Nixpkgs security tracker

Try the new UI
Login with GitHub

Suggestions search

With package: python313Packages.steamworkspy

Found 4 matching suggestions

View:
Compact
Detailed
Dismissed
(not in Nixpkgs)
Permalink CVE-2026-95592
5.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
updated 5 days, 19 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
WordPress Team plugin <= 6.0.0 - Insecure Direct Object References (IDOR) vulnerability

Unauthenticated Insecure Direct Object References (IDOR) in Team <= 6.0.0 versions.

Affected products

tlp-team
  • =<6.0.0

Matching in nixpkgs

pkgs.steam

Digital distribution platform

  • nixos-unstable -
  • nixos-26.05 -

pkgs.git-team

Command line interface for managing and enhancing git commit messages with co-authors

  • nixos-unstable -
    • nixos-unstable-small 2.0.0
  • nixos-26.05 -
    • nixos-26.05-small 1.8.1

pkgs.steamcmd

Steam command-line tools

  • nixos-unstable -
  • nixos-26.05 -

pkgs.teamocil

Simple tool used to automatically create windows and panes in tmux with YAML files

  • nixos-unstable -
    • nixos-unstable-small 1.4.2
  • nixos-26.05 -
    • nixos-26.05-small 1.4.2

pkgs.teamtype

Real-time co-editing of local text files

  • nixos-unstable -
    • nixos-unstable-small 0.9.2
  • nixos-26.05 -
    • nixos-26.05-small 0.9.2

pkgs.ethersync

Real-time co-editing of local text files

  • nixos-unstable -
    • nixos-unstable-small 0.9.2
  • nixos-26.05 -
    • nixos-26.05-small 0.9.2

pkgs.steam-acf

Tool to convert Steam .acf files to JSON

  • nixos-unstable -
    • nixos-unstable-small 0.1.0
  • nixos-26.05 -
    • nixos-26.05-small 0.1.0

pkgs.steam-run

Run commands in the same FHS environment that is used for Steam

  • nixos-unstable -
  • nixos-26.05 -

pkgs.steam-tui

Rust TUI client for steamcmd

  • nixos-unstable -
    • nixos-unstable-small 0.3.0
  • nixos-26.05 -
    • nixos-26.05-small 0.3.0

pkgs.steamback

Decky plugin to add versioned save-game snapshots to Steam-cloud enabled games

  • nixos-unstable -
    • nixos-unstable-small 0.3.6
  • nixos-26.05 -
    • nixos-26.05-small 0.3.6

pkgs.steampipe

Dynamically query your cloud, code, logs & more with SQL

  • nixos-unstable -
    • nixos-unstable-small 2.4.7
  • nixos-26.05 -
    • nixos-26.05-small 2.4.5

pkgs.steamworks

Configuration information distributed over LDAP in near realtime

  • nixos-unstable -
  • nixos-26.05 -

pkgs.teamviewer

Desktop sharing application, providing remote support and online meetings

  • nixos-unstable -
  • nixos-26.05 -

pkgs.adwsteamgtk

Simple Gtk wrapper for Adwaita-for-Steam

  • nixos-unstable -
    • nixos-unstable-small 0.8.0
  • nixos-26.05 -
    • nixos-26.05-small 0.8.0

pkgs.bitlbee-steam

Steam protocol plugin for BitlBee

  • nixos-unstable -
    • nixos-unstable-small 1.4.2
  • nixos-26.05 -
    • nixos-26.05-small 1.4.2

pkgs.ArchiSteamFarm

Application with primary purpose of idling Steam cards from multiple accounts simultaneously

  • nixos-unstable -
  • nixos-26.05 -

pkgs.archisteamfarm

Application with primary purpose of idling Steam cards from multiple accounts simultaneously

  • nixos-unstable -
  • nixos-26.05 -

pkgs.steam-run-free

Run commands in the same FHS environment that is used for Steam

  • nixos-unstable -
  • nixos-26.05 -

pkgs.steamguard-cli

Linux utility for generating 2FA codes for Steam and managing Steam trade confirmations

  • nixos-unstable -
  • nixos-26.05 -

pkgs.teams-for-linux

Unofficial Microsoft Teams client for Linux

  • nixos-unstable -
  • nixos-26.05 -

pkgs.teamspeak_server

TeamSpeak voice communication server

  • nixos-unstable -
  • nixos-26.05 -

pkgs.steam-art-manager

A tool to manage and change Steam library artwork

  • nixos-unstable -
  • nixos-26.05 -

pkgs.steamvr-linux-fixes

Vulkan layer that patches SteamVR vrcompositor for wired HMDs

  • nixos-unstable -
    • nixos-unstable-small 0.1.4

pkgs.vimPlugins.teamtype

Real-time co-editing of local text files

  • nixos-unstable -
    • nixos-unstable-small 0.9.2
  • nixos-26.05 -
    • nixos-26.05-small 0.9.2

pkgs.steam-lancache-prefill

Automatically fills a Lancache with games from Steam

  • nixos-unstable -
    • nixos-unstable-small 3.6.1
  • nixos-26.05 -
    • nixos-26.05-small 3.4.2

pkgs.python313Packages.steamodd

High level Steam API implementation with low level reusable core

  • nixos-unstable -
    • nixos-unstable-small 5.0
  • nixos-26.05 -
    • nixos-26.05-small 5.0

pkgs.python314Packages.steamodd

High level Steam API implementation with low level reusable core

  • nixos-unstable -
    • nixos-unstable-small 5.0
  • nixos-26.05 -
    • nixos-26.05-small 5.0

pkgs.gnomeExtensions.add-to-steam

Add executables to steam without having to open, or restart steam; Just like SteamOS.

