Nixpkgs security tracker

Login with GitHub

Dismissed suggestions

These automatic suggestions were dismissed after initial triaging.

to select a suggestion for revision.

View:
Compact
Detailed
Dismissed
(not in Nixpkgs)
Permalink CVE-2026-24118
9.8 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 2 weeks, 6 days ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
VM2 Sandbox Breakout Through __lookupGetter__

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability. This allows attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system. This issue has been patched in version 3.11.0.

Affected products

vm2
  • ==< 3.11.0

Matching in nixpkgs

Package maintainers

Dismissed
(not in Nixpkgs)
Permalink CVE-2026-42077
5.2 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): High (H)
updated 2 weeks, 6 days ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
Evolver: Prototype Pollution via `Object.assign()` in mailbox store operations

Evolver is a GEP-powered self-evolving engine for AI agents. Prior to version 1.69.3, a prototype pollution vulnerability in the mailbox store module allows attackers to modify the behavior of all JavaScript objects by injecting malicious properties into Object.prototype. The vulnerability exists in the _applyUpdate() and _updateRecord() functions which use Object.assign() to merge user-controlled data without filtering dangerous keys like __proto__, constructor, or prototype. This issue has been patched in version 1.69.3.

Affected products

evolver
  • ==< 1.69.3

Matching in nixpkgs

Package maintainers

Dismissed
(not in Nixpkgs)
Permalink CVE-2026-25293
9.6 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Adjacent (A)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Adjacent (A)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 2 weeks, 6 days ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
Incorrect authorization in PLC FW

Buffer overflow due to incorrect authorization in PLC FW

Affected products

Snapdragon
  • ==QCA7005

Matching in nixpkgs

Dismissed
(not in Nixpkgs)
Permalink CVE-2026-24082
7.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 2 weeks, 6 days ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
Use After Free in Automotive GPU

Memory Corruption when copying data from a freed source while executing performance counter deselect operation.

