Nixpkgs security tracker

Login with GitHub

Suggestions search

With package: piglit

Found 2 matching suggestions

View:
Compact
Detailed
Untriaged
Permalink CVE-2026-91995
9.3 CRITICAL
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): High (H)
  • Vulnerable System Impact Integrity (VI): High (H)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): High (H)
  • Modified Vulnerable System Impact Integrity (MVI): High (H)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 57 minutes ago Activity log
  • Created suggestion
pig before 4.1.0 Unverified Password Change via /register/password

pig before 4.1.0 contains an authentication bypass vulnerability in the /register/password endpoint where password verification results are discarded, allowing any value as the current password. Remote attackers can submit a username with an incorrect current password to overwrite any account credential including the admin account and gain full administrative control.

Affected products

pig
  • <4.1.0

Matching in nixpkgs

pkgs.pigz

Parallel implementation of gzip for multi-core machines

  • nixos-unstable 2.8
    • nixpkgs-unstable 2.8
    • nixos-unstable-small 2.8
  • nixos-26.05 2.8
    • nixos-26.05-small 2.8
    • nixpkgs-26.05-darwin 2.8

pkgs.dhcpig

Tool to perform advanced DHCP exhaustion attack

  • nixos-unstable 1.6
    • nixpkgs-unstable 1.6
    • nixos-unstable-small 1.6
  • nixos-26.05 1.6
    • nixos-26.05-small 1.6
    • nixpkgs-26.05-darwin 1.6

pkgs.pigeon

PEG parser generator for Go

pkgs.pigpio

C library for the Raspberry which allows control of the General Purpose Input Outputs (GPIO)

  • nixos-unstable 79
    • nixpkgs-unstable 79
    • nixos-unstable-small 79
  • nixos-26.05 79
    • nixos-26.05-small 79
    • nixpkgs-26.05-darwin 79

pkgs.pigeons

Connect to any machine behind a NAT or firewall with plain SSH

  • nixos-unstable -
    • nixos-unstable-small 0.2.1

pkgs.pigment

Extract color palettes from your images

pkgs.python313Packages.pigpio

C library for the Raspberry which allows control of the General Purpose Input Outputs (GPIO)

  • nixos-unstable 79
    • nixpkgs-unstable 79
    • nixos-unstable-small 79
  • nixos-26.05 79
    • nixos-26.05-small 79
    • nixpkgs-26.05-darwin 79

pkgs.python314Packages.pigpio

C library for the Raspberry which allows control of the General Purpose Input Outputs (GPIO)

  • nixos-unstable 79
    • nixpkgs-unstable 79
    • nixos-unstable-small 79
  • nixos-26.05 79
    • nixos-26.05-small 79
    • nixpkgs-26.05-darwin 79

pkgs.gnomeExtensions.pigeon-email-notifier

Email notifier for Gmail, Outlook, and IMAP using GNOME Online Accounts

  • nixos-unstable 6
    • nixpkgs-unstable 6
    • nixos-unstable-small 6
  • nixos-26.05 6
    • nixos-26.05-small 6
    • nixpkgs-26.05-darwin 6
Dismissed
(not in Nixpkgs)
Permalink CVE-2026-15512
2.1 LOW
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): Low (L)
  • Vulnerable System Impact Integrity (VI): Low (L)
  • Vulnerable System Impact Availability (VA): Low (L)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Exploit Maturity (E): POC (P)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
  • Modified Vulnerable System Impact Integrity (MVI): Low (L)
  • Modified Vulnerable System Impact Availability (MVA): Low (L)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
updated 2 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
pig-mesh Pig pig-codegen GeneratorServiceImpl.java code injection

A vulnerability was identified in pig-mesh Pig up to 3.9.2. Affected by this issue is some unknown functionality of the file \pig-master\pig-visual\pig-codegen\src\main\java\com\pig4cloud\pig\codegen\service\impl\GeneratorServiceImpl.java of the component pig-codegen. Such manipulation leads to code injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

Affected products

Pig
  • ==3.9.2
  • ==3.9.1
  • ==3.9.0

Matching in nixpkgs

pkgs.pigz

Parallel implementation of gzip for multi-core machines

  • nixos-unstable 2.8
    • nixpkgs-unstable 2.8
    • nixos-unstable-small 2.8
  • nixos-26.05 2.8
    • nixos-26.05-small 2.8
    • nixpkgs-26.05-darwin 2.8

pkgs.dhcpig

Tool to perform advanced DHCP exhaustion attack

  • nixos-unstable 1.6
    • nixpkgs-unstable 1.6
    • nixos-unstable-small 1.6
  • nixos-26.05 1.6
    • nixos-26.05-small 1.6
    • nixpkgs-26.05-darwin 1.6

pkgs.pigeon

PEG parser generator for Go

pkgs.pigpio

C library for the Raspberry which allows control of the General Purpose Input Outputs (GPIO)

  • nixos-unstable 79
    • nixpkgs-unstable 79
    • nixos-unstable-small 79
  • nixos-26.05 79
    • nixos-26.05-small 79
    • nixpkgs-26.05-darwin 79

pkgs.pigment

Extract color palettes from your images

pkgs.python313Packages.pigpio

C library for the Raspberry which allows control of the General Purpose Input Outputs (GPIO)

  • nixos-unstable 79
    • nixpkgs-unstable 79
    • nixos-unstable-small 79
  • nixos-26.05 79
    • nixos-26.05-small 79
    • nixpkgs-26.05-darwin 79

pkgs.python314Packages.pigpio

C library for the Raspberry which allows control of the General Purpose Input Outputs (GPIO)

  • nixos-unstable 79
    • nixpkgs-unstable 79
    • nixos-unstable-small 79
  • nixos-26.05 79
    • nixos-26.05-small 79
    • nixpkgs-26.05-darwin 79

pkgs.gnomeExtensions.pigeon-email-notifier

Gmail and Microsoft email notifier using GNOME Online Accounts

  • nixos-unstable 6
    • nixpkgs-unstable 6
    • nixos-unstable-small 6
  • nixos-26.05 6
    • nixos-26.05-small 6
    • nixpkgs-26.05-darwin 6

Package maintainers