Nixpkgs security tracker

Login with GitHub

Dismissed suggestions

These automatic suggestions were dismissed after initial triaging.

to select a suggestion for revision.

View:
Compact
Detailed
Dismissed
(not in Nixpkgs)
Permalink CVE-2026-43002
5.3 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): NONE
  • Integrity impact (I): NONE
  • Availability impact (A): LOW
updated 41 seconds ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
An issue was discovered in OpenStack Horizon 25.6 and 25.7 …

An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There is a write operation to the session storage backend before authentication and thus storage can be exhausted by unauthenticated requests. This is a regression of the CVE-2014-8124 fix.

Affected products

Horizon
  • <25.7.3

Matching in nixpkgs

pkgs.horizon-eda

Free EDA software to develop printed circuit boards

Package maintainers

Dismissed
(not in Nixpkgs)
Permalink CVE-2026-41950
6.5 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): NONE
  • Availability impact (A): NONE
updated a minute ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
Dify < 1.14.0 Authorization Bypass via File UUID

Dify before version 1.14.0 contains an authorization bypass vulnerability that allows authenticated users to read the full contents of files uploaded by other users within the same tenant by supplying an arbitrary file UUID in the files array of a chat-messages request. Attackers can exploit insufficient permission verification in the chat-messages endpoints to access files without ownership validation, bypassing workspace separation and signed URL protections to retrieve sensitive file contents through workflow processing.

Affected products

dify
  • <1.14.0

Matching in nixpkgs

Package maintainers

Dismissed
(not in Nixpkgs)
updated 2 minutes ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
Long-poll NDJSON body splitting causes unbounded memory allocation in Phoenix

Allocation of Resources Without Limits or Throttling vulnerability in phoenixframework phoenix allows a denial of service via the long-poll transport's NDJSON body handling. In 'Elixir.Phoenix.Transports.LongPoll':publish/4, when a POST request is received with Content-Type: application/x-ndjson, the request body is split on newline characters using String.split/2 with no limit on the number of resulting segments. An attacker can send a body consisting entirely of newline bytes, causing a 1:1 amplification into a list of empty binaries — a 1 MB body produces approximately one million list elements, an 8 MB body approximately 8.4 million. Each element is then walked by Enum.map, materializing another list of the same size. This exhausts BEAM memory and schedulers, crashing the node and terminating all active sessions. A session token required to reach the vulnerable endpoint is freely obtainable by any client via an unauthenticated GET request to the same URL with a matching Origin header, making this attack effectively unauthenticated. This issue affects phoenix: from 1.7.0 before 1.7.22 and 1.8.6.

Affected products

phoenix
  • <1.7.22
  • <1.8.6
phoenixframework/phoenix
  • *

Matching in nixpkgs

pkgs.phoenixd

Server equivalent of the popular Phoenix wallet for mobile

Package maintainers

Dismissed
(not in Nixpkgs)
Permalink CVE-2026-7712
6.3 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV):
  • Attack complexity (AC):
  • Privileges required (PR):
  • User interaction (UI):
  • Scope (S):
  • Confidentiality impact (C):
  • Integrity impact (I):
  • Availability impact (A):
updated 1 day, 19 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
MindsDB Pickle pickle.loads deserialization

A security vulnerability has been detected in MindsDB up to 26.01. Affected is the function pickle.loads of the component Pickle Handler. The manipulation leads to deserialization. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Affected products

MindsDB
  • ==26.01

Matching in nixpkgs

Package maintainers

Dismissed
(not in Nixpkgs)
Permalink CVE-2026-7711
7.3 HIGH
  • CVSS version: 3.1
  • Attack vector (AV):
  • Attack complexity (AC):
  • Privileges required (PR):
  • User interaction (UI):
  • Scope (S):
  • Confidentiality impact (C):
  • Integrity impact (I):
  • Availability impact (A):
updated 1 day, 19 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
MindsDB Engine proc_wrapper.py exec unrestricted upload

