Nixpkgs security tracker

Login with GitHub

Dismissed suggestions

These automatic suggestions were dismissed after initial triaging.

to select a suggestion for revision.

View:
Compact
Detailed
Dismissed
(no matching packages found)
Permalink CVE-2026-47085
4.0 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): Low (L)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
created 5 days, 17 hours ago Activity log
  • Created & dismissed (no matching packages found) suggestion
An issue was discovered in cyrus-imapd in Cyrus IMAP through …

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH token forgery can occur via a missing mboxkey. If an attacker knew a folder name on the victim's account for which the victim had never issued an auth URL, they could forge a working URLAUTH token by computing an HMAC-SHA1 value with a predictable key, giving them read access to the mailbox. (URLAUTH is an obscure feature, meaning that the odds of any user actually being susceptible to this attack are very low. Perhaps no public clients use URLAUTH.)

Affected products

Cyrus IMAP
  • <3.12.3
Dismissed
(no matching packages found)
Permalink CVE-2026-62826
4.6 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Exploit Code Maturity (E): Unproven (U)
  • Remediation Level (RL): Official Fix (O)
  • Report Confidence (RC): Confirmed (C)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
created 5 days, 17 hours ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Microsoft SharePoint Server Spoofing Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

References

Affected products

Microsoft SharePoint Server 2019
  • <16.0.10417.20175
Microsoft SharePoint Enterprise Server 2016
  • <16.0.5561.1001
Microsoft SharePoint Server Subscription Edition
  • <16.0.19725.20434
Dismissed
(no matching packages found)
Permalink CVE-2026-56454
5.9 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
created 5 days, 17 hours ago Activity log
  • Created & dismissed (no matching packages found) suggestion
HCL DFXAnalytics is affected by a Deprecated Protocol vulnerability due to the use of TLS 1.0 and TLS 1.1.

HCL DFXAnalytics is affected by a Deprecated Protocol vulnerability due to the use of TLS 1.0 and TLS 1.1. These legacy protocols contain numerous cryptographic design flaws that expose data to interception and decryption. To remediate this risk, the application must disable all support for TLS 1.0 and TLS 1.1, and exclusively enable support for secure protocols, specifically TLS 1.2 and TLS 1.3.

Affected products

DFXAnalytics
  • ==version 3.0 and below
Dismissed
(no matching packages found)
Permalink CVE-2024-58360
6.9 MEDIUM
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): None (N)
  • Vulnerable System Impact Integrity (VI): Low (L)
  • Vulnerable System Impact Availability (VA): Low (L)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): None (N)
  • Modified Vulnerable System Impact Integrity (MVI): Low (L)
  • Modified Vulnerable System Impact Availability (MVA): Low (L)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 5 days, 17 hours ago Activity log
  • Created & dismissed (no matching packages found) suggestion
stoatchat before 0.7.8 Unrestricted Account Creation

stoatchat versions before 0.7.8 fail to enforce account creation restrictions including invite-only mode, email verification, captcha, and shield verification. Attackers can create unlimited accounts with unverified email addresses, increasing denial-of-service risk and compromising service integrity.

Affected products

stoatchat
  • ==0.7.8
  • <0.7.8
Dismissed
(no matching packages found)
Permalink CVE-2026-35145
3.1 LOW
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
created 5 days, 17 hours ago Activity log
  • Created & dismissed (no matching packages found) suggestion
HCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Header vulnerability.

HCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Header vulnerability. The application fails to implement the HTTP Strict Transport Security (HSTS) policy within its responses, which could allow a remote attacker to downgrade the communication channel to an unencrypted connection (HTTP) and conduct man-in-the-middle (MitM) attacks. To remediate this, the application must include the "Strict-Transport-Security" header in all web application responses.

