Nixpkgs security tracker

Login with GitHub

Dismissed suggestions

These automatic suggestions were dismissed after initial triaging.

to select a suggestion for revision.

View:
Compact
Detailed
updated 4 months, 4 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    3 packages
    • tests.pkg-config.defaultPkgConfigPackages.ImageMagick
    • tests.pkg-config.defaultPkgConfigPackages.MagickWand
    • graphicsmagick-imagemagick-compat
  • @LeSuisse dismissed
A heap-based buffer overflow vulnerability was found in ImageMagick in …

A heap-based buffer overflow vulnerability was found in ImageMagick in versions prior to 7.0.11-14 in ReadTIFFImage() in coders/tiff.c. This issue is due to an incorrect setting of the pixel array size, which can lead to a crash and segmentation fault.

Affected products

ImageMagick
  • ==ImageMagick 7.0.11-14

Matching in nixpkgs

pkgs.imagemagick

Software suite to create, edit, compose, or convert bitmap images

Ignored packages (3)

Package maintainers

Current stable branch was never impacted
Permalink CVE-2024-37931
4.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
updated 5 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    76 packages
    • pinpoint
    • git-point
    • ratpoints
    • mountpoint-s3
    • breakpointHook
    • libpointmatcher
    • xpointerbarrier
    • highlight-pointer
    • breakpointHookCntr
    • quake3pointrelease
    • haskellPackages.pointed
    • haskellPackages.fixpoint
    • haskellPackages.pointfree
    • python312Packages.pypoint
    • python313Packages.pypoint
    • haskellPackages.breakpoint
    • haskellPackages.mountpoints
    • haskellPackages.pointedlist
    • python312Packages.datapoint
    • python313Packages.datapoint
    • haskellPackages.pointless-fun
    • python312Packages.entrypoint2
    • python312Packages.entrypoints
    • python312Packages.jsonpointer
    • python313Packages.entrypoint2
    • python313Packages.entrypoints
    • python313Packages.jsonpointer
    • gnomeExtensions.pointer-tracker
    • rubyPackages.indieweb-endpoints
    • haskellPackages.amazonka-pinpoint
    • python312Packages.fastentrypoints
    • python313Packages.fastentrypoints
    • typstPackages.stack-pointer_0_1_0
    • python312Packages.entry-points-txt
    • python312Packages.orbax-checkpoint
    • python313Packages.entry-points-txt
    • python313Packages.orbax-checkpoint
    • typstPackages.pointless-size_0_1_0
    • typstPackages.pointless-size_0_1_1
    • rubyPackages_3_1.indieweb-endpoints
    • rubyPackages_3_2.indieweb-endpoints
    • rubyPackages_3_3.indieweb-endpoints
    • rubyPackages_3_4.indieweb-endpoints
    • home-assistant-component-tests.point
    • haskellPackages.acme-pointful-numbers
    • python312Packages.mypy-boto3-pinpoint
    • python313Packages.mypy-boto3-pinpoint
    • python312Packages.checkpoint-schedules
    • python312Packages.langgraph-checkpoint
    • python313Packages.checkpoint-schedules
    • python313Packages.langgraph-checkpoint
    • haskellPackages.amazonka-pinpoint-email
    • haskellPackages.amazonka-pinpoint-sms-voice
    • python312Packages.mypy-boto3-pinpoint-email
    • python313Packages.mypy-boto3-pinpoint-email
    • python312Packages.types-aiobotocore-pinpoint
    • python313Packages.types-aiobotocore-pinpoint
    • python312Packages.langgraph-checkpoint-sqlite
    • python313Packages.langgraph-checkpoint-sqlite
    • haskellPackages.amazonka-pinpoint-sms-voice-v2
    • python312Packages.langgraph-checkpoint-postgres
    • python312Packages.mypy-boto3-pinpoint-sms-voice
    • python313Packages.langgraph-checkpoint-postgres
    • python313Packages.mypy-boto3-pinpoint-sms-voice
    • python312Packages.mypy-boto3-pinpoint-sms-voice-v2
    • python312Packages.types-aiobotocore-pinpoint-email
    • python313Packages.mypy-boto3-pinpoint-sms-voice-v2
    • python313Packages.types-aiobotocore-pinpoint-email
    • python312Packages.backports-entry-points-selectable
    • python313Packages.backports-entry-points-selectable
    • python312Packages.types-aiobotocore-pinpoint-sms-voice
    • python313Packages.types-aiobotocore-pinpoint-sms-voice
    • python312Packages.azure-synapse-managedprivateendpoints
    • python313Packages.azure-synapse-managedprivateendpoints
    • python312Packages.types-aiobotocore-pinpoint-sms-voice-v2
    • python313Packages.types-aiobotocore-pinpoint-sms-voice-v2
  • @LeSuisse dismissed
WordPress Point theme <= 1.1 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in Creativthemes Point allows Cross Site Request Forgery.This issue affects Point: from n/a through 1.1.