A weakness has been identified in MindsDB up to 26.01. This impacts the function exec of the file mindsdb/integrations/handlers/byom_handler/proc_wrapper.py of the component Engine Handler. Executing a manipulation can lead to unrestricted upload. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

Affected products

MindsDB
  • ==26.01

Matching in nixpkgs

Package maintainers

Dismissed
(not in Nixpkgs)
Permalink CVE-2026-5077
5.4 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV):
  • Attack complexity (AC):
  • Privileges required (PR):
  • User interaction (UI):
  • Scope (S):
  • Confidentiality impact (C):
  • Integrity impact (I):
  • Availability impact (A):
updated 2 days, 20 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
Total <= 2.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Title in Blog Section Image alt Attribute

The Total theme for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in versions up to, and including, 2.2.1 due to insufficient output escaping when rendering the_title() inside HTML attribute context in the home blog section template. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the malicious post to be published and displayed with a featured image in the Home Page blog section.

Affected products

Total
  • =<2.2.1

Matching in nixpkgs

pkgs.autotalent

Real-time pitch correction LADSPA plugin (no MIDI control)

  • nixos-unstable 0.2
    • nixpkgs-unstable 0.2
    • nixos-unstable-small 0.2
  • nixos-25.11 0.2
    • nixos-25.11-small 0.2
    • nixpkgs-25.11-darwin 0.2

Package maintainers

Permalink CVE-2026-7601
4.3 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV):
  • Attack complexity (AC):
  • Privileges required (PR):
  • User interaction (UI):
  • Scope (S):
  • Confidentiality impact (C):
  • Integrity impact (I):
  • Availability impact (A):
updated 2 days, 20 hours ago by @LeSuisse Activity log
Open5GS AMF gmm-handler.c denial of service

A vulnerability has been found in Open5GS up to 2.7.6. Affected is an unknown function of the file src/amf/gmm-handler.c of the component AMF. The manipulation of the argument reg_type leads to denial of service. The attack is possible to be carried out remotely. Upgrading to version 2.7.7 is able to address this issue. The identifier of the patch is ebc66942b6f8f1fab2d640e71cf4e9f1a423b426. It is advisable to upgrade the affected component.

Affected products

Open5GS
  • ==2.7.7
  • ==2.7.4
  • ==2.7.0
  • ==2.7.2
  • ==2.7.5
  • ==2.7.1
  • ==2.7.3
  • ==2.7.6

Matching in nixpkgs

Ignored packages (1)

Package maintainers

Already fixed.
Dismissed
(not in Nixpkgs)
Permalink CVE-2026-7668
7.3 HIGH
  • CVSS version: 3.1
  • Attack vector (AV):
  • Attack complexity (AC):
  • Privileges required (PR):
  • User interaction (UI):
  • Scope (S):
  • Confidentiality impact (C):
  • Integrity impact (I):
  • Availability impact (A):
updated 2 days, 20 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
MikroTik RouterOS SCEP Endpoint scep.p ASN1_STRING_data out-of-bounds

A vulnerability was identified in MikroTik RouterOS 6.49.8. This vulnerability affects the function ASN1_STRING_data in the library nova/lib/www/scep.p of the component SCEP Endpoint. The manipulation of the argument transactionID/messageType leads to out-of-bounds read. The attack may be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

Affected products

RouterOS
  • ==6.49.8

Matching in nixpkgs

Package maintainers

Dismissed
(not in Nixpkgs)
Permalink CVE-2024-13362
6.1 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV):
  • Attack complexity (AC):
  • Privileges required (PR):
  • User interaction (UI):
  • Scope (S):
  • Confidentiality impact (C):
  • Integrity impact (I):
  • Availability impact (A):
updated 3 days, 18 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
Freemius <= 2.10.1 - Reflected DOM-Based Cross-Site Scripting via url Parameter

Multiple plugins and/or themes for WordPress are vulnerable to Reflected Cross-Site Scripting via the url parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