  • nixos-unstable -
    • nixos-unstable-small 4
  • nixos-26.05 -
    • nixos-26.05-small 3

Package maintainers

Dismissed
(not in Nixpkgs)
Permalink CVE-2026-9038
8.6 HIGH
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Physical (P)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): High (H)
  • Vulnerable System Impact Integrity (VI): High (H)
  • Vulnerable System Impact Availability (VA): High (H)
  • Subsequent System Impact Confidentiality (SC): High (H)
  • Subsequent System Impact Integrity (SI): High (H)
  • Subsequent System Impact Availability (SA): High (H)
  • Modified Attack Vector (MAV): Physical (P)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): High (H)
  • Modified Vulnerable System Impact Integrity (MVI): High (H)
  • Modified Vulnerable System Impact Availability (MVA): High (H)
  • Modified Subsequent System Impact Confidentiality (MSC): High (H)
  • Modified Subsequent System Impact Integrity (MSI): High (H)
  • Modified Subsequent System Impact Availability (MSA): High (H)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
updated 4 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
Stack-based buffer overflow in XCharge C6

A stack-based buffer overflow vulnerability in the charging controller’s signal-processing logic allows an attacker with physical access to the charging interface to supply message fields that exceed expected bounds. Because the input is not sufficiently validated, memory corruption may occur, which can lead to execution of unauthorized code with elevated privileges.

Affected products

C6
  • <May_22_2026

Matching in nixpkgs

pkgs.cc65

C compiler for processors of 6502 family

  • nixos-unstable 2.19
    • nixpkgs-unstable 2.19
    • nixos-unstable-small 2.19

pkgs.ndisc6

Small collection of useful tools for IPv6 networking

pkgs.libiec61850

Open-source library for the IEC 61850 protocols

pkgs.crc64fast-nvme

SIMD accelerated carryless-multiplication CRC-64/NVME checksum computation (based on Intel's PCLMULQDQ paper)

pkgs.vimpager-latest

Use Vim as PAGER

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small
Dismissed
(not in Nixpkgs)
Permalink CVE-2026-9039
8.6 HIGH
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Physical (P)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): High (H)
  • Vulnerable System Impact Integrity (VI): High (H)
  • Vulnerable System Impact Availability (VA): High (H)
  • Subsequent System Impact Confidentiality (SC): High (H)
  • Subsequent System Impact Integrity (SI): High (H)
  • Subsequent System Impact Availability (SA): High (H)
  • Modified Attack Vector (MAV): Physical (P)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): High (H)
  • Modified Vulnerable System Impact Integrity (MVI): High (H)
  • Modified Vulnerable System Impact Availability (MVA): High (H)
  • Modified Subsequent System Impact Confidentiality (MSC): High (H)
  • Modified Subsequent System Impact Integrity (MSI): High (H)
  • Modified Subsequent System Impact Availability (MSA): High (H)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
updated 4 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
Initialization of a resource with an insecure default in XCharge C6

A configuration weakness in the device’s remote management service allows an authenticated session to be established over a communication channel intended solely for vehicle-charger signaling. The service is accessible on interfaces exposed through the charging connector, and it accepts a default administrative credential. A malicious device physically connected to the charging interface could leverage this misconfiguration to obtain full administrative access.

Affected products

C6
  • <May_22_2026

Matching in nixpkgs

pkgs.cc65

C compiler for processors of 6502 family

  • nixos-unstable 2.19
    • nixpkgs-unstable 2.19
    • nixos-unstable-small 2.19

pkgs.ndisc6

Small collection of useful tools for IPv6 networking

pkgs.libiec61850

Open-source library for the IEC 61850 protocols

pkgs.crc64fast-nvme

SIMD accelerated carryless-multiplication CRC-64/NVME checksum computation (based on Intel's PCLMULQDQ paper)

pkgs.vimpager-latest

Use Vim as PAGER

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small
Dismissed
(not in Nixpkgs)
Permalink CVE-2026-9037
9.3 CRITICAL
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): High (H)
  • Vulnerable System Impact Integrity (VI): High (H)
  • Vulnerable System Impact Availability (VA): High (H)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): High (H)
  • Modified Vulnerable System Impact Integrity (MVI): High (H)
  • Modified Vulnerable System Impact Availability (MVA): High (H)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
updated 4 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
Download of code without integrity check in XCharge C6

A firmware update mechanism in the affected charging controller fails to validate the authenticity of firmware packages delivered through the device's management interface. Because cryptographic signatures are not verified, an attacker with the ability to interfere with or impersonate the management channel could cause the device to install an unauthorized firmware package. This condition could allow execution of unauthorized code with high privileges on the device.

Affected products

C6
  • <May_22_2026

Matching in nixpkgs

pkgs.cc65

C compiler for processors of 6502 family

  • nixos-unstable 2.19
    • nixpkgs-unstable 2.19
    • nixos-unstable-small 2.19

pkgs.ndisc6

Small collection of useful tools for IPv6 networking

pkgs.libiec61850

Open-source library for the IEC 61850 protocols

pkgs.crc64fast-nvme

SIMD accelerated carryless-multiplication CRC-64/NVME checksum computation (based on Intel's PCLMULQDQ paper)

pkgs.vimpager-latest

Use Vim as PAGER

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small