Nixpkgs security tracker

Try the new UI
Login with GitHub

Suggestions search

With package: calico-kube-controllers

Found 8 matching suggestions

View:
Compact
Detailed
Dismissed
(not in Nixpkgs)
Permalink CVE-2025-36421
5.9 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
updated 4 days, 7 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
Multiple vulnerabilities in IBM Controller

IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques.

References

Affected products

Controller
  • =<11.1.3 FP1
  • =<11.0.1 FP7

Matching in nixpkgs

pkgs.unifi

Controller for Ubiquiti UniFi access points

  • nixos-unstable -
  • nixos-26.05 -

pkgs.sc-controller

User-mode driver and GUI for Steam Controller and other controllers

  • nixos-unstable -
    • nixos-unstable-small 0.7.2
  • nixos-26.05 -
    • nixos-26.05-small 0.6.2

pkgs.pid-fan-controller

Service to provide closed-loop PID fan control

  • nixos-unstable -
    • nixos-unstable-small 0.1.5
  • nixos-26.05 -
    • nixos-26.05-small 0.1.3

pkgs.gnomeExtensions.media-controller

Show the currently playing media in the top panel with playback controls and an iOS-inspired now-playing card. Works with any MPRIS-compatible player, including Spotify, Firefox, Chrome, VLC, mpv, Rhythmbox, and more.

  • nixos-unstable -
    • nixos-unstable-small 9

pkgs.gnomeExtensions.spotify-controller

A feature-rich Spotify controller for GNOME Shell with a beautiful popup UI.

  • nixos-unstable -
    • nixos-unstable-small 4
  • nixos-26.05 -
    • nixos-26.05-small 4

pkgs.gnomeExtensions.awesome-media-controller

Aurora Glass media controls in the GNOME top bar. Full-card popup with album art, progress, volume, shuffle, repeat, and multi-player switching.

  • nixos-unstable -
    • nixos-unstable-small 1

pkgs.gnomeExtensions.advanced-media-controller

Take control of all your music and media from one stylish spot in your GNOME panel — no more switching windows just to skip a track.

  • nixos-unstable -
    • nixos-unstable-small 31
  • nixos-26.05 -
    • nixos-26.05-small 23

pkgs.gnomeExtensions.ddc-brightness-controller

Control display brightness via DDC/CI using ddcutil. Bind keyboard shortcuts or use the panel menu to adjust monitor brightness.

  • nixos-unstable -
    • nixos-unstable-small 1

pkgs.gnomeExtensions.xbox-controller-indicator

Shows connected Xbox/gamepad controllers as colored icons in the panel. Configure colors per MAC address in the preferences.

  • nixos-unstable -
    • nixos-unstable-small 3

pkgs.gnomeExtensions.streamcontroller-integration

Allow automatic page switching in StreamController by adding a dbus interface to fetch info about the current window.

  • nixos-unstable -
    • nixos-unstable-small 7
  • nixos-26.05 -
    • nixos-26.05-small 6

Package maintainers

Dismissed
(not in Nixpkgs)
Permalink CVE-2025-1350
5.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
updated 4 days, 8 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
Multiple vulnerabilities in IBM Controller

IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.

References

Affected products

Controller
  • =<11.1.3 FP1
  • =<11.0.1 FP7

Matching in nixpkgs

pkgs.unifi

Controller for Ubiquiti UniFi access points

  • nixos-unstable -
  • nixos-26.05 -

pkgs.sc-controller

User-mode driver and GUI for Steam Controller and other controllers

  • nixos-unstable -
    • nixos-unstable-small 0.7.2
  • nixos-26.05 -
    • nixos-26.05-small 0.6.2

pkgs.pid-fan-controller

Service to provide closed-loop PID fan control

  • nixos-unstable -
    • nixos-unstable-small 0.1.5
  • nixos-26.05 -
    • nixos-26.05-small 0.1.3

pkgs.gnomeExtensions.media-controller

Show the currently playing media in the top panel with playback controls and an iOS-inspired now-playing card. Works with any MPRIS-compatible player, including Spotify, Firefox, Chrome, VLC, mpv, Rhythmbox, and more.

  • nixos-unstable -
    • nixos-unstable-small 9

pkgs.gnomeExtensions.spotify-controller

A feature-rich Spotify controller for GNOME Shell with a beautiful popup UI.

