Nixpkgs security tracker

Login with GitHub

Dismissed suggestions

These automatic suggestions were dismissed after initial triaging.

to select a suggestion for revision.

View:
Compact
Detailed
updated 5 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    3 packages
    • plank
    • libsForQt5.plank-player
    • plasma5Packages.plank-player
  • @LeSuisse dismissed
WordPress Plank theme <= 1.7 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Plank plank allows PHP Local File Inclusion.This issue affects Plank: from n/a through <= 1.7.

Affected products

plank
  • =<<= 1.7
Ignored packages (3)
WP theme not present
updated 5 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    5 packages
    • gnutls
    • guile-gnutls
    • python312Packages.python3-gnutls
    • python313Packages.python3-gnutls
    • python314Packages.python3-gnutls
  • @LeSuisse dismissed
uTLS has a Chrome Parrot Fingerprint Vulnerability due to GREASE ECH Cipher Suite Mismatch

uTLS is a fork of crypto/tls, created to customize ClientHello for fingerprinting resistance while still using it for the handshake. Versions 1.6.0 through 1.8.0 contain a fingerprint mismatch with Chrome when using GREASE ECH, related to cipher suite selection. When Chrome selects the preferred cipher suite in the outer ClientHello and for ECH, it does so consistently based on hardware support—for example, if it prefers AES for the outer cipher suite, it also uses AES for ECH. However, the Chrome parrot in uTLS hardcodes AES preference for outer cipher suites but selects the ECH cipher suite randomly between AES and ChaCha20. This creates a 50% chance of selecting ChaCha20 for ECH while using AES for the outer cipher suite, a combination impossible in Chrome. This issue only affects GREASE ECH; in real ECH, Chrome selects the first valid cipher suite when AES is preferred, which uTLS handles correctly. This issue has been fixed in version 1.8.1.

Affected products

utls
  • ==>= 1.6.0, < 1.8.1
Ignored packages (5)

pkgs.gnutls

GNU Transport Layer Security Library

Not present in nixpkgs
Permalink CVE-2026-26994
6.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
updated 5 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    5 packages
    • gnutls
    • guile-gnutls
    • python312Packages.python3-gnutls
    • python313Packages.python3-gnutls
    • python314Packages.python3-gnutls
  • @LeSuisse dismissed
uTLS ServerHellos are accepted without checking TLS 1.3 downgrade canaries

uTLS is a fork of crypto/tls, created to customize ClientHello for fingerprinting resistance while still using it for the handshake. In versions 1.6.7 and below, uTLS did not implement the TLS 1.3 downgrade protection mechanism specified in RFC 8446 Section 4.1.3 when using a uTLS ClientHello spec. This allowed an active network adversary to downgrade TLS 1.3 connections initiated by a uTLS client to a lower TLS version (e.g., TLS 1.2) by modifying the ClientHello message to exclude the SupportedVersions extension, causing the server to respond with a TLS 1.2 ServerHello (along with a downgrade canary in the ServerHello random field). Because uTLS did not check the downgrade canary in the ServerHello random field, clients would accept the downgraded connection without detecting the attack. This attack could also be used by an active network attacker to fingerprint uTLS connections. This issue has been fixed in version 1.7.0.

Affected products

utls
  • ==< 1.7.0
Ignored packages (5)

pkgs.gnutls

GNU Transport Layer Security Library

Not present in nixpkgs
updated 5 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    3 packages
    • python312Packages.cobble
    • python313Packages.cobble
    • python314Packages.cobble
  • @LeSuisse dismissed
WordPress Cobble theme <= 1.7 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Cobble cobble allows PHP Local File Inclusion.This issue affects Cobble: from n/a through <= 1.7.

Affected products

cobble
  • =<<= 1.7
Ignored packages (3)
WP theme not present in nixpkgs
updated 5 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored package calibre-web
  • @LeSuisse dismissed
A untrusted search path issue was found in Calibre at …

A untrusted search path issue was found in Calibre at devices/linux_mount_helper.c leading to the ability of unprivileged users to execute any program as root.

References

Affected products

Calibre
  • ==unknown

Matching in nixpkgs

Ignored packages (1)

pkgs.calibre-web

Web app for browsing, reading and downloading eBooks stored in a Calibre database

Package maintainers

Old issue, current stable branch was never impacted
updated 5 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored package calibre-web
  • @LeSuisse dismissed
Race condition issues were found in Calibre at devices/linux_mount_helper.c allowing …

Race condition issues were found in Calibre at devices/linux_mount_helper.c allowing unprivileged users the ability to mount any device to anywhere.

References

Affected products

Calibre
  • ==unknown

Matching in nixpkgs

Ignored packages (1)

pkgs.calibre-web

Web app for browsing, reading and downloading eBooks stored in a Calibre database

Package maintainers

Old issue, current stable branch was never impacted
updated 5 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored package calibre-web
  • @LeSuisse dismissed
Input validation issues were found in Calibre at devices/linux_mount_helper.c which …

Input validation issues were found in Calibre at devices/linux_mount_helper.c which can lead to argument injection and elevation of privileges.

References

Affected products

Calibre
  • ==unknown

Matching in nixpkgs

Ignored packages (1)

pkgs.calibre-web

Web app for browsing, reading and downloading eBooks stored in a Calibre database

Package maintainers

Old issue, current stable branch was never impacted
updated 5 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored package moodle-dl
  • @LeSuisse dismissed
Moodle before 2.2.2 has a default repository capabilities issue where …

Moodle before 2.2.2 has a default repository capabilities issue where all repositories are viewable by all users by default

Affected products

Moodle
  • ==2.0 to 2.0.7+
  • ==2.1 to 2.1.4+
  • ==2.2 to 2.2.1+

Matching in nixpkgs

pkgs.moodle

Free and open-source learning management system (LMS) written in PHP

Ignored packages (1)

pkgs.moodle-dl

Moodle downloader that downloads course content fast from Moodle

Old issue current stable branch was never impacted.
updated 5 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored package moodle-dl
  • @LeSuisse dismissed
Moodle before 2.2.2: Course information leak via hidden courses being …

Moodle before 2.2.2: Course information leak via hidden courses being displayed in tag search results

Affected products

Moodle
  • ==2.1 to 2.1.4+
  • ==2.2 to 2.2.1+

Matching in nixpkgs

pkgs.moodle

Free and open-source learning management system (LMS) written in PHP

Ignored packages (1)

pkgs.moodle-dl

Moodle downloader that downloads course content fast from Moodle

Old issue current stable branch was never impacted.
updated 5 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored package moodle-dl
  • @LeSuisse dismissed
Moodle before 2.2.2 has users' private files included in course …

Moodle before 2.2.2 has users' private files included in course backups

Affected products

Moodle
  • ==2.0 to 2.0.7+
  • ==2.1 to 2.1.4+
  • ==2.2 to 2.2.1+

Matching in nixpkgs

pkgs.moodle

Free and open-source learning management system (LMS) written in PHP

Ignored packages (1)

pkgs.moodle-dl

Moodle downloader that downloads course content fast from Moodle

Old issue current stable branch was never impacted.