Nixpkgs security tracker

Try the new UI
Login with GitHub

Suggestions search

With package: python313Packages.tag-expressions

Found 2 matching suggestions

View:
Compact
Detailed
Permalink CVE-2026-77550
10.0 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 3 weeks, 5 days ago Activity log
  • Created suggestion
A malicious actor with access to the network could exploit …

A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass authentication to such UniFi OS devices or instances.

Affected products

Express
  • <4.0.17
Express 7
  • <5.1.31
Cloud Keys
  • <5.1.31
Dream Wall
  • <5.1.31
Dream Routers
  • <5.1.31
Cloud Gateways
  • <5.1.31
Dream Machines
  • <5.1.31
UniFi OS Server
  • <5.1.37
Network Video Recorders
  • <5.1.31
Enterprise Firewall Core
  • <5.1.31
Network Attached Storage
  • <5.1.32
Enterprise Fortress Gateway
  • <5.1.31
Enterprise Network Video Recorders
  • <5.1.31
Enterprise Network Attached Storage
  • <5.1.31

Matching in nixpkgs

pkgs.expressvpn

CLI client for ExpressVPN

  • nixos-unstable -
  • nixos-26.05 -

pkgs.opteeQemuAarch64

Trusted Execution Environment for ARM

  • nixos-unstable -
    • nixos-unstable-small 4.7.0
  • nixos-26.05 -
    • nixos-26.05-small 4.7.0

pkgs.expresslrs-configurator

Cross-platform build & configuration tool for ExpressLRS

  • nixos-unstable -
    • nixos-unstable-small 1.8.3
  • nixos-26.05 -

pkgs.haskellPackages.express

Dynamically-typed expressions involving function application and variables

  • nixos-unstable -
  • nixos-26.05 -

Package maintainers

Permalink CVE-2026-77549
9.0 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 3 weeks, 5 days ago Activity log
  • Created suggestion
A malicious actor with access to the network and under …

A malicious actor with access to the network and under certain conditions could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass authentication to such UniFi OS devices or instances.

Affected products

Express
  • <4.0.17
Express 7
  • <5.1.31
Cloud Keys
  • <5.1.31
Dream Wall
  • <5.1.31
Dream Routers
  • <5.1.31
Cloud Gateways
  • <5.1.31
Dream Machines
  • <5.1.31
UniFi OS Server
  • <5.1.37
Network Video Recorders
  • <5.1.31
Enterprise Firewall Core
  • <5.1.31
Network Attached Storage
  • <5.1.32
Enterprise Fortress Gateway
  • <5.1.31
Enterprise Network Video Recorders
  • <5.1.31
Enterprise Network Attached Storage
  • <5.1.31

Matching in nixpkgs

pkgs.expressvpn

CLI client for ExpressVPN

  • nixos-unstable -
  • nixos-26.05 -

pkgs.opteeQemuAarch64

Trusted Execution Environment for ARM

  • nixos-unstable -
    • nixos-unstable-small 4.7.0
  • nixos-26.05 -
    • nixos-26.05-small 4.7.0

pkgs.expresslrs-configurator

Cross-platform build & configuration tool for ExpressLRS

  • nixos-unstable -
    • nixos-unstable-small 1.8.3
  • nixos-26.05 -

pkgs.haskellPackages.express

Dynamically-typed expressions involving function application and variables

  • nixos-unstable -
  • nixos-26.05 -

Package maintainers