Nixpkgs Security Tracker

Login with GitHub

Suggestions search

With package: python313Packages.pytorch-lightning

Found 3 matching suggestions

View:
Compact
Detailed
Untriaged
Permalink CVE-2026-4538
5.3 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV):
  • Attack complexity (AC):
  • Privileges required (PR):
  • User interaction (UI):
  • Scope (S):
  • Confidentiality impact (C):
  • Integrity impact (I):
  • Availability impact (A):
created 1 week ago
PyTorch pt2 Loading deserialization

A vulnerability was identified in PyTorch 2.10.0. The affected element is an unknown function of the component pt2 Loading Handler. The manipulation leads to deserialization. The attack can only be performed from a local environment. The exploit is publicly available and might be used. The project was informed of the problem early through a pull request but has not reacted yet.

Affected products

PyTorch
  • ==2.10.0

Matching in nixpkgs

Package maintainers

Untriaged
Permalink CVE-2026-24747
8.8 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): REQUIRED
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): HIGH
created 2 months ago
PyTorch Vulnerable to Remote Code Execution via Untrusted Checkpoint Files

PyTorch is a Python package that provides tensor computation. Prior to version 2.10.0, a vulnerability in PyTorch's `weights_only` unpickler allows an attacker to craft a malicious checkpoint file (`.pth`) that, when loaded with `torch.load(..., weights_only=True)`, can corrupt memory and potentially lead to arbitrary code execution. Version 2.10.0 fixes the issue.

Affected products

pytorch
  • ==< 2.10.0

Matching in nixpkgs

Package maintainers

Untriaged
Permalink CVE-2024-31386
4.3 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): REQUIRED
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): NONE
  • Integrity impact (I): LOW
  • Availability impact (A): NONE
created 6 months, 1 week ago
Multiple WordPress themes affected by Cross-Site Request Forgery vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in Hidekazu Ishikawa X-T9, Hidekazu Ishikawa Lightning, themeinwp Default Mag, Out the Box Namaha, Out the Box CityLogic, Marsian i-max, Jetmonsters Emmet Lite, Macho Themes Decode, Wayneconnor Sliding Door, Out the Box Shopstar!, Modernthemesnet Gridsby, TT Themes HappenStance, Marsian i-excel, Out the Box Panoramic, Modernthemesnet Sensible WP.This issue affects X-T9: from n/a through 1.19.0; Lightning: from n/a through 15.18.0; Default Mag: from n/a through 1.3.5; Namaha: from n/a through 1.0.40; CityLogic: from n/a through 1.1.29; i-max: from n/a through 1.6.2; Emmet Lite: from n/a through 1.7.5; Decode: from n/a through 3.15.3; Sliding Door: from n/a through 3.3; Shopstar!: from n/a through 1.1.33; Gridsby: from n/a through 1.3.0; HappenStance: from n/a through 3.0.1; i-excel: from n/a through 1.7.9; Panoramic: from n/a through 1.1.56; Sensible WP: from n/a through 1.3.1.

References

Affected products

x-t9
  • =<1.19.0
i-max
  • =<1.6.2
decode
  • =<3.15.3
namaha
  • =<1.0.40
gridsby
  • =<1.3.0
i-excel
  • =<1.7.9
shopstar
  • =<1.1.33
citylogic
  • =<1.1.29
lightning
  • =<15.18.0
panoramic
  • =<1.1.56
emmet-lite
  • =<1.7.5
default-mag
  • =<1.3.5
sensible-wp
  • =<1.3.1
happenstance
  • =<3.0.1
sliding-door
  • =<3.3

Matching in nixpkgs

pkgs.decoder

"secrets" decoding for FRITZ!OS devices

pkgs.dmidecode

Tool that reads information about your system's hardware from the BIOS according to the SMBIOS/DMI standard

  • nixos-unstable -

pkgs.lightning

Run-time code generation library

  • nixos-unstable -

pkgs.clightning

Bitcoin Lightning Network implementation in C

  • nixos-unstable -

pkgs.tivodecode

Converts a .TiVo file (produced by TiVoToGo) to a normal MPEG file

pkgs.lightningcss

Extremely fast CSS parser, transformer, and minifier written in Rust

  • nixos-unstable -

pkgs.lightning-terminal

All-in-one Lightning node management tool that includes LND, Loop, Pool, Faraday, and Tapd

Package maintainers