Nixpkgs security tracker

Login with GitHub

Dismissed suggestions

These automatic suggestions were dismissed after initial triaging.

to select a suggestion for revision.

View:
Compact
Detailed
Dismissed
(no matching packages found)
Permalink CVE-2026-62290
7.3 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
created 5 days, 23 hours ago Activity log
  • Created & dismissed (no matching packages found) suggestion
cert-manager: Direct ACME Challenge resources can bypass Issuer DNS01 solver policy and use ClusterIssuer DNS credentials

cert-manager adds certificates and certificate issuers as resource types in Kubernetes clusters, and simplifies the process of obtaining, renewing and using those certificates. From 1.18.0 until 1.19.6 and 1.20.3, Challenge resources under acme.cert-manager.io can be created directly by namespace users without admission validation tying the Challenge to an Order, owner reference, or Issuer-selected solver, allowing attacker-controlled Challenge.spec.solver values referencing a ClusterIssuer to bypass DNS01 solver selectors such as dnsZones, dnsNames, and matchLabels and cause cert-manager to use ClusterIssuer DNS credentials for attacker-selected provider settings and DNS names, including disclosure of X-Api-User and X-Api-Key headers for acme-dns. This issue is fixed in versions 1.19.6 and 1.20.3.

Affected products

cert-manager
  • ==>= 1.20.0, < 1.20.3
  • ==>= 1.18.0, < 1.19.6
Dismissed
(no matching packages found)
Permalink CVE-2026-56453
5.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): Required (R)
  • Scope (S): Changed (C)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): Low (L)
created 5 days, 23 hours ago Activity log
  • Created & dismissed (no matching packages found) suggestion
HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability.

HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability. A remote attacker can intercept and alter the contents of the server's HTTP responses before they reach the client application, allowing them to manipulate the authentication or authorization logic to bypass controls and gain unauthorized access to targeted user accounts.

Affected products

DFXAnalytics
  • ==version 3.0 and below
Dismissed
(no matching packages found)
Permalink CVE-2026-13754
6.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
created 5 days, 23 hours ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Tickera <= 3.6.0.0 - Authenticated (Staff+) SQL Injection via 's' Parameter

The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in all versions up to, and including, 3.6.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with custom-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Affected products

Tickera – Sell Tickets & Manage Events
  • =<3.6.0.0
Dismissed
(no matching packages found)
Permalink CVE-2021-27137
8.1 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 5 days, 23 hours ago Activity log
  • Created & dismissed (no matching packages found) suggestion
An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. …

An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality allows an unauthenticated remote attacker to send a request that would overflow an internal fixed buffer. Exploitation requires the DD-WRT user to enable UPnP (which is off by default, and only listens on internal interfaces by default). This occurs in ssdp_msearch (reachable by an M-SEARCH request).

Affected products

DD-WRT
  • <45724
Dismissed
(no matching packages found)
Permalink CVE-2026-11371
6.1 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Changed (C)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
created 5 days, 23 hours ago Activity log
  • Created & dismissed (no matching packages found) suggestion
BetterDocs < 4.5.5 - Unauthenticated Stored XSS via AI Doc Summarizer Prompt Injection

The BetterDocs WordPress plugin before 4.5.5 does not sanitise an AI-generated documentation summary before storing and outputting it, and the feature that generates it is exposed to unauthenticated users, allowing them to store a malicious payload via prompt injection that executes in the browser of any visitor who views the affected page, including administrators.

References

Affected products

BetterDocs
  • <4.5.5
Dismissed
(no matching packages found)
Permalink CVE-2026-10589
6.8 MEDIUM
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): None (N)
  • Vulnerable System Impact Integrity (VI): High (H)
  • Vulnerable System Impact Availability (VA): High (H)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): None (N)
  • Modified Vulnerable System Impact Integrity (MVI): High (H)
  • Modified Vulnerable System Impact Availability (MVA): High (H)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 5 days, 23 hours ago Activity log
  • Created & dismissed (no matching packages found) suggestion
A potential out of bounds write vulnerability could allow a …

A potential out of bounds write vulnerability could allow a local privileged attacker to execute code in System Management Mode.