  • nixos-unstable -
    • nixos-unstable-small 4
  • nixos-26.05 -
    • nixos-26.05-small 4

pkgs.gnomeExtensions.awesome-media-controller

Aurora Glass media controls in the GNOME top bar. Full-card popup with album art, progress, volume, shuffle, repeat, and multi-player switching.

  • nixos-unstable -
    • nixos-unstable-small 1

pkgs.gnomeExtensions.advanced-media-controller

Take control of all your music and media from one stylish spot in your GNOME panel — no more switching windows just to skip a track.

  • nixos-unstable -
    • nixos-unstable-small 31
  • nixos-26.05 -
    • nixos-26.05-small 23

pkgs.gnomeExtensions.ddc-brightness-controller

Control display brightness via DDC/CI using ddcutil. Bind keyboard shortcuts or use the panel menu to adjust monitor brightness.

  • nixos-unstable -
    • nixos-unstable-small 1

pkgs.gnomeExtensions.xbox-controller-indicator

Shows connected Xbox/gamepad controllers as colored icons in the panel. Configure colors per MAC address in the preferences.

  • nixos-unstable -
    • nixos-unstable-small 3

pkgs.gnomeExtensions.streamcontroller-integration

Allow automatic page switching in StreamController by adding a dbus interface to fetch info about the current window.

  • nixos-unstable -
    • nixos-unstable-small 7
  • nixos-26.05 -
    • nixos-26.05-small 6

Package maintainers

Untriaged
Permalink CVE-2026-6540
7.9 HIGH
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): None (N)
  • Vulnerable System Impact Integrity (VI): None (N)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): High (H)
  • Subsequent System Impact Integrity (SI): High (H)
  • Subsequent System Impact Availability (SA): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): None (N)
  • Modified Vulnerable System Impact Integrity (MVI): None (N)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): High (H)
  • Modified Subsequent System Impact Integrity (MSI): High (H)
  • Modified Subsequent System Impact Availability (MSA): Low (L)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 1 month, 3 weeks ago Activity log
  • Created suggestion
L7 policy bypass via unnormalized HTTP path matching

Calico's Application Layer Policy (disabled by default), which enforces HTTP rules through Dikastes, fails to perform URL path normalization. As a result, HTTP requests using path-traversal segments, encoded slashes, or repeated slashes are not correctly evaluated by Prefix path rules. Dikastes authorizes the request under the permitted prefix while the downstream workload or a fronting proxy normalizes the path and serves the restricted endpoint. An attacker with network access and no special RBAC can potentially reach HTTP endpoints the policy was intended to restrict.

Affected products

Calico
  • <3.31.6
Calico Cloud
  • <22.4.0
Calico Enterprise
  • <3.21.7
  • <3.22.4

Matching in nixpkgs

pkgs.calicoctl

Cloud native networking and network security

  • nixos-unstable -
  • nixos-26.05 -

pkgs.calico-typha

Cloud native networking and network security

  • nixos-unstable -
  • nixos-26.05 -

pkgs.confd-calico

Cloud native networking and network security

  • nixos-unstable -
  • nixos-26.05 -

pkgs.calico-apiserver

Cloud native networking and network security

  • nixos-unstable -
  • nixos-26.05 -

pkgs.calico-app-policy

Cloud native networking and network security

  • nixos-unstable -
  • nixos-26.05 -

pkgs.calico-cni-plugin

Cloud native networking and network security

  • nixos-unstable -
  • nixos-26.05 -

pkgs.calico-pod2daemon

Cloud native networking and network security

  • nixos-unstable -
  • nixos-26.05 -
Untriaged
Permalink CVE-2026-41187
6.2 MEDIUM
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): Low (L)
  • Vulnerable System Impact Integrity (VI): Low (L)
  • Vulnerable System Impact Availability (VA): Low (L)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): Low (L)
  • Subsequent System Impact Availability (SA): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
  • Modified Vulnerable System Impact Integrity (MVI): Low (L)
  • Modified Vulnerable System Impact Availability (MVA): Low (L)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Low (L)
  • Modified Subsequent System Impact Availability (MSA): High (H)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 1 month, 3 weeks ago Activity log
  • Created suggestion
Calico Tier Authorization Bypass via DeleteCollection

Calico's apiserver wraps tier-scoped resources so that every operation runs through AuthorizeTierOperation, but the Delete override on NetworkPolicy, GlobalNetworkPolicy, and their staged variants is not invoked for DeleteCollection requests. A user holding the deletecollection verb or wildcard verbs on tier-scoped policy resources can bulk-delete policies in tiers they otherwise have no rights on, breaking the tier authorization boundary.