Affected products

DFXAnalytics
  • ==version 3.0 and below
Dismissed
(no matching packages found)
Permalink CVE-2026-12979
5.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): Low (L)
created 5 days, 17 hours ago Activity log
  • Created & dismissed (no matching packages found) suggestion
FunnelKit < 3.15.0.6 - Admin+ Arbitrary File Deletion via Path Traversal in Template Importer

The FunnelKit WordPress plugin before 3.15.0.6 does not validate a user-supplied path before deleting a file during a template-import operation, allowing users with administrator privileges to delete arbitrary .json files outside the intended directory through path traversal, which can disable other FunnelKit WordPress plugin before 3.15.0.6 or (denial of service).

References

Affected products

FunnelKit
  • <3.15.0.6
Dismissed
(no matching packages found)
Permalink CVE-2026-10587
6.8 MEDIUM
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): None (N)
  • Vulnerable System Impact Integrity (VI): High (H)
  • Vulnerable System Impact Availability (VA): High (H)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): None (N)
  • Modified Vulnerable System Impact Integrity (MVI): High (H)
  • Modified Vulnerable System Impact Availability (MVA): High (H)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 5 days, 17 hours ago Activity log
  • Created & dismissed (no matching packages found) suggestion
A potential out-of-bounds write vulnerability could allow a local privileged …

A potential out-of-bounds write vulnerability could allow a local privileged attacker to modify power management settings in System Management Mode.

Affected products

LOQ 15IAX9E BIOS
  • =<Q8CN17WW
LOQ 15ARP10E BIOS
  • <SUCN18WW
Yoga 9 14IRP8 BIOS
  • <L4CN31WW
Legion 5 15APH9 BIOS
  • <PJCN18WW
Legion 5 15IRX9 BIOS
  • =<PTCN14WW
Legion 9 16IRX9 BIOS
  • =<NXCN20WW
IdeaPad 5 15ABA7 BIOS
  • <KACN29WW
Legion 5 15AHP10 BIOS
  • <RGCN35WW
Legion 5 15AKP10 BIOS
  • =<RYCN22WW
Legion 5 15IAX10 BIOS
  • =<S2CN15WW
Legion 5 15IRX10 BIOS
  • =<QNCN28WW
Legion 7 16AGP11 BIOS
  • =<TPCN27WW
Legion 7 16IAX10 BIOS
  • =<RXCN18WW
Lenovo S14 G3 IAP BIOS
  • =<JKCN49WW
Lenovo V14 G6 ITN BIOS
  • <RHCN20WW
Lenovo V15 G4 AMN BIOS
  • <L1CN72WW
Lenovo V15 G4 IAH BIOS
  • <MCCN39WW
Lenovo V15 G5 IRL BIOS
  • <PMCN38WW
Lenovo V15 G6 ARP BIOS
  • =<TYCN15WW
Yoga Pro 9 14IRP8 BIOS
  • =<MBCN33WW
Yoga Pro 9 16IMH9 BIOS
  • =<NKCN30WW
Yoga Book 9 13IMU9 BIOS
  • =<NVCN24WW
Yoga Pro 7 15IPH11 BIOS
  • <TNCN37WW
Legion Pro 5 16ARX8 BIOS
  • =<LPCN59WW
Legion Pro 5 16IRX9 BIOS
  • <N0CN35WW
Yoga Book 9 14IAH10 BIOS
  • =<QEME23WW
  • =<QECN21WW
IdeaPad Pro 5 16IMH9 BIOS
  • =<MECN68WW
IdeaPad Pro 5 16IRH8 BIOS
  • =<KZCN46WW
Legion Pro 5 16ADR10 BIOS
  • =<U5CN07WW
  • =<RLCN21WW
Legion Pro 5 16AFR10 BIOS
  • =<RECN14WW
Legion Pro 5 16IAX10 BIOS
  • =<Q6CN26WW
Legion Pro 5 16IRX10 BIOS
  • =<S9CN13WW
Legion Pro 7 16ARX8H BIOS
  • =<LPCN59WW
  • =<LPCN45WW
Legion Pro 7 16IRX9H BIOS
  • =<N2CN26WW
Legion Slim 5 14APH8 BIOS
  • =<MACN33WW
ThinkBook 16p G5 IRX BIOS
  • <P5CN31WW
ThinkBook 16p G6 ADR BIOS
  • <R7CN26WW
ThinkBook 16p G6 IAX BIOS
  • <R2CN57WW
Yoga 9 2-in-1 14IMH9 BIOS
  • =<NNCN31WW
IdeaPad Pro 5 16AGP11 BIOS
  • =<T8CN19WW
IdeaPad Pro 5 16ASP10 BIOS
  • =<R1CN24WW
IdeaPad Pro 5 16IAH10 BIOS
  • =<PZCN27WW
IdeaPad Pro 5 16IPH11 BIOS
  • <S4CN62WW
IdeaPad Slim 3 14ITN9 BIOS
  • <QUCN20WW
IdeaPad Slim 3 15AMN8 BIOS
  • <L1CN51WW
IdeaPad Slim 3 16IRH8 BIOS
  • <LTCN44WW
IdeaPad Slim 3 16IRU9 BIOS
  • <P2CN27WW
Legion Pro 7 16ADR10H BIOS
  • <SJCN17WW
Legion Pro 7 16AFR10H BIOS
  • <SMCN20WW
Legion Pro 7 16IAX10H BIOS
  • =<Q7CN31WW
ThinkBook Plus G4 IRU BIOS
  • =<LUCN47WW
Yoga 9 2-in-1 14ILL10 BIOS
  • =<Q9CN22WW
IdeaPad Slim 3 16ARP10 BIOS
  • <QBCN30WW
IdeaPad Slim 3 16IRH10R BIOS
  • =<QDCN23WW
Lenovo V15 G2 IJL Laptop BIOS
  • <HTCN49WW
ThinkBook Plus G6 Rollable BIOS
  • =<QWCN34WW
ThinkBook Plus G5 Tab&ThinkBook Plus G5 Station BIOS
  • =<P8CN42WW
Dismissed
(no matching packages found)
Permalink CVE-2026-12492
9.8 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 5 days, 17 hours ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Happy Coders OTP Login for WooCommerce < 2.8 - Unauthenticated Account Takeover via hcotp_auto_login_user

