Nixpkgs security tracker

Login with GitHub

Dismissed suggestions

These automatic suggestions were dismissed after initial triaging.

to select a suggestion for revision.

View:
Compact
Detailed
Permalink CVE-2026-3051
6.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): Low (L)
  • Exploit Code Maturity (E): Proof-of-Concept (P)
  • Remediation Level (RL): Not Defined (X)
  • Report Confidence (RC): Reasonable (R)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): Low (L)
updated 5 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    6 packages
    • rubyPackages.jekyll-theme-dinky
    • rubyPackages_3_1.jekyll-theme-dinky
    • rubyPackages_3_2.jekyll-theme-dinky
    • rubyPackages_3_3.jekyll-theme-dinky
    • rubyPackages_3_4.jekyll-theme-dinky
    • rubyPackages_4_0.jekyll-theme-dinky
  • @LeSuisse dismissed
DataLinkDC dinky Project Name GitRepository.java getProjectDir path traversal

A vulnerability has been found in DataLinkDC dinky up to 1.2.5. The affected element is the function getProjectDir of the file dinky-admin/src/main/java/org/dinky/utils/GitRepository.java of the component Project Name Handler. Such manipulation of the argument projectName leads to path traversal. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Affected products

dinky
  • ==1.2.4
  • ==1.2.5
  • ==1.2.2
  • ==1.2.3
  • ==1.2.1
  • ==1.2.0
Ignored packages (6)
Not present in nixpkgs
updated 5 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    9 packages
    • smfh
    • asmfmt
    • libsmf
    • nasmfmt
    • mt32emu-smf2wav
    • python312Packages.pysmf
    • python313Packages.pysmf
    • python314Packages.pysmf
    • tests.fetchFromGitHub.rootDir
  • @LeSuisse dismissed
free5GC SMF crash (nil pointer dereference) on PFCP SessionReportRequest when ReportType.USAR=1 and UsageReport omits mandatory URRID sub-IE 

free5GC SMF provides Session Management Function for free5GC, an open-source project for 5th generation (5G) mobile core networks. In versions up to and including 1.4.1, SMF panics and terminates when processing a malformed PFCP SessionReportRequest on the PFCP (UDP/8805) interface. No known upstream fix is available, but some workarounds are available. ACL/firewall the PFCP interface so only trusted UPF IPs can reach SMF (reduce spoofing/abuse surface); drop/inspect malformed PFCP SessionReportRequest messages at the network edge where feasible, and/or add recover() around PFCP handler dispatch to avoid whole-process termination (mitigation only).

Affected products

smf
  • ==<= 1.4.1
Ignored packages (9)

pkgs.smfh

Sleek Manifest File Handler

  • nixos-unstable 1.4
    • nixpkgs-unstable 1.4
    • nixos-unstable-small 1.4

pkgs.asmfmt

Go assembler formatter

pkgs.libsmf

C library for reading and writing Standard MIDI Files

  • nixos-unstable 1.3
    • nixpkgs-unstable 1.3
    • nixos-unstable-small 1.3
Not present in nixpkgs
updated 5 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed
An issue was discovered in in bwm-ng v0.6.2. An arbitrary …

An issue was discovered in in bwm-ng v0.6.2. An arbitrary null write exists in get_cmdln_options() function in src/options.c.

Affected products

bwm-ng
  • ==bwm-ng v0.6.2

Matching in nixpkgs

pkgs.bwm_ng

Small and simple console-based live network and disk io bandwidth monitor

Current stable branch was never impacted.
updated 5 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    10 packages
    • pscircle
    • libcircle
    • circle-flags
    • circleci-cli
    • pkgsRocm.libcircle
    • tela-circle-icon-theme
    • numix-icon-theme-circle
    • typstPackages.cross-circle
    • haskellPackages.circle-packing
    • typstPackages.cross-circle_1_0_0
  • @LeSuisse dismissed
Incorrect calculation in CIRCL secp384r1 CombinedMult

The CombinedMult function in the CIRCL ecc/p384 package (secp384r1 curve) produces an incorrect value for specific inputs. The issue is fixed by using complete addition formulas. ECDH and ECDSA signing relying on this curve are not affected. The bug was fixed in v1.6.3 https://github.com/cloudflare/circl/releases/tag/v1.6.3 .