References

Affected products

Glossary
  • =<2.2.38
Ultimeter
  • =<3.0.5
Geo Mashup
  • =<1.13.15
Ocean Extra
  • =<2.4.2
Code Manager
  • =<1.0.40
Open User Map
  • =<1.4.0
Easy Age Verify
  • =<1.8.5
Mapster WP Maps
  • =<1.9.0
Share This Image
  • =<2.07
Widgets on Pages
  • =<1.7
Justified Gallery
  • =<1.9.0
WP Page Templates
  • =<1.1.16
Inavii Social Feed
  • =<2.7.0
Custom PHP Settings
  • =<2.3.1
Marijuana Age Verify
  • =<1.5.5
WP Notification Bell
  • =<1.4.2
Gallery by FooGallery
  • =<2.4.27
Independent Analytics
  • =<2.9.7
Team Members Showcase
  • =<3.3.0
Dynamic Copyright Year
  • =<1.0.4
Full Screen Background
  • =<2.0.2
Joli Table Of Contents
  • =<2.6.0
WP Meta and Date Remover
  • =<2.3.4
Automatic YouTube Gallery
  • =<2.5.5
Display Eventbrite Events
  • =<6.1.10
Delete Posts automatically
  • =<3.9.6
Events Addon for Elementor
  • =<2.2.2
Mixed Media Gallery Blocks
  • =<3.2.4.4
Embedder for Google Reviews
  • =<1.6.6
Five-Star Ratings Shortcode
  • =<1.2.56
Menu Image, Icons made easy
  • =<3.12
Primary Addon for Elementor
  • =<1.6.0
Pay For Post with WooCommerce
  • =<3.1.26
Payment Gateway for ACBA BANK
  • =<1.2.6
XT Quick View for WooCommerce
  • =<2.1.5
Remove Add to Cart WooCommerce
  • =<1.4.7
Thank You Page for WooCommerce
  • =<4.2.0
Contact Form 7 Multi-Step Forms
  • =<4.4.1
MapGeo – Interactive Geo Maps
  • =<1.6.22
Product Layouts for WooCommerce
  • =<1.3.1
StreamWeasels Twitch Integration
  • =<1.9.2
Text To Speech TTS Accessibility
  • =<1.7.34
Unlimited Elements For Elementor
  • =<1.5.140
XT Floating Cart for WooCommerce
  • =<2.8.4
Message Filter for Contact Form 7
  • =<1.6.3.2
WP fail2ban – Advanced Security
  • =<5.3.4
Go Fetch Jobs (for WP Job Manager)
  • =<1.8.4.8.1
Smart phone field for Gravity Forms
  • =<2.1.6
Advanced Classifieds & Directory Pro
  • =<3.2.4
WPIDE – File Manager & Code Editor
  • =<3.5.1
Checkout with Cash App on WooCommerce
  • =<6.0.2
Restaurant & Cafe Addon for Elementor
  • =<1.5.8
XT Variation Swatches for WooCommerce
  • =<1.9.4
Role Based Pricing for Woo by Meow Crew
  • =<1.6.0
Ivory Search – WordPress Search Plugin
  • =<5.5.8
Premmerce Product Filter for WooCommerce
  • =<3.7.3
WPBITS Addons For Elementor Page Builder
  • =<1.7
Automatic Internal Links for SEO by Pagup
  • =<2.0.0
Custom WooCommerce Checkout Fields Editor
  • =<1.3.4
Bulk Edit Posts and Products in Spreadsheet
  • =<2.25.16
Featured Images in RSS for Mailchimp & More
  • =<1.6.3
Place Order Without Payment for WooCommerce
  • =<2.6.5
Premmerce Permalink Manager for WooCommerce
  • =<2.3.11
TablePress – Tables in WordPress made easy
  • =<3.0.2
WP Shortcodes Plugin — Shortcodes Ultimate
  • =<7.3.3
GA4WP – Analytics Dashboard for the Website
  • =<2.6.0
Carousel, Recent Post Slider and Banner Slider
  • =<2.1
Goal Tracker – Custom Event Tracking for GA4
  • =<1.1.5
URL Shortify – Simple and Easy URL Shortener
  • =<1.10.4
Announcement & Notification Banner – Bulletin
  • =<3.12.1
RevivePress – Keep your Old Content Evergreen
  • =<1.5.8
Security Ninja – WordPress Security & Firewall
  • =<5.222
Anti-Spam Protection – No API Key, GDPR Friendly
  • =<2.3.7
Lightbox & Modal Popup WordPress Plugin – FooBox
  • =<2.7.33
AidWP – Donation & Payment Forms (Stripe Powered)
  • =<3.2.6
Internal Link Juicer: SEO Auto Linker for WordPress
  • =<2.24.6
PDF Poster – Display PDF Files with Custom Viewer
  • =<2.2.0
TreePress – Easy Family Trees & Ancestor Profiles
  • =<3.0.6
Post to Google My Business (Google Business Profile)
  • =<3.1.28
AWCA – The Great Analytics Insights for Your eStore
  • =<3.12.0
YASR – Yet Another Star Rating Plugin for WordPress
  • =<3.4.12
Coupon Affiliates – Affiliate Plugin for WooCommerce
  • =<5.17.2
Forumax – AI Powered Advanced Community Forum Plugin
  • =<1.2.7
WP Mobile Menu – The Mobile-Friendly Responsive Menu
