Nixpkgs security tracker

Try the new UI
Login with GitHub

Suggestions search

With package: fabric-installer

Found 3 matching suggestions

View:
Compact
Detailed
Dismissed
(not in Nixpkgs)
Permalink CVE-2026-14478
7.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 1 month, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
Incorrect Permission Assignment in Autodesk Installer Named Pipes

A maliciously created executable, when executed on the victim's machine, may allow a local low-privileged attacker to inject unauthenticated IPC messages into named pipes, modify pipe permissions or ownership, and potentially impact confidentiality, integrity, and availability.

Affected products

Installer
  • <2.23.0

Matching in nixpkgs

pkgs.calaos_installer

Calaos Installer, a tool to create calaos configuration

  • nixos-unstable 3.11
    • nixpkgs-unstable 3.11
    • nixos-unstable-small 3.11
  • nixos-26.05 3.11
    • nixos-26.05-small 3.11
    • nixpkgs-26.05-darwin 3.11

pkgs.melonloader-installer

Automated installer for MelonLoader, the universal mod-loader for games built in the Unity Engine

pkgs.gnomeExtensions.shell-easy-uninstaller

Add an uninstall option to the right-click menu of applications in the App Grid and Dash.

  • nixos-unstable 3
    • nixpkgs-unstable 3
    • nixos-unstable-small 8
  • nixos-26.05 3
    • nixos-26.05-small 3
    • nixpkgs-26.05-darwin 3

Package maintainers

Dismissed
(not in Nixpkgs)
Permalink CVE-2026-14479
5.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): High (H)
updated 1 month, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
Denial of Service in Autodesk Installer IPC Channel

A maliciously crafted input, when processed by the Autodesk Installer IPC frame parser, may trigger improper validation of an input-specified position or offset, resulting in an out-of-range substring operation. A malicious actor may leverage this vulnerability to cause the NT AUTHORITY\SYSTEM service to terminate unexpectedly, resulting in a denial-of-service condition.

Affected products

Installer
  • <2.23.0

Matching in nixpkgs

pkgs.calaos_installer

Calaos Installer, a tool to create calaos configuration

  • nixos-unstable 3.11
    • nixpkgs-unstable 3.11
    • nixos-unstable-small 3.11
  • nixos-26.05 3.11
    • nixos-26.05-small 3.11
    • nixpkgs-26.05-darwin 3.11

pkgs.melonloader-installer

Automated installer for MelonLoader, the universal mod-loader for games built in the Unity Engine

pkgs.gnomeExtensions.shell-easy-uninstaller

Add an uninstall option to the right-click menu of applications in the App Grid and Dash.

  • nixos-unstable 3
    • nixpkgs-unstable 3
    • nixos-unstable-small 8
  • nixos-26.05 3
    • nixos-26.05-small 3
    • nixpkgs-26.05-darwin 3

Package maintainers

Untriaged
created 4 months, 2 weeks ago Activity log
  • Created suggestion
ObjectInputStream.readObject() without ObjectInputFilter in fabric-sdk-java allows Java deserialization RCE

Hyperledger Fabric is an enterprise-grade permissioned distributed ledger framework for developing solutions and applications. From versions 1.0.0 to 2.2.26, Channel.java implements readObject() and exposes deSerializeChannel() which call ObjectInputStream.readObject() on untrusted byte arrays without configuring an ObjectInputFilter. This is a classic Java deserialization RCE pattern. At time of publication, there are no publicly available patches.

Affected products

fabric
  • ==>= 1.0.0, <= 2.2.26

Matching in nixpkgs

pkgs.Fabric

Pythonic remote execution

  • nixos-unstable -
    • nixos-unstable-small 3.2.3
  • nixos-26.05 -
    • nixos-26.05-small 3.2.2

pkgs.fabric

Pythonic remote execution

  • nixos-unstable -
    • nixos-unstable-small 3.2.3

pkgs.fabric-ai

Fabric is an open-source framework for augmenting humans using AI. It provides a modular framework for solving specific problems using a crowdsourced set of AI prompts that can be used anywhere

  • nixos-unstable -
  • nixos-26.05 -

pkgs.libfabric

Open Fabric Interfaces

  • nixos-unstable -
    • nixos-unstable-small 2.6.0
  • nixos-26.05 -
    • nixos-26.05-small 2.5.1

pkgs.fabric-installer

Lightweight, experimental modding toolchain for Minecraft

  • nixos-unstable -
    • nixos-unstable-small 1.1.2
  • nixos-26.05 -
    • nixos-26.05-small 1.1.1

pkgs.hyperledger-fabric

High-performance, secure, permissioned blockchain network

  • nixos-unstable -
  • nixos-26.05 -