching, and persisting [SQLite] databases

  • nixos-unstable 0
    • nixpkgs-unstable 0
    • nixos-unstable-small 0
  • nixos-26.05 0
    • nixos-26.05-small 0
    • nixpkgs-26.05-darwin 0

pkgs.lua51Packages.sqlite

SQLite/LuaJIT binding and a highly opinionated wrapper for storing, retrieving, caching, and persisting [SQLite] databases

  • nixos-unstable 0
    • nixpkgs-unstable 0
    • nixos-unstable-small 0
  • nixos-26.05 0
    • nixos-26.05-small 0
    • nixpkgs-26.05-darwin 0

pkgs.lua52Packages.sqlite

SQLite/LuaJIT binding and a highly opinionated wrapper for storing, retrieving, caching, and persisting [SQLite] databases

  • nixos-unstable 0
    • nixpkgs-unstable 0
    • nixos-unstable-small 0
  • nixos-26.05 0
    • nixos-26.05-small 0
    • nixpkgs-26.05-darwin 0

pkgs.lua53Packages.sqlite

SQLite/LuaJIT binding and a highly opinionated wrapper for storing, retrieving, caching, and persisting [SQLite] databases

  • nixos-unstable 0
    • nixpkgs-unstable 0
    • nixos-unstable-small 0
  • nixos-26.05 0
    • nixos-26.05-small 0
    • nixpkgs-26.05-darwin 0

pkgs.lua54Packages.sqlite

SQLite/LuaJIT binding and a highly opinionated wrapper for storing, retrieving, caching, and persisting [SQLite] databases

  • nixos-unstable 0
    • nixpkgs-unstable 0
    • nixos-unstable-small 0
  • nixos-26.05 0
    • nixos-26.05-small 0
    • nixpkgs-26.05-darwin 0

pkgs.lua55Packages.sqlite

SQLite/LuaJIT binding and a highly opinionated wrapper for storing, retrieving, caching, and persisting [SQLite] databases

  • nixos-unstable 0
    • nixpkgs-unstable 0
    • nixos-unstable-small 0
  • nixos-26.05 0
    • nixos-26.05-small 0
    • nixpkgs-26.05-darwin 0

pkgs.luajitPackages.sqlite

SQLite/LuaJIT binding and a highly opinionated wrapper for storing, retrieving, caching, and persisting [SQLite] databases

  • nixos-unstable 0
    • nixpkgs-unstable 0
    • nixos-unstable-small 0
  • nixos-26.05 0
    • nixos-26.05-small 0
    • nixpkgs-26.05-darwin 0
  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small
  • nixos-26.05 -
    • nixos-26.05-small
    • nixpkgs-26.05-darwin
  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small
  • nixos-26.05 -
    • nixos-26.05-small
    • nixpkgs-26.05-darwin
  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small
  • nixos-26.05 -
    • nixos-26.05-small
    • nixpkgs-26.05-darwin
  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small
  • nixos-26.05 -
    • nixos-26.05-small
    • nixpkgs-26.05-darwin

pkgs.chickenPackages_5.chickenEggs.ephem

A wrapper for libnova a 'general purpose, double precision, Celestial Mechanics, Astrometry and Astrodynamics library.'

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small
  • nixos-26.05 -
    • nixos-26.05-small
    • nixpkgs-26.05-darwin

pkgs.obs-studio-plugins.obs-stroke-glow-shadow

OBS plugin to provide efficient Stroke, Glow, and Shadow effects on masked sources

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small
  • nixos-26.05 -
    • nixos-26.05-small
    • nixpkgs-26.05-darwin
Untriaged
Permalink CVE-2026-19683
6.3 MEDIUM
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): Present (P)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): Low (L)
  • Vulnerable System Impact Integrity (VI): Low (L)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): Present (P)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
  • Modified Vulnerable System Impact Integrity (MVI): Low (L)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 2 weeks, 5 days ago Activity log
  • Created suggestion
Unencrypted Credential Transmission in Omada Gateway Dynamic DNS Authentication in Omada Gateways

A vulnerability exists in the Dynamic DNS (DDNS) functionality of TP-Link Omada Gateways. During communication with a third-party DDNS service, authentication credentials are transmitted over an unencrypted channel. An attacker who can observe or manipulate traffic between an affected device and the DDNS service may obtain sensitive authentication information or interfere with DDNS update operations. Exploitation requires DDNS to be configured, communication with an external DDNS service, and attacker visibility or control of the relevant network path.  Successful exploitation may result in disclosure of DDNS account credentials, unauthorized access to DDNS management functionality, or modification of DNS records associated with the affected deployment.