Affected products

point
  • =<1.1
Ignored packages (76)

pkgs.pinpoint

Tool for making hackers do excellent presentations

  • nixos-unstable -

pkgs.git-point

Set arbitrary refs without shooting yourself in the foot, a procelain `git update-ref`

  • nixos-unstable -

pkgs.ratpoints

Program to find rational points on hyperelliptic curves

  • nixos-unstable -

pkgs.mountpoint-s3

Simple, high-throughput file client for mounting an Amazon S3 bucket as a local file system

  • nixos-unstable -

pkgs.libpointmatcher

"Iterative Closest Point" library for 2-D/3-D mapping in robotic

  • nixos-unstable -

pkgs.xpointerbarrier

Create X11 pointer barriers around your working area

  • nixos-unstable -

pkgs.highlight-pointer

Highlight mouse pointer/cursor using a dot

  • nixos-unstable -
    • nixpkgs-unstable 1.2

pkgs.typstPackages.pointless-size_0_1_0

中文字号的号数制及字体度量单位 Chinese size system (hào-system) and type-related measurements units

  • nixos-unstable -

pkgs.typstPackages.pointless-size_0_1_1

中文字号的号数制及字体度量单位 Chinese size system (hào-system) and type-related measurements units

  • nixos-unstable -
WP theme not present in nixpkgs
updated 5 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    3 packages
    • eludris
    • cloudrecon
    • vscode-extensions.saoudrizwan.claude-dev
  • @LeSuisse dismissed
free5GC vulnerable to improper error handling in NEF with information exposure

free5GC is an open-source project for 5th generation (5G) mobile core networks. Versions up to and including 1.4.1 of the User Data Repository are affected by Improper Error Handling with Information Exposure. The NEF component reliably leaks internal parsing error details (e.g., invalid character 'n' after top-level value) to remote clients, which can aid attackers in service fingerprinting. All deployments of free5GC using the Nnef_PfdManagement service may be vulnerable. free5gc/udr pull request 56 contains a patch. No direct workaround is available at the application level. Applying the official patch is recommended.

Affected products

udr
  • ==<= 1.4.1
Ignored packages (3)

pkgs.eludris

Simple CLI to help you with setting up and managing your Eludris instance

pkgs.cloudrecon

Tool to find assets from certificates

pkgs.vscode-extensions.saoudrizwan.claude-dev

VSCode extension providing an autonomous coding agent right in your IDE, capable of creating/editing files, executing commands, using the browser, and more with your permission every step of the way

Not present in nixpkgs
Permalink CVE-2026-25899
7.5 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): High (H)
updated 5 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    3 packages
    • guile-fibers
    • ocamlPackages.fiber
    • ocamlPackages_latest.fiber
  • @LeSuisse dismissed
Fiber is Vulnerable to Denial of Service via Flash Cookie Unbounded Allocation

Fiber is an Express inspired web framework written in Go. In versions on the v3 branch prior to 3.1.0, the use of the `fiber_flash` cookie can force an unbounded allocation on any server. A crafted 10-character cookie value triggers an attempt to allocate up to 85GB of memory via unvalidated msgpack deserialization. No authentication is required. Every GoFiber v3 endpoint is affected regardless of whether the application uses flash messages. Version 3.1.0 fixes the issue.