Affected products

CIRCL
  • <1.6.3
Ignored packages (10)

pkgs.pscircle

Visualize Linux processes in a form of a radial tree

pkgs.libcircle

API for distributing embarrassingly parallel workloads using self-stabilization

  • nixos-unstable 0.3
    • nixpkgs-unstable 0.3
    • nixos-unstable-small 0.3

pkgs.circle-flags

Collection of 400+ minimal circular SVG country and state flags

pkgs.circleci-cli

Command to enable you to reproduce the CircleCI environment locally and run jobs as if they were running on the hosted CirleCI application.

pkgs.pkgsRocm.libcircle

API for distributing embarrassingly parallel workloads using self-stabilization

  • nixos-unstable 0.3
    • nixpkgs-unstable 0.3
    • nixos-unstable-small 0.3

pkgs.typstPackages.cross-circle

A rather convoluted implementation of cross'n'circle (aka. tic tac toe). Customize it to your hearts content

Not directly present in nixpkgs
Permalink CVE-2026-28195
4.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
updated 5 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    3 packages
    • python312Packages.teamcity-messages
    • python313Packages.teamcity-messages
    • python314Packages.teamcity-messages
  • @LeSuisse dismissed
In JetBrains TeamCity before 2025.11.3 missing authorization allowed project developers …

In JetBrains TeamCity before 2025.11.3 missing authorization allowed project developers to add parameters to build configurations

Affected products

TeamCity
  • <2025.11.3
Ignored packages (3)
Not present in nixpkgs
Permalink CVE-2026-28196
2.3 LOW
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
updated 5 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    3 packages
    • python312Packages.teamcity-messages
    • python313Packages.teamcity-messages
    • python314Packages.teamcity-messages
  • @LeSuisse dismissed
In JetBrains TeamCity before 2025.11.3 disabling versioned settings left a …

In JetBrains TeamCity before 2025.11.3 disabling versioned settings left a credentials config on disk

Affected products

TeamCity
  • <2025.11.3
Ignored packages (3)
Not present in nixpkgs
Permalink CVE-2026-28194
4.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
updated 5 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    3 packages
    • python312Packages.teamcity-messages
    • python313Packages.teamcity-messages
    • python314Packages.teamcity-messages
  • @LeSuisse dismissed
In JetBrains TeamCity before 2025.11.3 open redirect was possible in …

In JetBrains TeamCity before 2025.11.3 open redirect was possible in the React project creation flow

Affected products

TeamCity
  • <2025.11.3
Ignored packages (3)
Not present in nixpkgs
updated 5 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    3 packages
    • typstPackages.mercator
    • typstPackages.mercator_0_1_0
    • typstPackages.mercator_0_1_1
  • @LeSuisse dismissed
Mercator vulnerable to stored XSS via unescaped Blade directives in display templates

Mercator is an open source web application designed to enable mapping of information systems. A stored Cross-Site Scripting (XSS) vulnerability exists in Mercator prior to version 2026.02.22 due to the use of unescaped Blade directives (`{!! !!}`) in display templates. An authenticated user with the User role can inject arbitrary JavaScript payloads into fields such as "contact point" when creating or editing entities. The payload is then executed in the browser of any user who views the affected page, including administrators. Version 2026.02.22 fixes the vulnerability.

Affected products

mercator
  • ==< 2026.02.22
Ignored packages (3)
Not present in nixpkgs
updated 5 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    5 packages
    • loudmouth
    • cloudmonkey
    • python312Packages.nextcloudmonitor
    • python313Packages.nextcloudmonitor
    • python314Packages.nextcloudmonitor
  • @LeSuisse dismissed
free5GC has Null Pointer Dereference in UDM, Leading to Service Panic

free5gc UDM provides Unified Data Management (UDM) for free5GC, an open-source project for 5th generation (5G) mobile core networks. Versions up to and including 1.4.1 have a NULL Pointer Dereference vulnerability. Remote unauthenticated attackers can trigger a service panic (Denial of Service) by sending a crafted PUT request with an unexpected ueId, crashing the UDM service. All deployments of free5GC using the UDM component may be affected. free5gc/udm pull request 76 contains a fix for the issue. No direct workaround is available at the application level. Applying the official patch is recommended.

Affected products

udm
  • ==<= 1.4.1
Ignored packages (5)

pkgs.loudmouth

Lightweight C library for the Jabber protocol

Not present in nixpkgs
updated 5 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    10 packages
    • svelte-check
    • svelte-language-server
    • nodePackages.svelte-check
    • nodePackages_latest.svelte-check
    • vscode-extensions.svelte.svelte-vscode
    • tree-sitter-grammars.tree-sitter-svelte
    • vimPlugins.nvim-treesitter-parsers.svelte
    • python312Packages.tree-sitter-grammars.tree-sitter-svelte
    • python313Packages.tree-sitter-grammars.tree-sitter-svelte
    • python314Packages.tree-sitter-grammars.tree-sitter-svelte
  • @LeSuisse dismissed
Svelte vulnerable to XSS during SSR with contenteditable `bind:innerText` and `bind:textContent`

Svelte performance oriented web framework. Prior to version 5.53.5, the contents of `bind:innerText` and `bind:textContent` on `contenteditable` elements were not properly escaped. This could enable HTML injection and Cross-Site Scripting (XSS) if rendering untrusted data as the binding's initial value on the server. Version 5.53.5 fixes the issue.

Affected products

svelte
  • ==< 5.53.5
Ignored packages (10)
Not present in nixpkgs