Nixpkgs security tracker

Try the new UI
Login with GitHub

Suggestions search

With package: python314Packages.huaweicloudsdkcodeartspipeline

Found 5 matching suggestions

View:
Compact
Detailed
Dismissed
(not in Nixpkgs)
Permalink CVE-2026-72708
8.7 HIGH
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): High (H)
  • Vulnerable System Impact Integrity (VI): None (N)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): High (H)
  • Modified Vulnerable System Impact Integrity (MVI): None (N)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
updated 1 week, 1 day ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
SPIP < 4.4.18 Unauthenticated SQL Injection via sitemap annee Parameter

SPIP before 4.4.18 contains an unauthenticated blind SQL injection vulnerability in the public sitemap endpoint where the MySQL escaper spip_mysql_cite() in ecrire/req/mysql.php returns values unescaped when the target column is a date type and the supplied value matches the pattern of a word character followed by an open parenthesis. Attackers can supply a crafted value such as a time-based payload through the annee parameter in squelettes-dist/sitemap.xml.html to embed arbitrary SQL directly into the generated query, enabling time-based and boolean-based blind SQL injection that can expose arbitrary database content including the alea_ephemere secret used to sign action nonces.

References

Affected products

SPIP
  • <4.4.18

Matching in nixpkgs

pkgs.spiped

Utility for secure encrypted channels between sockets

pkgs.aespipe

AES encrypting or decrypting pipe

  • nixos-unstable 2.4j
    • nixpkgs-unstable 2.4j
    • nixos-unstable-small 2.4j
  • nixos-26.05 2.4j
    • nixos-26.05-small 2.4j
    • nixpkgs-26.05-darwin 2.4j

pkgs.lesspipe

Preprocessor for less

  • nixos-unstable 2.20
    • nixpkgs-unstable 2.20
    • nixos-unstable-small 2.20
  • nixos-26.05 2.20
    • nixos-26.05-small 2.20
    • nixpkgs-26.05-darwin 2.20

Package maintainers

Untriaged
Permalink CVE-2026-72709
9.3 CRITICAL
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): High (H)
  • Vulnerable System Impact Integrity (VI): High (H)
  • Vulnerable System Impact Availability (VA): High (H)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): High (H)
  • Modified Vulnerable System Impact Integrity (MVI): High (H)
  • Modified Vulnerable System Impact Availability (MVA): High (H)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 1 week, 1 day ago Activity log
  • Created suggestion
SPIP < 4.4.18 Missing Authorization via ecrire/action/ editer_auteur

SPIP before 4.4.18 contains a missing authorization vulnerability in the administrative action endpoints under ecrire/action/ that allows unauthenticated attackers to perform privileged actions by supplying a valid HMAC-SHA256 nonce without any server-side permission check via autoriser(). Attackers can obtain a valid nonce, compute it for any action as the anonymous user, and invoke the editer_auteur action directly over HTTP to reset the password of any user account, including the administrator.

References

Affected products

SPIP
  • <4.4.18

Matching in nixpkgs

pkgs.spiped

Utility for secure encrypted channels between sockets

  • nixos-unstable -
    • nixos-unstable-small 1.6.4
  • nixos-26.05 -
    • nixos-26.05-small 1.6.4

pkgs.aespipe

AES encrypting or decrypting pipe

  • nixos-unstable -
    • nixos-unstable-small 2.4j
  • nixos-26.05 -
    • nixos-26.05-small 2.4j

pkgs.lesspipe

Preprocessor for less

  • nixos-unstable -
    • nixos-unstable-small 2.20
  • nixos-26.05 -
    • nixos-26.05-small 2.20

pkgs.crosspipe

PipeWire graph GTK4/Libadwaita GUI

  • nixos-unstable -
    • nixos-unstable-small 0.1.1
  • nixos-26.05 -
    • nixos-26.05-small 0.1.1