Affected products

v1
  • <1.2.6 Build 20260723 Rel.41321
ER605 v2
  • <2.4.4 Build 20260630 Rel.14398
DR3150 v1
  • <1.0.1 Build 20260722 Rel.16854
ER605W v2
  • <2.0.4 Build 20260723 Rel.43763
ER706W v1
  • <1.2.11 Build 20260723 Rel.41567
ER7206 v2
  • <2.3.5 Build 20260625 Rel.43136
ER7406 v1
  • <1.3.4 Build 20260625 Rel.43136
ER8411 v1
  • <1.4.1 Build 20260708 Rel.64832
DR3650v v1
  • <1.2.0 Build 20260630 Rel.83311
ER707-M2 v1
  • <1.4.4 Build 20260625 Rel.43063
ER7212PC v2
  • <2.4.3 Build 20260722 Rel.40250
ER706W-4G v2
  • <2.1.11 Build 20260723 Rel.41624
ER7412-M2 v1
  • <1.2.0 Build 20260630 Rel.82947
DR3220v-4G v1
  • <1.2.0 Build 20260630 Rel.82652
DR3650v-4G v1
  • <1.2.0 Build 20260630 Rel.83347
ER706WP-4G v1
  • <1.1.11 Build 20260723 Rel.41624
ER701-5G-Outdoor v1
  • <1.0.3 Build 20260723 Rel.40931
ER603WP-4G-Outdoor v1
  • <1.0.2 Build 20260723 Rel.43271
ER703WP-4G-Outdoor v1
  • <1.1.7 Build 20260723 Rel.41712

Matching in nixpkgs

pkgs.av1an

Cross-platform command-line encoding framework

pkgs.dav1d

Cross-platform AV1 decoder focused on speed and correctness

pkgs.rav1d

AV1 cross-platform decoder, Rust port of dav1d

pkgs.rav1e

Fastest and safest AV1 encoder

pkgs.drumkv1

Old-school drum-kit sampler synthesizer with stereo fx

pkgs.padthv1

Polyphonic additive synthesizer

pkgs.samplv1

Old-school all-digital polyphonic sampler synthesizer with stereo fx

pkgs.svt-av1

AV1-compliant encoder/decoder library core

pkgs.synthv1

Old-school 4-oscillator subtractive polyphonic synthesizer with stereo fx

pkgs.svt-av1-hdr

Scalable Video Technology AV1 Encoder and Decoder

pkgs.sbclPackages.jzon

None

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small
  • nixos-26.05 -
    • nixos-26.05-small
    • nixpkgs-26.05-darwin

pkgs.luaPackages.sqlite

SQLite/LuaJIT binding and a highly opinionated wrapper for storing, retrieving, caching, and persisting [SQLite] databases

  • nixos-unstable 0
    • nixpkgs-unstable 0
    • nixos-unstable-small 0
  • nixos-26.05 0
    • nixos-26.05-small 0
    • nixpkgs-26.05-darwin 0

pkgs.lua51Packages.sqlite

SQLite/LuaJIT binding and a highly opinionated wrapper for storing, retrieving, caching, and persisting [SQLite] databases

  • nixos-unstable 0
    • nixpkgs-unstable 0
    • nixos-unstable-small 0
  • nixos-26.05 0
    • nixos-26.05-small 0
    • nixpkgs-26.05-darwin 0

pkgs.lua52Packages.sqlite

SQLite/LuaJIT binding and a highly opinionated wrapper for storing, retrieving, caching, and persisting [SQLite] databases