  • =<2.8.6
Spotlight Social Feeds – Block, Shortcode, and Widget
  • =<1.7.0
File Manager for Google Drive – Integrate Google Drive
  • =<1.4.9
AI Puffer – Chat. Create. Automate. (formerly AI Power)
  • =<1.8.99
EleSpare – News, Magazine and Blog Addons for Elementor
  • =<3.3.2
Advanced Scrollbar – Custom Scrollbar Styling and Behavior
  • =<1.1.3
Music Player for Elementor – Audio Player & Podcast Player
  • =<2.4.1
Post List Designer – Category Post, Recent Post, Post List
  • =<3.3.7
bBlocks – Essential Gutenberg Blocks & Patterns Collection
  • =<1.9.8
Knowledge Base documentation & wiki plugin – BasePress Docs
  • =<2.16.3.3
WOW Styler for CF7 – Visual Styler for Contact Form 7 Forms
  • =<1.7.0
WP Coupons and Deals – Coupon Plugin For Affiliate Marketers
  • =<3.2.2
StoreCustomizer – A plugin to Customize all WooCommerce Pages
  • =<2.5.9
Disable Payment Methods based on cart conditions for WooCommerce
  • =<1.16.3
TopNewsWp – Display Tikcer News, RSS Feed Widget and Many More
  • =<2.4.1
Auto-Install Free SSL – Generate & Install Free SSL Certificates
  • =<4.5.0
Send Users Email – Email Subscribers, Email Marketing Newsletter
  • =<1.5.10
Logo Showcase – Responsive Logo Carousel, Logo Slider & Logo Grid
  • =<3.2.7
Secure Gateway for Authorize.net and WooCommerce by Pledged Plugins
  • =<6.1.13
AI Bud – AI Content Generator, AI Chatbot, ChatGPT, Gemini, GPT-4o
  • =<1.7.2
Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player
  • =<2.0.82
Easy Social Feed – Social Photos Gallery and Post Feed for WordPress
  • =<6.6.5
Bulk Auto Image Alt Text (Alt tag, Alt attribute) optimizer (image SEO)
  • =<2.1.0
Easy Appointment Booking & Scheduling System – Webba Booking Calendar
  • =<5.0.57
HTML5 Audio Player – The Ultimate No-Code Podcast, MP3 & Audio Player
  • =<2.2.27
EazyDocs – AI Powered Knowledge Base, Wiki, Documentation & FAQ Builder
  • =<2.5.7
WP Books Gallery – Build Stunning Book Showcases & Libraries in Minutes
  • =<4.6.8
BlockSpare — News, Magazine and Blog Addons for (Gutenberg) Block Editor
  • =<3.2.6
WP Data Access – App Builder for Tables, Forms, Charts, Maps & Dashboards
  • =<5.5.31
Dracula Dark Mode – Accessibility, Reading Mode & Dark Mode for WordPress
  • =<1.2.7
Notification Bar, Announcement and Cookie Notice WordPress Plugin – FooBar
  • =<2.1.34
Meta Field Block – Display custom fields in the Block Editor without coding
  • =<1.3.3
Radio Station by netmix® – Manage and play your Show Schedule in WordPress!
  • =<2.5.9
WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatars
  • =<3.8.3
Solid Testimonials – Testimonial Slider, Video Testimonials & Customer Reviews
  • =<3.2.8
Better Messages – Live Chat, Chat Rooms, Real-Time Messaging & Private Messages
  • =<2.6.7
Restrict – membership, site, content and user access restrictions for WordPress
  • =<2.3.0
Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent
  • =<1.1.13
WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto
  • =<8.0.7
Image Alt Text Manager – Bulk & Dynamic Alt Tags For image SEO Optimization + AI
  • =<1.6.3
Blog Designer Pack – Blog, Post Grid, Post Slider, Post Carousel, Category Post, News
  • =<3.4.9
Kikote – Location Picker at Checkout & Google Address AutoFill Plugin for WooCommerce
  • =<1.10.6
AEH Speed Optimization: Browser Cache, Optimized Minify, Lazy Loading & Image Optimization
  • =<2.9.2
WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan
  • =<7.7.0
Post Slider and Post Carousel with Post Vertical Scrolling Widget – A Responsive Post Slider
  • =<3.2.7
Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits
  • =<2.0.7.2
Team Members – A WordPress Team Plugin with Gallery, Grid, Carousel, Slider, Table, List, and More
  • =<2.5.8
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App
  • =<3.0.0