Package maintainers

Untriaged
Permalink CVE-2026-72710
9.3 CRITICAL
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): High (H)
  • Vulnerable System Impact Integrity (VI): High (H)
  • Vulnerable System Impact Availability (VA): High (H)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): High (H)
  • Modified Vulnerable System Impact Integrity (MVI): High (H)
  • Modified Vulnerable System Impact Availability (MVA): High (H)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 1 week, 1 day ago Activity log
  • Created suggestion
SPIP < 4.4.18 Remote Code Execution via editer_objet.php Job Queue Injection

SPIP before 4.4.18 contains a remote code execution vulnerability in the editer_objet action where the arg parameter resolves SQL table names without enforcing an editable columns allowlist, allowing attackers with a valid nonce to inject attacker-controlled rows into the spip_jobs table. Attackers can supply arg=job/0 with crafted fonction and args values, which are later unserialized and executed when the cron job queue is drained, resulting in arbitrary PHP function execution on the underlying system.

References

Affected products

SPIP
  • <4.4.18

Matching in nixpkgs

pkgs.spiped

Utility for secure encrypted channels between sockets

  • nixos-unstable -
    • nixos-unstable-small 1.6.4
  • nixos-26.05 -
    • nixos-26.05-small 1.6.4

pkgs.aespipe

AES encrypting or decrypting pipe

  • nixos-unstable -
    • nixos-unstable-small 2.4j
  • nixos-26.05 -
    • nixos-26.05-small 2.4j

pkgs.lesspipe

Preprocessor for less

  • nixos-unstable -
    • nixos-unstable-small 2.20
  • nixos-26.05 -
    • nixos-26.05-small 2.20

pkgs.crosspipe

PipeWire graph GTK4/Libadwaita GUI

  • nixos-unstable -
    • nixos-unstable-small 0.1.1
  • nixos-26.05 -
    • nixos-26.05-small 0.1.1

Package maintainers

Untriaged
Permalink CVE-2026-77806
9.8 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 4 weeks, 1 day ago Activity log
  • Created suggestion
SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary …

SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to code injection via an X-Spip-Filtre HTTP request header that is mishandled by analyse_resultat_skel.

Affected products

SPIP
  • <4.4.21

Matching in nixpkgs

pkgs.spiped

Utility for secure encrypted channels between sockets

  • nixos-unstable -
    • nixos-unstable-small 1.6.4
  • nixos-26.05 -
    • nixos-26.05-small 1.6.4

pkgs.aespipe

AES encrypting or decrypting pipe

  • nixos-unstable -
    • nixos-unstable-small 2.4j
  • nixos-26.05 -
    • nixos-26.05-small 2.4j

pkgs.lesspipe

Preprocessor for less

  • nixos-unstable -
    • nixos-unstable-small 2.20
  • nixos-26.05 -
    • nixos-26.05-small 2.20

pkgs.crosspipe

PipeWire graph GTK4/Libadwaita GUI

  • nixos-unstable -
    • nixos-unstable-small 0.1.1
  • nixos-26.05 -
    • nixos-26.05-small 0.1.1

Package maintainers

Untriaged
Permalink CVE-2026-77647
9.8 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 4 weeks, 2 days ago Activity log
  • Created suggestion
SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary …

SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to incorrect identification of <?php blocks, and var_export's mishandling of certain cases such as presence of a '<' character.

Affected products

SPIP
  • <4.4.20

Matching in nixpkgs

pkgs.spiped

Utility for secure encrypted channels between sockets

  • nixos-unstable -
    • nixos-unstable-small 1.6.4
  • nixos-26.05 -
    • nixos-26.05-small 1.6.4

pkgs.aespipe

AES encrypting or decrypting pipe

  • nixos-unstable -
    • nixos-unstable-small 2.4j
  • nixos-26.05 -
    • nixos-26.05-small 2.4j

pkgs.lesspipe

Preprocessor for less

  • nixos-unstable -
    • nixos-unstable-small 2.20
  • nixos-26.05 -
    • nixos-26.05-small 2.20

pkgs.crosspipe

PipeWire graph GTK4/Libadwaita GUI

  • nixos-unstable -
    • nixos-unstable-small 0.1.1
  • nixos-26.05 -
    • nixos-26.05-small 0.1.1

Package maintainers