Nixpkgs security tracker

Login with GitHub

Dismissed suggestions

These automatic suggestions were dismissed after initial triaging.

to select a suggestion for revision.

View:
Compact
Detailed
Permalink CVE-2026-2709
3.5 LOW
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Exploit Code Maturity (E): Proof-of-Concept (P)
  • Remediation Level (RL): Not Defined (X)
  • Report Confidence (RC): Reasonable (R)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
updated 5 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    13 packages
    • busybox
    • gobusybox
    • busybox-sandbox-shell
    • python312Packages.busypie
    • python313Packages.busypie
    • python314Packages.busypie
    • minimal-bootstrap.busybox-static
    • python312Packages.busylight-core
    • python313Packages.busylight-core
    • python314Packages.busylight-core
    • python312Packages.busylight-for-humans
    • python313Packages.busylight-for-humans
    • python314Packages.busylight-for-humans
  • @LeSuisse dismissed
busy Callback app.js redirect

A flaw has been found in busy up to 2.5.5. The affected element is an unknown function of the file source-code/busy-master/src/server/app.js of the component Callback Handler. Executing a manipulation of the argument state can lead to open redirect. It is possible to launch the attack remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Affected products

busy
  • ==2.5.3
  • ==2.5.4
  • ==2.5.0
  • ==2.5.1
  • ==2.5.2
  • ==2.5.5
Ignored packages (13)

pkgs.busybox

Tiny versions of common UNIX utilities in a single small executable

Not present in nixpkgs
Permalink CVE-2026-0549
6.4 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
updated 5 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    31 packages
    • fedigroups
    • sway-assign-cgroups
    • haskellPackages.groups
    • haskellPackages.semigroups
    • haskellPackages.groups-generic
    • haskellPackages.finite-semigroups
    • haskellPackages.quickcheck-groups
    • haskellPackages.numbered-semigroups
    • python312Packages.dependency-groups
    • python313Packages.dependency-groups
    • python314Packages.dependency-groups
    • gnomeExtensions.kolour-groups-windows
    • haskellPackages.gogol-groups-settings
    • haskellPackages.commutative-semigroups
    • haskellPackages.gogol-groups-migration
    • haskellPackages.amazonka-resourcegroups
    • chickenPackages_5.chickenEggs.posix-groups
    • python312Packages.mypy-boto3-resource-groups
    • python313Packages.mypy-boto3-resource-groups
    • python314Packages.mypy-boto3-resource-groups
    • python312Packages.azure-mgmt-managementgroups
    • python313Packages.azure-mgmt-managementgroups
    • python314Packages.azure-mgmt-managementgroups
    • haskellPackages.amazonka-resourcegroupstagging
    • python312Packages.types-aiobotocore-resource-groups
    • python313Packages.types-aiobotocore-resource-groups
    • python312Packages.mypy-boto3-resourcegroupstaggingapi
    • python313Packages.mypy-boto3-resourcegroupstaggingapi
    • python314Packages.mypy-boto3-resourcegroupstaggingapi
    • python312Packages.types-aiobotocore-resourcegroupstaggingapi
    • python313Packages.types-aiobotocore-resourcegroupstaggingapi
  • @LeSuisse dismissed
Groups <= 3.10.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'groups_group_info' Shortcode

The Groups plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'groups_group_info' shortcode in all versions up to, and including, 3.10.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Affected products

Groups
  • =<3.10.0
Ignored packages (31)

pkgs.fedigroups

Approximation of groups usable with Fediverse software that implements the Mastodon client API

pkgs.sway-assign-cgroups

Place GUI applications into systemd scopes for systemd-oomd compatibility

WP plugin not present in nixpkgs.
Permalink CVE-2026-26345
4.7 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Changed (C)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
updated 5 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    4 packages
    • spip
    • spiped
    • aespipe
    • lesspipe
  • @LeSuisse dismissed
SPIP < 4.4.8 Cross-Site Scripting in Public Area

SPIP before 4.4.8 allows Cross-Site Scripting (XSS) in the public area for certain edge-case usage patterns. The echapper_html_suspect() function does not adequately detect all forms of malicious content, permitting an attacker to inject scripts that execute in a visitor's browser. This vulnerability is not mitigated by the SPIP security screen.