Affected products

Snapdragon
  • ==Snapdragon X72 5G Modem-RF System
  • ==Snapdragon X35 5G Modem-RF System
  • ==WCD9335
  • ==WCD9395
  • ==SW5100P
  • ==WSA8815
  • ==Snapdragon 460 Mobile Platform
  • ==XRV9209
  • ==Snapdragon 4 Gen 1 Mobile Platform
  • ==SA8295P
  • ==WCN7861
  • ==SA8155P
  • ==WCN6755
  • ==Flight RB5 5G Platform
  • ==LeMans_AU_LGIT
  • ==Qualcomm Dragonwing QRU100 Platform
  • ==SM7550P
  • ==XRV7209
  • ==Milos
  • ==QDX1011
  • ==QCS4290
  • ==SA8255P
  • ==Kalpeni
  • ==WCN3980
  • ==QXM1086
  • ==SA8145P
  • ==SW5100
  • ==WCD9375
  • ==QCA6564A
  • ==QCN9012
  • ==Pandeiro
  • ==WCN7881
  • ==FastConnect 6200
  • ==FastConnect 6900
  • ==FWA Gen 3 Ultra Platform
  • ==QCA8081
  • ==QCA9367
  • ==Snapdragon 7s Gen 3 Mobile Platform
  • ==QCM2290
  • ==Snapdragon 480 5G Mobile Platform
  • ==Smart Audio 400 Platform
  • ==Snapdragon X75 5G Modem-RF System
  • ==QCM5430
  • ==SM8550P
  • ==QCA6698AU
  • ==WCD9371
  • ==Qualcomm Dragonwing X100 Accelerator Card
  • ==Snapdragon 685 4G Mobile Platform
  • ==QFW7124
  • ==WSA8835
  • ==QCN6274
  • ==QCS8550
  • ==Snapdragon 6 Gen 4 Mobile Platform
  • ==LeMansAU
  • ==QPA1083BD
  • ==WCN3988
  • ==Snapdragon AR1+ Gen 1 Platform
  • ==QCA8337
  • ==SM7635P
  • ==Snapdragon Auto 5G Modem-RF Gen 2
  • ==QLN1086BD
  • ==FastConnect 6700
  • ==AR8031
  • ==SA6145P
  • ==QCA6564AU
  • ==SA6155P
  • ==WCN3950
  • ==WSA8832
  • ==QCN9011
  • ==Snapdragon AR1 Gen 1 Platform
  • ==WCD9378
  • ==QCA8695AU
  • ==WSA8845
  • ==QXM1093
  • ==QCA2066
  • ==QCA6688AQ
  • ==QDU1110
  • ==QDX1010
  • ==SM6225P
  • ==Robotics RB2 Platform
  • ==Snapdragon 8 Gen 3 Mobile Platform
  • ==WCD9370
  • ==Snapdragon 662 Mobile Platform
  • ==WCD9385
  • ==MDM9250
  • ==SM8635
  • ==QCA6696
  • ==WCN7860
  • ==SRV1H
  • ==Snapdragon X32 5G Modem-RF System
  • ==SM7525
  • ==Robotics RB5 Platform
  • ==Milos_IOT
  • ==WSA8810
  • ==SD662
  • ==QCA6595AU
  • ==SA4150P
  • ==SA6150P
  • ==QCA6797AQ
  • ==SM7675P
  • ==QXM1096
  • ==QCA6574A
  • ==Snapdragon 8 Gen 2 Mobile Platform
  • ==SXR2330P
  • ==QCA6574
  • ==QCN6224
  • ==QXM1095
  • ==QFW7114
  • ==QAMSRV1M
  • ==G3x Gen 2
  • ==QCS2290
  • ==Snapdragon 480+ 5G Mobile Platform
  • ==QDU1210
  • ==WSA8830
  • ==QEP8111
  • ==SA7255P
  • ==QPA1086BD
  • ==QCM6490
  • ==WCD9390
  • ==QAM8255P
  • ==Snapdragon 8+ Gen 2 Mobile Platform
  • ==QCA6174A
  • ==SA8195P
  • ==SM8635P
  • ==CSRA6620
  • ==G1 Gen 1
  • ==SM8650Q
  • ==QXM1094
  • ==AR8035
  • ==SM6650P
  • ==FastConnect 7800
  • ==QCS6690
  • ==QRB5165M
  • ==WCN6650
  • ==WSA8840
  • ==Snapdragon Auto 5G Modem-RF
  • ==SAR1165P
  • ==QRU1032
  • ==WCN3910
  • ==QAMSRV1H
  • ==QCA9377
  • ==SRV1M
  • ==SA8770P
  • ==QXM1083
  • ==QCC710
  • ==QLN1083BD
  • ==Qualcomm Video Collaboration VC5 Platform
  • ==WCN6450
  • ==QCA6595
  • ==WSA8845H
  • ==QAM8295P
  • ==SA8620P
  • ==WCD9380
  • ==QCA6698AQ
  • ==QDU1000
  • ==Snapdragon 680 4G Mobile Platform
  • ==Snapdragon 695 5G Mobile Platform
  • ==QCM6125
  • ==Qualcomm Video Collaboration VC1 Platform
  • ==SA9000P
  • ==QCA6574AU
  • ==SM7675
  • ==SA7775P
  • ==SA4155P
  • ==Qualcomm Video Collaboration VC3 Platform
  • ==SM7550
  • ==QCM4325
  • ==SA8150P
  • ==QCA6584AU
  • ==QCA6678AQ
  • ==SXR2350P
  • ==CSRA6640
  • ==WCD9340
  • ==QCA6391
  • ==MDM9628
  • ==QRB5165N

Matching in nixpkgs

Dismissed
(not in Nixpkgs)
Permalink CVE-2025-47406
6.1 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): Low (L)
updated 2 weeks, 6 days ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
Buffer Over-read in DSP Service

Information Disclosure while processing IOCTL handler callbacks without verifying buffer size.

