Nixpkgs Security Tracker

Login with GitHub

Dismissed suggestions

These automatic suggestions were dismissed after initial triaging.

to select a suggestion for revision.

View:
Compact
Detailed
Permalink CVE-2026-2435
6.3 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV):
  • Attack complexity (AC):
  • Privileges required (PR):
  • User interaction (UI):
  • Scope (S):
  • Confidentiality impact (C):
  • Integrity impact (I):
  • Availability impact (A):
updated 1 month ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed
    28 packages
    • cassette
    • assetfinder
    • assetripper
    • taproot-assets
    • etlegacy-assets
    • retroarch-assets
    • go-bindata-assetfs
    • haskellPackages.cassette
    • python312Packages.webassets
    • python313Packages.webassets
    • python314Packages.webassets
    • haskellPackages.asset-bundle
    • python312Packages.flask-assets
    • python313Packages.flask-assets
    • python314Packages.flask-assets
    • haskellPackages.wai-make-assets
    • haskellPackages.gogol-cloudasset
    • python312Packages.django-js-asset
    • python313Packages.django-js-asset
    • python314Packages.django-js-asset
    • python312Packages.google-cloud-asset
    • python313Packages.google-cloud-asset
    • python314Packages.google-cloud-asset
    • haskellPackages.gogol-digitalassetlinks
    • perlPackages.MojoliciousPluginAssetPack
    • perl5Packages.MojoliciousPluginAssetPack
    • perl538Packages.MojoliciousPluginAssetPack
    • perl540Packages.MojoliciousPluginAssetPack
  • @LeSuisse dismissed
ASSET-7706

Tanium addressed a SQL injection vulnerability in Asset.

References

Affected products

Asset
  • <1.36.108
  • <1.32.179
  • <1.33.269
Ignored packages (28)
Not present in nixpkgs
Permalink CVE-2026-2709
3.5 LOW
  • CVSS version: 3.1
  • Attack vector (AV):
  • Attack complexity (AC):
  • Privileges required (PR):
  • User interaction (UI):
  • Scope (S):
  • Confidentiality impact (C):
  • Integrity impact (I):
  • Availability impact (A):
updated 1 month ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed
    13 packages
    • busybox
    • gobusybox
    • busybox-sandbox-shell
    • python312Packages.busypie
    • python313Packages.busypie
    • python314Packages.busypie
    • minimal-bootstrap.busybox-static
    • python312Packages.busylight-core
    • python313Packages.busylight-core
    • python314Packages.busylight-core
    • python312Packages.busylight-for-humans
    • python313Packages.busylight-for-humans
    • python314Packages.busylight-for-humans
  • @LeSuisse dismissed
busy Callback app.js redirect

A flaw has been found in busy up to 2.5.5. The affected element is an unknown function of the file source-code/busy-master/src/server/app.js of the component Callback Handler. Executing a manipulation of the argument state can lead to open redirect. It is possible to launch the attack remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Affected products

busy
  • ==2.5.1
  • ==2.5.4
  • ==2.5.2
  • ==2.5.0
  • ==2.5.5
  • ==2.5.3
Ignored packages (13)
Not present in nixpkgs
Permalink CVE-2026-0549
6.4 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV):
  • Attack complexity (AC):
  • Privileges required (PR):
  • User interaction (UI):
  • Scope (S):
  • Confidentiality impact (C):
  • Integrity impact (I):
  • Availability impact (A):
updated 1 month ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed
    31 packages
    • fedigroups
    • sway-assign-cgroups
    • haskellPackages.groups
    • haskellPackages.semigroups
    • haskellPackages.groups-generic
    • haskellPackages.finite-semigroups
    • haskellPackages.quickcheck-groups
    • haskellPackages.numbered-semigroups
    • python312Packages.dependency-groups
    • python313Packages.dependency-groups
    • python314Packages.dependency-groups
    • gnomeExtensions.kolour-groups-windows
    • haskellPackages.gogol-groups-settings
    • haskellPackages.commutative-semigroups
    • haskellPackages.gogol-groups-migration
    • haskellPackages.amazonka-resourcegroups
    • chickenPackages_5.chickenEggs.posix-groups
    • python312Packages.mypy-boto3-resource-groups
    • python313Packages.mypy-boto3-resource-groups
    • python314Packages.mypy-boto3-resource-groups
    • python312Packages.azure-mgmt-managementgroups
    • python313Packages.azure-mgmt-managementgroups
    • python314Packages.azure-mgmt-managementgroups
    • haskellPackages.amazonka-resourcegroupstagging
    • python312Packages.types-aiobotocore-resource-groups
    • python313Packages.types-aiobotocore-resource-groups
    • python312Packages.mypy-boto3-resourcegroupstaggingapi
    • python313Packages.mypy-boto3-resourcegroupstaggingapi
    • python314Packages.mypy-boto3-resourcegroupstaggingapi
    • python312Packages.types-aiobotocore-resourcegroupstaggingapi
    • python313Packages.types-aiobotocore-resourcegroupstaggingapi
  • @LeSuisse dismissed
Groups <= 3.10.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'groups_group_info' Shortcode