Affected products

fiber
  • ==>= 3.0.0, < 3.1.0
Ignored packages (3)
Not directly present in nixpkgs
updated 5 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    3 packages
    • guile-fibers
    • ocamlPackages.fiber
    • ocamlPackages_latest.fiber
  • @LeSuisse dismissed
Fiber has a Denial of Service Vulnerability via Route Parameter Overflow

Fiber is an Express inspired web framework written in Go. A denial of service vulnerability exists in Fiber v2 and v3 that allows remote attackers to crash the application by sending requests to routes with more than 30 parameters. The vulnerability results from missing validation during route registration combined with an unbounded array write during request matching. Version 2.52.12 patches the issue in the v2 branch and 3.1.0 patches the issue in the v3 branch.

Affected products

fiber
  • ==>= 3.0.0, < 3.1.0
  • ==>= 2.0.0, < 2.52.12
Ignored packages (3)
Not directly present in nixpkgs
updated 5 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    3 packages
    • guile-fibers
    • ocamlPackages.fiber
    • ocamlPackages_latest.fiber
  • @LeSuisse dismissed
Fiber has an Arbitrary File Read in Static Middleware on Windows

Fiber is an Express inspired web framework written in Go. A Path Traversal (CWE-22) vulnerability in Fiber allows a remote attacker to bypass the static middleware sanitizer and read arbitrary files on the server file system on Windows. This affects Fiber v3 through version 3.0.0. This has been patched in Fiber v3 version 3.1.0.

Affected products

fiber
  • ==>= 3.0.0, < 3.1.0
Ignored packages (3)
Not directly present in nixpkgs, Windows
Permalink CVE-2026-27700
8.2 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
updated 5 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    22 packages
    • libsForQt5.phonon
    • kdePackages.phonon
    • kdePackages.phonon-vlc
    • plasma5Packages.phonon
    • typstPackages.phonokit
    • python312Packages.phonopy
    • python313Packages.phonopy
    • python314Packages.phonopy
    • typstPackages.phonokit_0_0_1
    • typstPackages.phonokit_0_2_0
    • typstPackages.phonokit_0_3_0
    • typstPackages.phonokit_0_3_5
    • typstPackages.phonokit_0_3_6
    • typstPackages.phonokit_0_3_7
    • typstPackages.phonokit_0_4_0
    • libsForQt5.phonon-backend-vlc
    • python312Packages.pythonocc-core
    • python313Packages.pythonocc-core
    • python314Packages.pythonocc-core
    • plasma5Packages.phonon-backend-vlc
    • libsForQt5.phonon-backend-gstreamer
    • plasma5Packages.phonon-backend-gstreamer
  • @LeSuisse dismissed
Hono is Vulnerable to Authentication Bypass by IP Spoofing in AWS Lambda ALB conninfo

Hono is a Web application framework that provides support for any JavaScript runtime. In versions 4.12.0 and 4.12.1, when using the AWS Lambda adapter (`hono/aws-lambda`) behind an Application Load Balancer (ALB), the `getConnInfo()` function incorrectly selected the first value from the `X-Forwarded-For` header. Because AWS ALB appends the real client IP address to the end of the `X-Forwarded-For` header, the first value can be attacker-controlled. This could allow IP-based access control mechanisms (such as the `ipRestriction` middleware) to be bypassed. Version 4.12.2 patches the issue.

