Nixpkgs security tracker

Login with GitHub

Dismissed suggestions

These automatic suggestions were dismissed after initial triaging.

to select a suggestion for revision.

View:
Compact
Detailed
Dismissed
(not in Nixpkgs)
updated 2 hours ago by @jopejoe1 Activity log
  • Created automatic suggestion
  • @jopejoe1 ignored
    11 packages
    • gnomeExtensions.ubuntu-net-speed
    • plymouth-vortex-ubuntu-theme
    • nerd-fonts.ubuntu-sans
    • nerd-fonts.ubuntu-mono
    • kmod-blacklist-ubuntu
    • nerd-fonts.ubuntu
    • ubuntu-sans-mono
    • ubuntu-classic
    • ubuntu-themes
    • ubuntu-sans
    • banana-vera
  • @jopejoe1 dismissed (not in Nixpkgs)

Senstive information disclosure was affecting subiquity


subiquity
  • =<25.04
  • =<24.04.4
  • =<25.10
Dismissed
(not in Nixpkgs)
updated 2 hours ago by @jopejoe1 Activity log
  • Created automatic suggestion
  • @jopejoe1 ignored
    11 packages
    • banana-vera
    • ubuntu-sans
    • ubuntu-themes
    • ubuntu-classic
    • ubuntu-sans-mono
    • nerd-fonts.ubuntu
    • kmod-blacklist-ubuntu
    • nerd-fonts.ubuntu-mono
    • nerd-fonts.ubuntu-sans
    • plymouth-vortex-ubuntu-theme
    • gnomeExtensions.ubuntu-net-speed
  • @jopejoe1 dismissed (not in Nixpkgs)

Senstive information disclosure was affecting ubuntu-desktop-provision


ubuntu-desktop-provision
  • =<25.04
  • =<24.04.4
  • =<25.10
Dismissed
(not in Nixpkgs)
Permalink CVE-2026-35569
8.7 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): REQUIRED
  • Scope (S): CHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): NONE
updated 16 hours ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse dismissed (not in Nixpkgs)

ApostropheCMS: Stored XSS in SEO Fields Leads to Authenticated API Data Exposure in ApostropheCMS


apostrophe
  • ==< 4.29.0
Dismissed
(not in Nixpkgs)
Permalink CVE-2026-39857
5.3 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): NONE
  • Availability impact (A): NONE
updated 16 hours ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse dismissed (not in Nixpkgs)

Information Disclosure via `choices`/`counts` Query Parameters Bypassing publicApiProjection Field Restrictions


apostrophe
  • ==< 4.29.0
Dismissed
(not in Nixpkgs)
updated 17 hours ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse dismissed (not in Nixpkgs)

WordPress Tutor LMS plugin <= 3.9.7 - Broken Access Control vulnerability


tutor
  • =<3.9.7
Dismissed
(not in Nixpkgs)
Permalink CVE-2025-52641
2.9 LOW
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): HIGH
  • Privileges required (PR): HIGH
  • User interaction (UI): REQUIRED
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): LOW
  • Availability impact (A): NONE
updated 17 hours ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse dismissed (not in Nixpkgs)

Internal Filesystem Exploration vulnerability


AION
  • ==2.0
Dismissed
(not in Nixpkgs)
Permalink CVE-2026-33877
3.7 LOW
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): HIGH
  • Privileges required (PR): NONE
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): NONE
  • Availability impact (A): NONE
updated 17 hours ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse dismissed (not in Nixpkgs)

ApostropheCMS: User Enumeration via Timing Side Channel in Password Reset Endpoint


apostrophe
  • ==< 4.29.0
Dismissed
(not in Nixpkgs)
Permalink CVE-2026-40947
2.9 LOW
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): HIGH
  • Privileges required (PR): NONE
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): NONE
  • Integrity impact (I): LOW
  • Availability impact (A): NONE
updated 17 hours ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse ignored package yubikey-manager
  • @LeSuisse dismissed (not in Nixpkgs)

Yubico libfido2 before 1.17.0, python-fido2 before 2.2.0, and yubikey-manager before …


libfido2
  • <1.17.0
python-fido2
  • <2.2.0
yubikey-manager
  • <5.9.1
Windows only
Dismissed
(not in Nixpkgs)
Permalink CVE-2026-33889
5.4 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): REQUIRED
  • Scope (S): CHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): LOW
  • Availability impact (A): NONE
updated 17 hours ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse dismissed (not in Nixpkgs)

ApostropheCMS: Stored XSS via CSS Custom Property Injection in `@apostrophecms/color-field` Escaping Style Tag Context


apostrophe
  • ==< 4.29.0
Dismissed
(not in Nixpkgs)
Permalink CVE-2026-40316
8.8 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): REQUIRED
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): HIGH
updated 17 hours ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse dismissed (not in Nixpkgs)

OWASP BLT has RCE in Github Actions via untrusted Django model execution in workflow


BLT
  • ==<= 2.1