The Groups plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'groups_group_info' shortcode in all versions up to, and including, 3.10.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Affected products

Groups
  • =<3.10.0
Ignored packages (31)
WP plugin not present in nixpkgs.
Permalink CVE-2026-26345
4.7 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): HIGH
  • Privileges required (PR): NONE
  • User interaction (UI): REQUIRED
  • Scope (S): CHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): LOW
  • Availability impact (A): NONE
updated 1 month ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed
    4 packages
    • spip
    • spiped
    • aespipe
    • lesspipe
  • @LeSuisse dismissed
SPIP < 4.4.8 Cross-Site Scripting in Public Area

SPIP before 4.4.8 allows Cross-Site Scripting (XSS) in the public area for certain edge-case usage patterns. The echapper_html_suspect() function does not adequately detect all forms of malicious content, permitting an attacker to inject scripts that execute in a visitor's browser. This vulnerability is not mitigated by the SPIP security screen.

Affected products

SPIP
  • <4.4.8
Ignored packages (4)
Not present in nixpkgs.
Permalink CVE-2026-2662
3.3 LOW
  • CVSS version: 3.1
  • Attack vector (AV):
  • Attack complexity (AC):
  • Privileges required (PR):
  • User interaction (UI):
  • Scope (S):
  • Confidentiality impact (C):
  • Integrity impact (I):
  • Availability impact (A):
updated 1 month ago by @pyrox0 Activity log
  • Created automatic suggestion
  • @pyrox0 removed
    20 packages
    • lilypond
    • lilypond-unstable
    • lilypond-with-fonts
    • openlilylib-fonts.ross
    • gnomeExtensions.lilypad
    • openlilylib-fonts.haydn
    • openlilylib-fonts.bravura
    • openlilylib-fonts.cadence
    • openlilylib-fonts.gonville
    • openlilylib-fonts.lilyjazz
    • openlilylib-fonts.paganini
    • openlilylib-fonts.profondo
    • openlilylib-fonts.beethoven
    • openlilylib-fonts.improviso
    • openlilylib-fonts.scorlatti
    • lilypond-unstable-with-fonts
    • openlilylib-fonts.lilyboulez
    • openlilylib-fonts.sebastiano
    • openlilylib-fonts.lv-goldenage
    • openlilylib-fonts.gutenberg1939
  • @pyrox0 dismissed
FascinatedBox lily lily_emitter.c count_transforms out-of-bounds

A weakness has been identified in FascinatedBox lily up to 2.3. This vulnerability affects the function count_transforms of the file src/lily_emitter.c. This manipulation causes out-of-bounds read. The attack can only be executed locally. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

Affected products

lily
  • ==2.3
  • ==2.2
  • ==2.1
  • ==2.0
Ignored packages (20)
Does not apply to nixpkgs
updated 1 month ago by @pyrox0 Activity log
  • Created automatic suggestion
  • @pyrox0 removed package netcat
  • @pyrox0 dismissed
Off-by-one error in the OBJ_obj2txt function in LibreSSL before 2.3.1 …

Off-by-one error in the OBJ_obj2txt function in LibreSSL before 2.3.1 allows remote attackers to cause a denial of service (program crash) or possible execute arbitrary code via a crafted X.509 certificate, which triggers a stack-based buffer overflow. Note: this vulnerability exists because of an incorrect fix for CVE-2014-3508.

References

Affected products

LibreSSL
  • ==before 2.3.1

Matching in nixpkgs

Ignored packages (1)

pkgs.netcat

Utility which reads and writes data across network connections — LibreSSL implementation

Package maintainers

Does not apply to nixpkgs
updated 1 month ago by @pyrox0 Activity log
  • Created automatic suggestion
  • @pyrox0 removed
    26 packages
    • curl-impersonate
    • curl-impersonate-ff
    • curl-impersonate-chrome
    • yubikey-personalization
    • yubikey-personalization-gui
    • haskellPackages.amazonka-personalize
    • python312Packages.onedrive-personal-sdk
    • python313Packages.onedrive-personal-sdk
    • python314Packages.onedrive-personal-sdk
    • python312Packages.mypy-boto3-personalize
    • python313Packages.mypy-boto3-personalize
    • python314Packages.mypy-boto3-personalize
    • haskellPackages.amazonka-personalize-events
    • haskellPackages.amazonka-personalize-runtime
    • python312Packages.mypy-boto3-personalize-events
    • python312Packages.types-aiobotocore-personalize
    • python313Packages.mypy-boto3-personalize-events
    • python313Packages.types-aiobotocore-personalize
    • python314Packages.mypy-boto3-personalize-events
    • python312Packages.mypy-boto3-personalize-runtime
    • python313Packages.mypy-boto3-personalize-runtime
    • python314Packages.mypy-boto3-personalize-runtime
    • python312Packages.types-aiobotocore-personalize-events
    • python313Packages.types-aiobotocore-personalize-events
    • python312Packages.types-aiobotocore-personalize-runtime
    • python313Packages.types-aiobotocore-personalize-runtime
  • @pyrox0 dismissed
Cross-site request forgery (CSRF) vulnerability in the persona_xsrf_token function in …

Cross-site request forgery (CSRF) vulnerability in the persona_xsrf_token function in persona.module in the Mozilla Persona module 7.x-1.x before 7.x-1.11 for Drupal allows remote attackers to hijack the authentication of aribitrary users via a security token that is not a string data type.