Affected products

Calico
  • <3.31.6
  • <3.32.1
Calico Cloud
  • <22.4.0
Calico Enterprise
  • <3.21.7
  • <3.22.5

Matching in nixpkgs

pkgs.calicoctl

Cloud native networking and network security

  • nixos-unstable -
  • nixos-26.05 -

pkgs.calico-typha

Cloud native networking and network security

  • nixos-unstable -
  • nixos-26.05 -

pkgs.confd-calico

Cloud native networking and network security

  • nixos-unstable -
  • nixos-26.05 -

pkgs.calico-apiserver

Cloud native networking and network security

  • nixos-unstable -
  • nixos-26.05 -

pkgs.calico-app-policy

Cloud native networking and network security

  • nixos-unstable -
  • nixos-26.05 -

pkgs.calico-cni-plugin

Cloud native networking and network security

  • nixos-unstable -
  • nixos-26.05 -

pkgs.calico-pod2daemon

Cloud native networking and network security

  • nixos-unstable -
  • nixos-26.05 -
Untriaged
Permalink CVE-2026-41186
6.0 MEDIUM
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Adjacent (A)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): Present (P)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): High (H)
  • Vulnerable System Impact Integrity (VI): None (N)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): Low (L)
  • Subsequent System Impact Integrity (SI): Low (L)
  • Subsequent System Impact Availability (SA): Low (L)
  • Modified Attack Vector (MAV): Adjacent (A)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): Present (P)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): High (H)
  • Modified Vulnerable System Impact Integrity (MVI): None (N)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): Low (L)
  • Modified Subsequent System Impact Integrity (MSI): Low (L)
  • Modified Subsequent System Impact Availability (MSA): Low (L)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 1 month, 3 weeks ago Activity log
  • Created suggestion
Unauthenticated Go pprof exposure in Calico debug server

When Calico's shared debug server is enabled (disabled by default), the Calico kube-controllers and Goldmane components bind their Go pprof debug listener to 0.0.0.0 without authentication. Any pod with network reachability to the listener can retrieve the process heap, goroutine stacks (including function arguments), and command-line arguments. Depending on the process's in-memory state, the heap may contain sensitive material. The debug listener is opt-in but is unsafe when enabled because it offers no authentication and no safe localhost-only binding option.

Affected products

Calico
  • <3.31.6
  • <3.32.1
Calico Cloud
  • <22.4.0
Calico Enterprise
  • <3.21.7
  • <3.22.4

Matching in nixpkgs

pkgs.calicoctl

Cloud native networking and network security

  • nixos-unstable -
  • nixos-26.05 -

pkgs.calico-typha

Cloud native networking and network security

  • nixos-unstable -
  • nixos-26.05 -

pkgs.confd-calico

Cloud native networking and network security

  • nixos-unstable -
  • nixos-26.05 -

pkgs.calico-apiserver

Cloud native networking and network security

  • nixos-unstable -
  • nixos-26.05 -

pkgs.calico-app-policy

Cloud native networking and network security

  • nixos-unstable -
  • nixos-26.05 -

pkgs.calico-cni-plugin

Cloud native networking and network security

  • nixos-unstable -
  • nixos-26.05 -

pkgs.calico-pod2daemon

Cloud native networking and network security

  • nixos-unstable -
  • nixos-26.05 -
Untriaged
Permalink CVE-2026-6720
7.2 HIGH
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): Present (P)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): Passive (P)
  • Vulnerable System Impact Confidentiality (VC): High (H)
  • Vulnerable System Impact Integrity (VI): None (N)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): High (H)
  • Subsequent System Impact Integrity (SI): High (H)
  • Subsequent System Impact Availability (SA): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): Present (P)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): Passive (P)
  • Modified Vulnerable System Impact Confidentiality (MVC): High (H)
  • Modified Vulnerable System Impact Integrity (MVI): None (N)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): High (H)
  • Modified Subsequent System Impact Integrity (MSI): High (H)
  • Modified Subsequent System Impact Availability (MSA): High (H)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 3 months, 3 weeks ago Activity log
  • Created suggestion
Calicoctl leaks cluster credentials to stderr when verbose logging is enabled

When calicoctl is invoked with --log-level=info or --log-level=debug, the client prints the full contents of its loaded connection-configuration struct to stderr in a single log line. The struct embeds every credential calicoctl uses to talk to the cluster — inline kubeconfig (with bearer token), Kubernetes API bearer token, etcd password, and inline PEM-encoded etcd client certificate and key. Any reader of that stderr stream — CI job logs, session-recording archives, shared support-ticket transcripts, or local filesystem viewers on the host that ran calicoctl — can extract these credentials with zero Kubernetes privilege. calicoctl's default log level is panic, so this issue only triggers when verbose logging is explicitly enabled.