Affected products

SPIP
  • <4.4.8
Ignored packages (4)

pkgs.spiped

Utility for secure encrypted channels between sockets

pkgs.aespipe

AES encrypting or decrypting pipe

  • nixos-unstable 2.4j
    • nixpkgs-unstable 2.4j
    • nixos-unstable-small 2.4j

pkgs.lesspipe

Preprocessor for less

  • nixos-unstable 2.20
    • nixpkgs-unstable 2.20
    • nixos-unstable-small 2.20
Not present in nixpkgs.
Permalink CVE-2026-2662
3.3 LOW
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): Low (L)
  • Exploit Code Maturity (E): Proof-of-Concept (P)
  • Remediation Level (RL): Not Defined (X)
  • Report Confidence (RC): Reasonable (R)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): Low (L)
updated 5 months, 1 week ago by @pyrox0 Activity log
  • Created suggestion
  • @pyrox0 ignored
    20 packages
    • lilypond
    • lilypond-unstable
    • lilypond-with-fonts
    • openlilylib-fonts.ross
    • gnomeExtensions.lilypad
    • openlilylib-fonts.haydn
    • openlilylib-fonts.bravura
    • openlilylib-fonts.cadence
    • openlilylib-fonts.gonville
    • openlilylib-fonts.lilyjazz
    • openlilylib-fonts.paganini
    • openlilylib-fonts.profondo
    • openlilylib-fonts.beethoven
    • openlilylib-fonts.improviso
    • openlilylib-fonts.scorlatti
    • lilypond-unstable-with-fonts
    • openlilylib-fonts.lilyboulez
    • openlilylib-fonts.sebastiano
    • openlilylib-fonts.lv-goldenage
    • openlilylib-fonts.gutenberg1939
  • @pyrox0 dismissed
FascinatedBox lily lily_emitter.c count_transforms out-of-bounds

A weakness has been identified in FascinatedBox lily up to 2.3. This vulnerability affects the function count_transforms of the file src/lily_emitter.c. This manipulation causes out-of-bounds read. The attack can only be executed locally. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

Affected products

lily
  • ==2.2
  • ==2.0
  • ==2.3
  • ==2.1
Ignored packages (20)
Does not apply to nixpkgs
updated 5 months, 1 week ago by @pyrox0 Activity log
  • Created suggestion
  • @pyrox0 ignored package netcat
  • @pyrox0 dismissed
Off-by-one error in the OBJ_obj2txt function in LibreSSL before 2.3.1 …

Off-by-one error in the OBJ_obj2txt function in LibreSSL before 2.3.1 allows remote attackers to cause a denial of service (program crash) or possible execute arbitrary code via a crafted X.509 certificate, which triggers a stack-based buffer overflow. Note: this vulnerability exists because of an incorrect fix for CVE-2014-3508.

Affected products

LibreSSL
  • ==before 2.3.1

Matching in nixpkgs

Ignored packages (1)

pkgs.netcat

Utility which reads and writes data across network connections — LibreSSL implementation

Package maintainers

Does not apply to nixpkgs
updated 5 months, 1 week ago by @pyrox0 Activity log
  • Created suggestion
  • @pyrox0 ignored
    26 packages
    • curl-impersonate
    • curl-impersonate-ff
    • curl-impersonate-chrome
    • yubikey-personalization
    • yubikey-personalization-gui
    • haskellPackages.amazonka-personalize
    • python312Packages.onedrive-personal-sdk
    • python313Packages.onedrive-personal-sdk
    • python314Packages.onedrive-personal-sdk
    • python312Packages.mypy-boto3-personalize
    • python313Packages.mypy-boto3-personalize
    • python314Packages.mypy-boto3-personalize
    • haskellPackages.amazonka-personalize-events
    • haskellPackages.amazonka-personalize-runtime
    • python312Packages.mypy-boto3-personalize-events
    • python312Packages.types-aiobotocore-personalize
    • python313Packages.mypy-boto3-personalize-events
    • python313Packages.types-aiobotocore-personalize
    • python314Packages.mypy-boto3-personalize-events
    • python312Packages.mypy-boto3-personalize-runtime
    • python313Packages.mypy-boto3-personalize-runtime
    • python314Packages.mypy-boto3-personalize-runtime
    • python312Packages.types-aiobotocore-personalize-events
    • python313Packages.types-aiobotocore-personalize-events
    • python312Packages.types-aiobotocore-personalize-runtime
    • python313Packages.types-aiobotocore-personalize-runtime
  • @pyrox0 dismissed
Cross-site request forgery (CSRF) vulnerability in the persona_xsrf_token function in …

Cross-site request forgery (CSRF) vulnerability in the persona_xsrf_token function in persona.module in the Mozilla Persona module 7.x-1.x before 7.x-1.11 for Drupal allows remote attackers to hijack the authentication of aribitrary users via a security token that is not a string data type.

References

Affected products

Persona
  • ==7.x-1.x versions prior to 7.x-1.11
Ignored packages (26)

pkgs.curl-impersonate

Special build of curl that can impersonate Chrome, Edge, Safari and Firefox

Does not apply to nixpkgs
updated 5 months, 1 week ago by @pyrox0 Activity log
  • Created suggestion
  • @pyrox0 ignored package steamguard-cli
  • @pyrox0 dismissed
Innominate mGuard before 7.6.4 and 8.x before 8.0.3 does not …

Innominate mGuard before 7.6.4 and 8.x before 8.0.3 does not require authentication for snapshot downloads, which allows remote attackers to obtain sensitive information via a crafted HTTPS request.