The Happy Coders OTP Login for WooCommerce WordPress plugin before 2.8 does not verify that a one-time password was actually validated before authenticating a user based on a supplied identifier, allowing unauthenticated attackers to log in as any existing user, including administrators, as well as to create new accounts.

References

Affected products

Happy Coders OTP Login for WooCommerce
  • <2.8
Dismissed
(no matching packages found)
Permalink CVE-2026-46562
9.8 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 5 days, 17 hours ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Yamcs: Remote Code Execution via Mission Database algorithm override

Yamcs is a mission control framework. Prior to 5.12.7, the Nashorn ScriptEngine used to evaluate user-supplied JavaScript algorithm text in yamcs-core/src/main/java/org/yamcs/algorithms/ScriptAlgorithmExecutorFactory.java was constructed without a ClassFilter, so a user with the ChangeMissionDatabase privilege could override an algorithm through the MdbOverrideApi.updateAlgorithm endpoint and supply JavaScript that reaches arbitrary Java classes (for example Java.type("java.lang.Runtime").getRuntime().exec(...)) to execute arbitrary OS commands as the Yamcs process; in the default configuration with no security.yaml the built-in guest user has superuser=true, making the issue reachable without authentication. This issue is fixed in versions 5.12.7 and 5.13.0, which disable algorithm editing by default.

Affected products

yamcs
  • ==< 5.12.7
Dismissed
(no matching packages found)
Permalink CVE-2026-15610
4.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
created 5 days, 17 hours ago Activity log
  • Created & dismissed (no matching packages found) suggestion
WPBot <= 8.5.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary RAG Document Re-Sync via ajax_rag_manual_sync() Function

The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 8.5.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to trigger arbitrary re-embedding of stored RAG documents, modifying the rag_documents table and consuming the site owner's paid third-party AI API credits (OpenAI, Gemini, OpenRouter, or xAI).

Affected products

WPBot – AI ChatBot for Live Support, Lead Generation, AI Services
  • =<8.5.6