Affected products

hono
  • ==>= 4.12.0, < 4.12.2
Ignored packages (22)

pkgs.typstPackages.phonokit_0_0_1

Phonology toolkit: IPA transcription (tipa-style), prosodic structures, vowel/consonant charts with language inventories

Not present in nixpkgs
updated 5 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    20 packages
    • serverspec
    • vscode-langservers-extracted
    • haskellPackages.serversession
    • python312Packages.pytest-mockservers
    • python313Packages.pytest-mockservers
    • python314Packages.pytest-mockservers
    • haskellPackages.serversession-frontend-wai
    • haskellPackages.serversession-backend-redis
    • haskellPackages.serversession-frontend-snap
    • python312Packages.paypal-checkout-serversdk
    • python313Packages.paypal-checkout-serversdk
    • python314Packages.paypal-checkout-serversdk
    • haskellPackages.serversession-frontend-yesod
    • haskellPackages.serversession-backend-acid-state
    • python312Packages.azure-mgmt-mysqlflexibleservers
    • python313Packages.azure-mgmt-mysqlflexibleservers
    • python314Packages.azure-mgmt-mysqlflexibleservers
    • python312Packages.azure-mgmt-postgresqlflexibleservers
    • python313Packages.azure-mgmt-postgresqlflexibleservers
    • python314Packages.azure-mgmt-postgresqlflexibleservers
  • @LeSuisse dismissed
mcp-server-git : Path traversal in git_add allows staging files outside repository boundaries

Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). In mcp-server-git versions prior to 2026.1.14, the git_add tool did not validate that file paths provided in the files argument were within the repository boundaries. Because the tool used GitPython's repo.index.add() rather than the Git CLI, relative paths containing `../` sequences that resolve outside the repository were accepted and staged into the Git index. Users are advised to upgrade to 2026.1.14 or newer to remediate this issue.

Affected products

servers
  • ==< 2026.1.14
Ignored packages (20)

pkgs.serverspec

RSpec tests for your servers configured by CFEngine, Puppet, Ansible, Itamae or anything else

Not present in nixpkgs
Permalink CVE-2025-67860
3.8 LOW
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): Low (L)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
updated 5 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored package theharvester
  • @LeSuisse dismissed
NeuVector scanner insecurely handles passwords as command arguments

A vulnerability has been identified in the NeuVector scanner where the scanner process accepts registry and controller credentials as command-line arguments, potentially exposing sensitive credentials to local users.

Affected products

github.com/neuvector/scanner
  • <4.072
Ignored packages (1)

pkgs.theharvester

Gather E-mails, subdomains and names from different public sources

Not present in nixpkgs
updated 5 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    9 packages
    • smfh
    • asmfmt
    • libsmf
    • nasmfmt
    • mt32emu-smf2wav
    • python312Packages.pysmf
    • python313Packages.pysmf
    • python314Packages.pysmf
    • tests.fetchFromGitHub.rootDir
  • @LeSuisse dismissed
free5GC SMF crash (nil pointer dereference) on PFCP SessionReportRequest when ReportType.USAR=1 and UsageReport omits mandatory URRID sub-IE 

free5GC SMF provides Session Management Function for free5GC, an open-source project for 5th generation (5G) mobile core networks. In versions up to and including 1.4.1, SMF panics and terminates when processing a malformed PFCP SessionReportRequest on the PFCP (UDP/8805) interface. No known upstream fix is available, but some workarounds are available. ACL/firewall the PFCP interface so only trusted UPF IPs can reach SMF (reduce spoofing/abuse surface); drop/inspect malformed PFCP SessionReportRequest messages at the network edge where feasible, and/or add recover() around PFCP handler dispatch to avoid whole-process termination (mitigation only).

Affected products

smf
  • ==<= 1.4.1
Ignored packages (9)

pkgs.smfh

Sleek Manifest File Handler

  • nixos-unstable 1.4
    • nixpkgs-unstable 1.4
    • nixos-unstable-small 1.4

pkgs.asmfmt

Go assembler formatter

pkgs.libsmf

C library for reading and writing Standard MIDI Files

  • nixos-unstable 1.3
    • nixpkgs-unstable 1.3
    • nixos-unstable-small 1.3
Not present in nixpkgs