  • nixos-unstable 0
    • nixpkgs-unstable 0
    • nixos-unstable-small 0
  • nixos-26.05 0
    • nixos-26.05-small 0
    • nixpkgs-26.05-darwin 0

pkgs.lua53Packages.sqlite

SQLite/LuaJIT binding and a highly opinionated wrapper for storing, retrieving, caching, and persisting [SQLite] databases

  • nixos-unstable 0
    • nixpkgs-unstable 0
    • nixos-unstable-small 0
  • nixos-26.05 0
    • nixos-26.05-small 0
    • nixpkgs-26.05-darwin 0

pkgs.lua54Packages.sqlite

SQLite/LuaJIT binding and a highly opinionated wrapper for storing, retrieving, caching, and persisting [SQLite] databases

  • nixos-unstable 0
    • nixpkgs-unstable 0
    • nixos-unstable-small 0
  • nixos-26.05 0
    • nixos-26.05-small 0
    • nixpkgs-26.05-darwin 0

pkgs.lua55Packages.sqlite

SQLite/LuaJIT binding and a highly opinionated wrapper for storing, retrieving, caching, and persisting [SQLite] databases

  • nixos-unstable 0
    • nixpkgs-unstable 0
    • nixos-unstable-small 0
  • nixos-26.05 0
    • nixos-26.05-small 0
    • nixpkgs-26.05-darwin 0

pkgs.luajitPackages.sqlite

SQLite/LuaJIT binding and a highly opinionated wrapper for storing, retrieving, caching, and persisting [SQLite] databases

  • nixos-unstable 0
    • nixpkgs-unstable 0
    • nixos-unstable-small 0
  • nixos-26.05 0
    • nixos-26.05-small 0
    • nixpkgs-26.05-darwin 0
  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small
  • nixos-26.05 -
    • nixos-26.05-small
    • nixpkgs-26.05-darwin
  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small
  • nixos-26.05 -
    • nixos-26.05-small
    • nixpkgs-26.05-darwin
  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small
  • nixos-26.05 -
    • nixos-26.05-small
    • nixpkgs-26.05-darwin
  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small
  • nixos-26.05 -
    • nixos-26.05-small
    • nixpkgs-26.05-darwin

pkgs.chickenPackages_5.chickenEggs.ephem

A wrapper for libnova a 'general purpose, double precision, Celestial Mechanics, Astrometry and Astrodynamics library.'

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small
  • nixos-26.05 -
    • nixos-26.05-small
    • nixpkgs-26.05-darwin

pkgs.obs-studio-plugins.obs-stroke-glow-shadow

OBS plugin to provide efficient Stroke, Glow, and Shadow effects on masked sources

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small
  • nixos-26.05 -
    • nixos-26.05-small
    • nixpkgs-26.05-darwin
Dismissed
(not in Nixpkgs)
Permalink CVE-2026-66145
9.1 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): None (N)
updated 3 weeks, 6 days ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
An unauthenticated remote code execution vulnerability was identified in GMS …

An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier versions which allows remote attacker to read sensitive data and perform arbitrary file write via zipslip.

Affected products

GMS
  • ==9.5.1 and earlier versions

Matching in nixpkgs

pkgs.gmsh

Three-dimensional finite element mesh generator

pkgs.vgmstream

Library for playback of various streamed audio formats used in video games

  • nixos-unstable 2117
    • nixpkgs-unstable 2117
    • nixos-unstable-small 2117
  • nixos-26.05 2117
    • nixos-26.05-small 2117
    • nixpkgs-26.05-darwin 2117

pkgs.x42-gmsynth

Chris Colins' General User soundfont player LV2 plugin

Dismissed
(not in Nixpkgs)
Permalink CVE-2026-66148
6.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): Low (L)
updated 3 weeks, 6 days ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
An authenticated command injection vulnerability was identified in GMS Command-Line …

An authenticated command injection vulnerability was identified in GMS Command-Line Interface (CLI) 9.5.1 (Build 9510.1044) and earlier versions which allows low-privileged local user to execute system commands with root privileges.