Affected products

n/a
  • ==n/a
mGuard
  • ==8.1.0
  • ==8.1.1
  • =<8.0.2
  • ==8.0.3
  • ==7.6.4
Ignored packages (1)

pkgs.steamguard-cli

Linux utility for generating 2FA codes for Steam and managing Steam trade confirmations

Does not apply to nixpkgs
updated 5 months, 1 week ago by @pyrox0 Activity log
  • Created suggestion
  • @pyrox0 ignored
    9 packages
    • smfh
    • asmfmt
    • libsmf
    • nasmfmt
    • mt32emu-smf2wav
    • python312Packages.pysmf
    • python313Packages.pysmf
    • python314Packages.pysmf
    • tests.fetchFromGitHub.rootDir
  • @pyrox0 dismissed
Simple Machines Forum (SMF) through 2.0.5 has XSS

Simple Machines Forum (SMF) through 2.0.5 has XSS

Affected products

SMF
  • ==through 2.0.5
Ignored packages (9)

pkgs.smfh

Sleek Manifest File Handler

  • nixos-unstable 1.3
    • nixpkgs-unstable 1.3
    • nixos-unstable-small 1.4

pkgs.asmfmt

Go assembler formatter

pkgs.libsmf

C library for reading and writing Standard MIDI Files

  • nixos-unstable 1.3
    • nixpkgs-unstable 1.3
    • nixos-unstable-small 1.3
Does not apply to nixpkgs
updated 5 months, 1 week ago by @pyrox0 Activity log
  • Created suggestion
  • @pyrox0 ignored
    4 packages
    • prmt
    • prmers
    • hyprmon
    • hyprmagnifier
  • @pyrox0 dismissed
Stack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and …

Stack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 and earlier, CENTUM CS 3000 Entry R3.09.50 and earlier, CENTUM VP R5.04.20 and earlier, CENTUM VP Entry R5.04.20 and earlier, ProSafe-RS R3.02.10 and earlier, Exaopc R3.72.00 and earlier, Exaquantum R2.85.00 and earlier, Exaquantum/Batch R2.50.30 and earlier, Exapilot R3.96.10 and earlier, Exaplog R3.40.00 and earlier, Exasmoc R4.03.20 and earlier, Exarqe R4.03.20 and earlier, Field Wireless Device OPC Server R2.01.02 and earlier, PRM R3.12.00 and earlier, STARDOM VDS R7.30.01 and earlier, STARDOM OPC Server for Windows R3.40 and earlier, FAST/TOOLS R10.01 and earlier, B/M9000CS R5.05.01 and earlier, B/M9000 VP R7.03.04 and earlier, and FieldMate R1.01 or R1.02 allows remote attackers to execute arbitrary code via a crafted packet.

References

Affected products

PRM
  • ==R3.12.00 and earlier
Exaopc
  • ==R3.72.00 and earlier
Exarqe
  • ==R4.03.20 and earlier
Exaplog
  • ==R3.40.00 and earlier
Exasmoc
  • ==R4.03.20 and earlier
Exapilot
  • ==R3.96.10 and earlier
B/M9000CS
  • ==R5.05.01 and earlier
CENTUM VP
  • ==R5.04.20 and earlier
FieldMate
  • ==R1.01
  • ==R1.02
B/M9000 VP
  • ==R7.03.04 and earlier
Exaquantum
  • ==R2.85.00 and earlier
FAST/TOOLS
  • ==R10.01 and earlier
ProSafe-RS
  • ==R3.02.10 and earlier
STARDOM VDS
  • ==R7.30.01 and earlier
CENTUM CS 1000
  • ==R3.08.70 and earlier
CENTUM CS 3000
  • ==R3.09.50 and earlier
CENTUM VP Entry
  • ==R5.04.20 and earlier
Exaquantum/Batch
  • ==R2.50.30 and earlier
CENTUM CS 3000 Entry
  • ==R3.09.50 and earlier
STARDOM OPC Server for Windows
  • ==R3.40 and earlier
Field Wireless Device OPC Server
  • ==R2.01.02 and earlier
Ignored packages (4)

pkgs.prmt

Ultra-fast, customizable shell prompt generator

pkgs.hyprmon

TUI monitor configuration tool for Hyprland with visual layout, drag-and-drop, and profile management

Does not apply to anything in nixpkgs
updated 5 months, 1 week ago by @pyrox0 Activity log
  • Created suggestion
  • @pyrox0 dismissed
libbluray MountManager class has a time-of-check time-of-use (TOCTOU) race when …

libbluray MountManager class has a time-of-check time-of-use (TOCTOU) race when expanding JAR files

Affected products

libbluray
  • ==1

Matching in nixpkgs

pkgs.libbluray

Library to access Blu-Ray disks for video playback

Package maintainers

Does not apply to nixpkgs versions