Affected products

LOQ 15IAX9E BIOS
  • =<Q8CN17WW
LOQ 15ARP10E BIOS
  • <SUCN18WW
Yoga 9 14IRP8 BIOS
  • <L4CN31WW
Legion 5 15APH9 BIOS
  • <PJCN18WW
Legion 5 15IRX9 BIOS
  • =<PTCN14WW
Legion 9 16IRX9 BIOS
  • =<NXCN20WW
IdeaPad 5 15ABA7 BIOS
  • <KACN29WW
Legion 5 15AHP10 BIOS
  • <RGCN35WW
Legion 5 15AKP10 BIOS
  • =<RYCN22WW
Legion 5 15IAX10 BIOS
  • =<S2CN15WW
Legion 5 15IRX10 BIOS
  • =<QNCN28WW
Legion 7 16AGP11 BIOS
  • =<TPCN27WW
Legion 7 16IAX10 BIOS
  • =<RXCN18WW
Lenovo S14 G3 IAP BIOS
  • =<JKCN49WW
Lenovo V14 G6 ITN BIOS
  • <RHCN20WW
Lenovo V15 G4 AMN BIOS
  • <L1CN72WW
Lenovo V15 G4 IAH BIOS
  • <MCCN39WW
Lenovo V15 G5 IRL BIOS
  • <PMCN38WW
Lenovo V15 G6 ARP BIOS
  • =<TYCN15WW
Yoga Pro 9 14IRP8 BIOS
  • =<MBCN33WW
Yoga Pro 9 16IMH9 BIOS
  • =<NKCN30WW
Yoga Book 9 13IMU9 BIOS
  • =<NVCN24WW
Yoga Pro 7 15IPH11 BIOS
  • <TNCN37WW
Legion Pro 5 16ARX8 BIOS
  • =<LPCN59WW
Legion Pro 5 16IRX9 BIOS
  • <N0CN35WW
Yoga Book 9 14IAH10 BIOS
  • =<QEME23WW
  • =<QECN21WW
IdeaPad Pro 5 16IMH9 BIOS
  • =<MECN68WW
IdeaPad Pro 5 16IRH8 BIOS
  • =<KZCN46WW
Legion Pro 5 16ADR10 BIOS
  • =<U5CN07WW
  • =<RLCN21WW
Legion Pro 5 16AFR10 BIOS
  • =<RECN14WW
Legion Pro 5 16IAX10 BIOS
  • =<Q6CN26WW
Legion Pro 5 16IRX10 BIOS
  • =<S9CN13WW
Legion Pro 7 16ARX8H BIOS
  • =<LPCN59WW
  • =<LPCN45WW
Legion Pro 7 16IRX9H BIOS
  • =<N2CN26WW
Legion Slim 5 14APH8 BIOS
  • =<MACN33WW
ThinkBook 16p G5 IRX BIOS
  • <P5CN31WW
ThinkBook 16p G6 ADR BIOS
  • <R7CN26WW
ThinkBook 16p G6 IAX BIOS
  • <R2CN57WW
Yoga 9 2-in-1 14IMH9 BIOS
  • =<NNCN31WW
IdeaPad Pro 5 16AGP11 BIOS
  • =<T8CN19WW
IdeaPad Pro 5 16ASP10 BIOS
  • =<R1CN24WW
IdeaPad Pro 5 16IAH10 BIOS
  • =<PZCN27WW
IdeaPad Pro 5 16IPH11 BIOS
  • <S4CN62WW
IdeaPad Slim 3 14ITN9 BIOS
  • <QUCN20WW
IdeaPad Slim 3 15AMN8 BIOS
  • <L1CN51WW
IdeaPad Slim 3 16IRH8 BIOS
  • <LTCN44WW
IdeaPad Slim 3 16IRU9 BIOS
  • <P2CN27WW
Legion Pro 7 16ADR10H BIOS
  • <SJCN17WW
Legion Pro 7 16AFR10H BIOS
  • <SMCN20WW
Legion Pro 7 16IAX10H BIOS
  • =<Q7CN31WW
ThinkBook Plus G4 IRU BIOS
  • =<LUCN47WW
Yoga 9 2-in-1 14ILL10 BIOS
  • =<Q9CN22WW
IdeaPad Slim 3 16ARP10 BIOS
  • <QBCN30WW
IdeaPad Slim 3 16IRH10R BIOS
  • =<QDCN23WW
Lenovo V15 G2 IJL Laptop BIOS
  • <HTCN49WW
ThinkBook Plus G6 Rollable BIOS
  • =<QWCN34WW
ThinkBook Plus G5 Tab&ThinkBook Plus G5 Station BIOS
  • =<P8CN42WW
Dismissed
(no matching packages found)
Permalink CVE-2026-57205
4.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
created 5 days, 23 hours ago Activity log
  • Created & dismissed (no matching packages found) suggestion
SimpleChat: Authenticated users can access other users' profile metadata through user IDOR endpoints

SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. Prior to 0.241.203, the authenticated GET /api/user/info/<user_id> and GET /api/user/profile-image/<user_id> endpoints in application/single_app/route_backend_users.py accepted a caller-supplied user_id and read the matching Cosmos DB user-settings document without object-level authorization, allowing a low-privilege authenticated user to retrieve another user's email address, display name, and profile image. This issue is fixed in version 0.241.203.

Affected products

simplechat
  • ==< 0.241.203
Dismissed
(no matching packages found)
Permalink CVE-2026-11866
5.4 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): Low (L)
created 5 days, 23 hours ago Activity log
  • Created & dismissed (no matching packages found) suggestion
LatePoint < 5.6.3 - Multiple Privileged Actions via CSRF

The Appointment Booking Plugin WordPress plugin before 5.6.3 does not validate a CSRF nonce on several state-changing actions handled by its central request dispatcher, allowing attackers to perform privileged actions, such as overwriting the booking-form configuration or disconnecting the connected payment gateway, via Cross-Site Request Forgery against a logged-in administrator.

References

Affected products

Appointment Booking Plugin
  • <5.6.3
Dismissed
(no matching packages found)
Permalink CVE-2026-15445
4.9 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
created 5 days, 23 hours ago Activity log
  • Created & dismissed (no matching packages found) suggestion
SEO Booster <= 7.3.1 - Authenticated (Administrator+) SQL Injection via 'orderby' Parameter

The SEO Booster plugin for WordPress is vulnerable to time-based SQL Injection via the 'orderby' parameter in all versions up to, and including, 7.3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Although esc_sql() and sanitize_text_field() are applied, neither neutralizes SQL keywords, commas, parentheses, or subquery syntax in an unquoted ORDER BY context, leaving the clause fully attacker-controlled.

Affected products

SEO Booster
  • =<7.3.1
Dismissed
(no matching packages found)
Permalink CVE-2026-33434
4.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): Low (L)
created 5 days, 23 hours ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Wazuh: Rate Limit Bypass via /events Endpoint

Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 4.6.0 and above, prior to 4.14.5, a logic error in CheckRateLimitsMiddleware.dispatch() causes the /events endpoint rate check to unconditionally overwrite the general rate limit result. When the global max_request_per_minute is exceeded, requests to /events still succeed if the events-specific counter (hardcoded 30/min) has not been reached. This allows event injection into analysisd beyond the admin-configured global rate limit. This issue has been fixed in version 4.14.5.

Affected products

wazuh
  • ==>= 4.6.0, < 4.14.5