Affected products

GMS
  • ==9.5.1 and earlier versions

Matching in nixpkgs

pkgs.gmsh

Three-dimensional finite element mesh generator

pkgs.vgmstream

Library for playback of various streamed audio formats used in video games

  • nixos-unstable 2117
    • nixpkgs-unstable 2117
    • nixos-unstable-small 2117
  • nixos-26.05 2117
    • nixos-26.05-small 2117
    • nixpkgs-26.05-darwin 2117

pkgs.x42-gmsynth

Chris Colins' General User soundfont player LV2 plugin

Dismissed
(not in Nixpkgs)
updated 3 weeks, 6 days ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
An insecure handling of serialized objects vulnerability was found in …

An insecure handling of serialized objects vulnerability was found in the one of the service of GMS application 9.5.1 (Build 9510.1044) and earlier versions. A local attacker with the ability to interact with the service could exploit this behavior to perform unauthorized actions through the affected component.

Affected products

GMS
  • ==9.5.1 and earlier versions

Matching in nixpkgs

pkgs.gmsh

Three-dimensional finite element mesh generator

pkgs.vgmstream

Library for playback of various streamed audio formats used in video games

  • nixos-unstable 2117
    • nixpkgs-unstable 2117
    • nixos-unstable-small 2117
  • nixos-26.05 2117
    • nixos-26.05-small 2117
    • nixpkgs-26.05-darwin 2117

pkgs.x42-gmsynth

Chris Colins' General User soundfont player LV2 plugin

Dismissed
(not in Nixpkgs)
Permalink CVE-2026-66154
8.3 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Adjacent (A)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Adjacent (A)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 3 weeks, 6 days ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
An insufficient certificate validation in a privileged communication workflow, was …

An insufficient certificate validation in a privileged communication workflow, was identified in a GMS application 9.5.1 (Build 9510.1044) and earlier versions which, under a successful MitM attack and controlled network conditions, could permit unauthorized changes.

Affected products

GMS
  • ==9.5.1 and earlier versions

Matching in nixpkgs

pkgs.gmsh

Three-dimensional finite element mesh generator

pkgs.vgmstream

Library for playback of various streamed audio formats used in video games

  • nixos-unstable 2117
    • nixpkgs-unstable 2117
    • nixos-unstable-small 2117
  • nixos-26.05 2117
    • nixos-26.05-small 2117
    • nixpkgs-26.05-darwin 2117

pkgs.x42-gmsynth

Chris Colins' General User soundfont player LV2 plugin

Dismissed
(not in Nixpkgs)
Permalink CVE-2026-66146
6.1 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Changed (C)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
updated 3 weeks, 6 days ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
Multiple Cross-Site Scripting (XSS) vulnerabilities were identified in GMS 9.5.1 …

Multiple Cross-Site Scripting (XSS) vulnerabilities were identified in GMS 9.5.1 (Build 9510.1044) and earlier versions that allow a remote attacker to execute javascript script in a user's browser.

Affected products

GMS
  • ==9.5.1 and earlier versions

Matching in nixpkgs

pkgs.gmsh

Three-dimensional finite element mesh generator

pkgs.vgmstream

Library for playback of various streamed audio formats used in video games

  • nixos-unstable 2117
    • nixpkgs-unstable 2117
    • nixos-unstable-small 2117
  • nixos-26.05 2117
    • nixos-26.05-small 2117
    • nixpkgs-26.05-darwin 2117

pkgs.x42-gmsynth

Chris Colins' General User soundfont player LV2 plugin

Untriaged
Permalink CVE-2026-66147
9.4 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 4 weeks ago Activity log
  • Created suggestion
An unauthenticated command injection vulnerability was identified in the GMS …

An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier versions which allows remote attacker to perform remote code execution through specially crafted requests.

Affected products

GMS
  • ==9.5.1 and earlier versions

Matching in nixpkgs

pkgs.gmsh

Three-dimensional finite element mesh generator

pkgs.vgmstream

Library for playback of various streamed audio formats used in video games

  • nixos-unstable 2117
    • nixpkgs-unstable 2117
    • nixos-unstable-small 2117
  • nixos-26.05 2117
    • nixos-26.05-small 2117
    • nixpkgs-26.05-darwin 2117

pkgs.x42-gmsynth

Chris Colins' General User soundfont player LV2 plugin