Affected products

Persona
  • ==7.x-1.x versions prior to 7.x-1.11
Ignored packages (26)
Does not apply to nixpkgs
updated 1 month ago by @pyrox0 Activity log
  • Created automatic suggestion
  • @pyrox0 removed package steamguard-cli
  • @pyrox0 dismissed
Innominate mGuard before 7.6.4 and 8.x before 8.0.3 does not …

Innominate mGuard before 7.6.4 and 8.x before 8.0.3 does not require authentication for snapshot downloads, which allows remote attackers to obtain sensitive information via a crafted HTTPS request.

Affected products

n/a
  • ==n/a
mGuard
  • ==8.1.0
  • ==8.1.1
  • =<8.0.2
  • ==8.0.3
  • ==7.6.4
Ignored packages (1)
Does not apply to nixpkgs
updated 1 month ago by @pyrox0 Activity log
  • Created automatic suggestion
  • @pyrox0 removed
    9 packages
    • smfh
    • asmfmt
    • libsmf
    • nasmfmt
    • mt32emu-smf2wav
    • python312Packages.pysmf
    • python313Packages.pysmf
    • python314Packages.pysmf
    • tests.fetchFromGitHub.rootDir
  • @pyrox0 dismissed
Simple Machines Forum (SMF) through 2.0.5 has XSS

Simple Machines Forum (SMF) through 2.0.5 has XSS

Affected products

SMF
  • ==through 2.0.5
Ignored packages (9)

pkgs.libsmf

C library for reading and writing Standard MIDI Files

Does not apply to nixpkgs
updated 1 month ago by @pyrox0 Activity log
  • Created automatic suggestion
  • @pyrox0 removed
    4 packages
    • prmt
    • prmers
    • hyprmon
    • hyprmagnifier
  • @pyrox0 dismissed
Stack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and …

Stack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 and earlier, CENTUM CS 3000 Entry R3.09.50 and earlier, CENTUM VP R5.04.20 and earlier, CENTUM VP Entry R5.04.20 and earlier, ProSafe-RS R3.02.10 and earlier, Exaopc R3.72.00 and earlier, Exaquantum R2.85.00 and earlier, Exaquantum/Batch R2.50.30 and earlier, Exapilot R3.96.10 and earlier, Exaplog R3.40.00 and earlier, Exasmoc R4.03.20 and earlier, Exarqe R4.03.20 and earlier, Field Wireless Device OPC Server R2.01.02 and earlier, PRM R3.12.00 and earlier, STARDOM VDS R7.30.01 and earlier, STARDOM OPC Server for Windows R3.40 and earlier, FAST/TOOLS R10.01 and earlier, B/M9000CS R5.05.01 and earlier, B/M9000 VP R7.03.04 and earlier, and FieldMate R1.01 or R1.02 allows remote attackers to execute arbitrary code via a crafted packet.

Affected products

PRM
  • ==R3.12.00 and earlier
Exaopc
  • ==R3.72.00 and earlier
Exarqe
  • ==R4.03.20 and earlier
Exaplog
  • ==R3.40.00 and earlier
Exasmoc
  • ==R4.03.20 and earlier
Exapilot
  • ==R3.96.10 and earlier
B/M9000CS
  • ==R5.05.01 and earlier
CENTUM VP
  • ==R5.04.20 and earlier
FieldMate
  • ==R1.02
  • ==R1.01
B/M9000 VP
  • ==R7.03.04 and earlier
Exaquantum
  • ==R2.85.00 and earlier
FAST/TOOLS
  • ==R10.01 and earlier
ProSafe-RS
  • ==R3.02.10 and earlier
STARDOM VDS
  • ==R7.30.01 and earlier
CENTUM CS 1000
  • ==R3.08.70 and earlier
CENTUM CS 3000
  • ==R3.09.50 and earlier
CENTUM VP Entry
  • ==R5.04.20 and earlier
Exaquantum/Batch
  • ==R2.50.30 and earlier
CENTUM CS 3000 Entry
  • ==R3.09.50 and earlier
STARDOM OPC Server for Windows
  • ==R3.40 and earlier
Field Wireless Device OPC Server
  • ==R2.01.02 and earlier
Ignored packages (4)
Does not apply to anything in nixpkgs