Affected products

Snapdragon
  • ==X2000092
  • ==QCM5430
  • ==X2000090
  • ==FastConnect 7800
  • ==IQX7181
  • ==WSA8840
  • ==XG101039
  • ==Snapdragon 8cx Gen 3 Compute Platform
  • ==WSA8835
  • ==XG101032
  • ==X2000094
  • ==WSA8845H
  • ==WCD9380
  • ==FastConnect 6700
  • ==X2000086
  • ==IQX5121
  • ==QCA0000
  • ==WSA8845
  • ==WCD9378C
  • ==Qualcomm Video Collaboration VC3 Platform
  • ==WCD9375
  • ==WSA8830
  • ==Cologne
  • ==XG101002
  • ==SC8380XP
  • ==X2000077
  • ==QCM6490
  • ==WCD9370
  • ==FastConnect 6900
  • ==Snapdragon 7c+ Gen 3 Compute
  • ==WCD9385

Matching in nixpkgs

Dismissed
(not in Nixpkgs)
Permalink CVE-2026-42092
6.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
updated 2 weeks, 6 days ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
Global Settings Publication Exposes Sensitive Configuration to Any Authenticated User in Titra

titra is an open source time tracking project. In version 0.99.52, the globalsettings Meteor publication returns all global settings without any admin or role check. Any authenticated user can subscribe via DDP and receive sensitive configuration fields such as google_secret, openai_apikey, and google_clientid. At time of publication no public patch is available.

Affected products

titra
  • === 0.99.52

Matching in nixpkgs

Dismissed
(not in Nixpkgs)
Permalink CVE-2025-42611
6.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
updated 2 weeks, 6 days ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
Improper certificate validation in multiple RouterOS services

RouterOS provides various services that rely on correct verification of client and server certificates to secure confidentiality and integrity of communications. This includes OpenVPN, CAPsMAN, Dot1x (802.1X), among others. The vulnerability lies in shared certificate validation logic which uses the system certificate store that is shared and equally trusted by all system services. This causes confusion of scope, allowing any certificate authority present in the system-wide trust store to be trusted in any context (with some exceptions), allowing partial or full authentication bypass in CAPsMAN, OpenVPN, Dot1X and potentially others.

References

Affected products

RouterOS
  • =<7.20.x

Matching in nixpkgs

Package maintainers

Dismissed
(not in Nixpkgs)
Permalink CVE-2026-42997
7.7 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
updated 2 weeks, 6 days ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
An issue was discovered in idrac in OpenStack Ironic before …

An issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request authorization to be sent to a remote endpoint. The credential forwarded is a time-limited Keystone token (which provides access to all OpenStack services Ironic is authorized for); or basic credentials configured for molds storage. The fixed versions are 26.1.6, 29.0.5, 32.0.1, and 35.0.1.

Affected products

Ironic
  • <26.1.6
  • <32.0.1
  • <29.0.5
  • <35.0.1

Matching in nixpkgs

pkgs.ironicclient

Client for OpenStack bare metal provisioning API, includes a Python module (ironicclient) and CLI (baremetal)

Package maintainers

Dismissed
(not in Nixpkgs)
updated 2 weeks, 6 days ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
twenty-server SSRF protection bypass via IPv4-mapped IPv6 address normalization

Twenty is an open source CRM built with NestJS (Node.js). In versions 1.18.0 and earlier, the SSRF protection in twenty-server's SecureHttpClientService can be bypassed using IPv4-mapped IPv6 addresses in URL IP literals. Node.js's URL parser normalizes IPv4-mapped IPv6 addresses to compressed hex form (e.g., ::ffff:169.254.169.254 becomes ::ffff:a9fe:a9fe), but the isPrivateIp utility only recognizes the dotted-decimal notation. As a result, the hex form passes the SSRF check unchecked. Additionally, the socket lookup validation event does not fire for IP literal addresses, bypassing the second validation layer. An authenticated user can reach any internal IP, including cloud metadata endpoints, to exfiltrate credentials such as IAM keys.

Affected products

twenty
  • ==<= 1.18.0

Matching in nixpkgs

Package maintainers

Dismissed
(not in Nixpkgs)
Permalink CVE-2026-43002
5.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): Low (L)
updated 2 weeks, 6 days ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
An issue was discovered in OpenStack Horizon 25.6 and 25.7 …

An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There is a write operation to the session storage backend before authentication and thus storage can be exhausted by unauthenticated requests. This is a regression of the CVE-2014-8124 fix.

Affected products

Horizon
  • <25.7.3

Matching in nixpkgs

pkgs.horizon-eda

Free EDA software to develop printed circuit boards

Package maintainers