Nixpkgs Security Tracker

Login with GitHub

Dismissed suggestions

These automatic suggestions were dismissed after initial triaging.

to select a suggestion for revision.

View:
Compact
Detailed
updated 3 weeks, 4 days ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed
    5 packages
    • gnutls
    • guile-gnutls
    • python312Packages.python3-gnutls
    • python313Packages.python3-gnutls
    • python314Packages.python3-gnutls
  • @LeSuisse dismissed
uTLS has a Chrome Parrot Fingerprint Vulnerability due to GREASE ECH Cipher Suite Mismatch

uTLS is a fork of crypto/tls, created to customize ClientHello for fingerprinting resistance while still using it for the handshake. Versions 1.6.0 through 1.8.0 contain a fingerprint mismatch with Chrome when using GREASE ECH, related to cipher suite selection. When Chrome selects the preferred cipher suite in the outer ClientHello and for ECH, it does so consistently based on hardware support—for example, if it prefers AES for the outer cipher suite, it also uses AES for ECH. However, the Chrome parrot in uTLS hardcodes AES preference for outer cipher suites but selects the ECH cipher suite randomly between AES and ChaCha20. This creates a 50% chance of selecting ChaCha20 for ECH while using AES for the outer cipher suite, a combination impossible in Chrome. This issue only affects GREASE ECH; in real ECH, Chrome selects the first valid cipher suite when AES is preferred, which uTLS handles correctly. This issue has been fixed in version 1.8.1.

Affected products

utls
  • ==>= 1.6.0, < 1.8.1
Ignored packages (5)
Not present in nixpkgs
Permalink CVE-2026-26994
6.5 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): LOW
  • Availability impact (A): NONE
updated 3 weeks, 4 days ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed
    5 packages
    • gnutls
    • guile-gnutls
    • python312Packages.python3-gnutls
    • python313Packages.python3-gnutls
    • python314Packages.python3-gnutls
  • @LeSuisse dismissed
uTLS ServerHellos are accepted without checking TLS 1.3 downgrade canaries

uTLS is a fork of crypto/tls, created to customize ClientHello for fingerprinting resistance while still using it for the handshake. In versions 1.6.7 and below, uTLS did not implement the TLS 1.3 downgrade protection mechanism specified in RFC 8446 Section 4.1.3 when using a uTLS ClientHello spec. This allowed an active network adversary to downgrade TLS 1.3 connections initiated by a uTLS client to a lower TLS version (e.g., TLS 1.2) by modifying the ClientHello message to exclude the SupportedVersions extension, causing the server to respond with a TLS 1.2 ServerHello (along with a downgrade canary in the ServerHello random field). Because uTLS did not check the downgrade canary in the ServerHello random field, clients would accept the downgraded connection without detecting the attack. This attack could also be used by an active network attacker to fingerprint uTLS connections. This issue has been fixed in version 1.7.0.

Affected products

utls
  • ==< 1.7.0
Ignored packages (5)
Not present in nixpkgs
updated 3 weeks, 4 days ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed
    3 packages
    • python312Packages.cobble
    • python313Packages.cobble
    • python314Packages.cobble
  • @LeSuisse dismissed
WordPress Cobble theme <= 1.7 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Cobble cobble allows PHP Local File Inclusion.This issue affects Cobble: from n/a through <= 1.7.

Affected products

cobble
  • =<<= 1.7
Ignored packages (3)
WP theme not present in nixpkgs
updated 3 weeks, 4 days ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed package calibre-web
  • @LeSuisse dismissed
A untrusted search path issue was found in Calibre at …

A untrusted search path issue was found in Calibre at devices/linux_mount_helper.c leading to the ability of unprivileged users to execute any program as root.

Affected products

Calibre
  • ==unknown

Matching in nixpkgs

Ignored packages (1)

Package maintainers

Old issue, current stable branch was never impacted
updated 3 weeks, 4 days ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed package calibre-web
  • @LeSuisse dismissed
Race condition issues were found in Calibre at devices/linux_mount_helper.c allowing …

Race condition issues were found in Calibre at devices/linux_mount_helper.c allowing unprivileged users the ability to mount any device to anywhere.

Affected products

Calibre
  • ==unknown

Matching in nixpkgs

Ignored packages (1)

Package maintainers

Old issue, current stable branch was never impacted
updated 3 weeks, 4 days ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed package calibre-web
  • @LeSuisse dismissed
Input validation issues were found in Calibre at devices/linux_mount_helper.c which …

Input validation issues were found in Calibre at devices/linux_mount_helper.c which can lead to argument injection and elevation of privileges.

Affected products

Calibre
  • ==unknown

Matching in nixpkgs

Ignored packages (1)

Package maintainers

Old issue, current stable branch was never impacted
updated 3 weeks, 4 days ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed package moodle-dl
  • @LeSuisse dismissed
Moodle before 2.2.2 has a default repository capabilities issue where …

Moodle before 2.2.2 has a default repository capabilities issue where all repositories are viewable by all users by default

References

Affected products

Moodle
  • ==2.0 to 2.0.7+
  • ==2.2 to 2.2.1+
  • ==2.1 to 2.1.4+

Matching in nixpkgs

Ignored packages (1)

Package maintainers

Old issue current stable branch was never impacted.
updated 3 weeks, 4 days ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed package moodle-dl
  • @LeSuisse dismissed
Moodle before 2.2.2: Course information leak via hidden courses being …

Moodle before 2.2.2: Course information leak via hidden courses being displayed in tag search results

References

Affected products

Moodle
  • ==2.2 to 2.2.1+
  • ==2.1 to 2.1.4+

Matching in nixpkgs

Ignored packages (1)

Package maintainers

Old issue current stable branch was never impacted.
updated 3 weeks, 4 days ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed package moodle-dl
  • @LeSuisse dismissed
Moodle before 2.2.2 has users' private files included in course …

Moodle before 2.2.2 has users' private files included in course backups

References

Affected products

Moodle
  • ==2.0 to 2.0.7+
  • ==2.2 to 2.2.1+
  • ==2.1 to 2.1.4+

Matching in nixpkgs

Ignored packages (1)

Package maintainers

Old issue current stable branch was never impacted.
updated 3 weeks, 4 days ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed package moodle-dl
  • @LeSuisse dismissed
Moodle before 2.2.2: Overview report allows users to see hidden …

Moodle before 2.2.2: Overview report allows users to see hidden courses

References

Affected products

Moodle
  • ==2.2 to 2.2.1+
  • ==2.1 to 2.1.4+

Matching in nixpkgs

Ignored packages (1)

Package maintainers

Old issue current stable branch was never impacted.