Matching in nixpkgs

pkgs.pyglossary

Tool for converting dictionary files aka glossaries. Mainly to help use our offline glossaries in any Open Source dictionary we like on any operating system / device

pkgs.pyglossary-gui

Tool for converting dictionary files aka glossaries. Mainly to help use our offline glossaries in any Open Source dictionary we like on any operating system / device

pkgs.python312Packages.pyglossary

Tool for converting dictionary files aka glossaries. Mainly to help use our offline glossaries in any Open Source dictionary we like on any operating system / device

pkgs.python313Packages.pyglossary

Tool for converting dictionary files aka glossaries. Mainly to help use our offline glossaries in any Open Source dictionary we like on any operating system / device

pkgs.python314Packages.pyglossary

Tool for converting dictionary files aka glossaries. Mainly to help use our offline glossaries in any Open Source dictionary we like on any operating system / device

Package maintainers

Dismissed
(not in Nixpkgs)
updated 3 days, 18 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
HTTP/2 frame size limit checked after body is buffered in bandit

Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated memory exhaustion via oversized HTTP/2 frames. 'Elixir.Bandit.HTTP2.Frame':deserialize/2 in lib/bandit/http2/frame.ex checks the SETTINGS_MAX_FRAME_SIZE limit only after pattern-matching payload::binary-size(length), which requires the entire frame body to be present in memory before either the accept or reject clause can fire. A peer that announces a frame length up to the 24-bit maximum (~16 MiB) causes the server to buffer that entire body before the size guard is evaluated, regardless of the max_frame_size negotiated during the HTTP/2 handshake (default 16 KiB per RFC 9113). An unauthenticated attacker holding many concurrent connections can force the server to buffer far more memory than the negotiated frame size limit should permit, leading to memory pressure and potential denial of service. This issue affects bandit: from 0.3.6 before 1.11.0.

Affected products

bandit
  • <1.11.0
mtrudel/bandit
  • <1.11.0

Matching in nixpkgs

pkgs.bandit

Security oriented static analyser for python code

Package maintainers