Affected products

Calico
  • <3.32.0
Calico Cloud
  • <22.4.0
Calico Enterprise
  • <3.21.7
  • ==3.22.3

Matching in nixpkgs

pkgs.calicoctl

Cloud native networking and network security

  • nixos-unstable -
  • nixos-26.05 -

pkgs.calico-typha

Cloud native networking and network security

  • nixos-unstable -
  • nixos-26.05 -

pkgs.confd-calico

Cloud native networking and network security

  • nixos-unstable -
  • nixos-26.05 -

pkgs.calico-apiserver

Cloud native networking and network security

  • nixos-unstable -
  • nixos-26.05 -

pkgs.calico-app-policy

Cloud native networking and network security

  • nixos-unstable -
  • nixos-26.05 -

pkgs.calico-cni-plugin

Cloud native networking and network security

  • nixos-unstable -
  • nixos-26.05 -

pkgs.calico-pod2daemon

Cloud native networking and network security

  • nixos-unstable -
  • nixos-26.05 -
Untriaged
Permalink CVE-2026-41185
6.0 MEDIUM
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): Present (P)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): High (H)
  • Vulnerable System Impact Integrity (VI): None (N)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): Low (L)
  • Subsequent System Impact Integrity (SI): Low (L)
  • Subsequent System Impact Availability (SA): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): Present (P)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): High (H)
  • Modified Vulnerable System Impact Integrity (MVI): None (N)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): Low (L)
  • Modified Subsequent System Impact Integrity (MSI): Low (L)
  • Modified Subsequent System Impact Availability (MSA): Low (L)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 3 months, 3 weeks ago Activity log
  • Created suggestion
ServiceAccount token disclosure via Azure IPAM CNI plugin logs

When Calico is configured with the Azure IPAM plugin, the Calico CNI binary mutates the incoming CNI configuration to attach subnet information before delegating to the IPAM plugin. After mutating, the Azure IPAM helper logs the entire unmarshaled configuration map (stdinData) at INFO level to /var/log/calico/cni/cni.log on every CNI ADD and DEL invocation — once per pod scheduled or terminated on the node. When the cluster is deployed using token-based Kubernetes authentication, this log entry contains the ServiceAccount token, client key, and certificate authority in plaintext. Any principal with read access to /var/log/calico/cni/cni.log on a node  can read these logs and extract the credentials, which grant cluster-wide Calico networking admin privileges.

Affected products

Calico
  • <3.32.0
Calico Cloud
  • <22.4.0
Calico Enterprise
  • <3.21.7
  • <3.22.3

Matching in nixpkgs

pkgs.calicoctl

Cloud native networking and network security

  • nixos-unstable -
  • nixos-26.05 -

pkgs.calico-typha

Cloud native networking and network security

  • nixos-unstable -
  • nixos-26.05 -

pkgs.confd-calico

Cloud native networking and network security

  • nixos-unstable -
  • nixos-26.05 -

pkgs.calico-apiserver

Cloud native networking and network security

  • nixos-unstable -
  • nixos-26.05 -

pkgs.calico-app-policy

Cloud native networking and network security

  • nixos-unstable -
  • nixos-26.05 -

pkgs.calico-cni-plugin

Cloud native networking and network security

  • nixos-unstable -
  • nixos-26.05 -

pkgs.calico-pod2daemon

Cloud native networking and network security

  • nixos-unstable -
  • nixos-26.05 -
Dismissed
(not in Nixpkgs)
Permalink CVE-2026-5065
8.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 3 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
IBM Controller is affected by vulnerabilities

IBM Controller 11.0.1, 11.1.0, 11.1.1, and 11.1.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.

References

Affected products

Controller
  • =<26.0.0.5
  • ==11.1.1
  • ==11.1.0
  • ==11.1.2

Matching in nixpkgs

pkgs.sc-controller

User-mode driver and GUI for Steam Controller and other controllers

pkgs.gnomeExtensions.advanced-media-controller

Take control of all your music and media from one stylish spot in your GNOME panel — no more switching windows just to skip a track.

  • nixos-unstable 23
    • nixpkgs-unstable 23
    • nixos-unstable-small 23

Package maintainers