Nixpkgs security tracker

Login with GitHub

Dismissed suggestions

These automatic suggestions were dismissed after initial triaging.

to select a suggestion for revision.

View:
Compact
Detailed
updated 5 months, 1 week ago by @pyrox0 Activity log
  • Created suggestion
  • @LeSuisse ignored package boinctui
  • @pyrox0 dismissed
Multiple SQL injection vulnerabilities in BOINC allow remote attackers to …

Multiple SQL injection vulnerabilities in BOINC allow remote attackers to execute arbitrary SQL commands via unspecified vectors.

References

Affected products

BOINC
  • ==possibly 7.x and earlier

Matching in nixpkgs

pkgs.boinc

Free software for distributed and grid computing

Ignored packages (1)

Package maintainers

Do not apply to nixpkgs versions
Permalink CVE-2026-2650
8.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 5 months, 1 week ago by @pyrox0 Activity log
  • Created suggestion
  • @pyrox0 ignored
    19 packages
    • netflix
    • mkchromecast
    • chrome-export
    • go-chromecast
    • xf86videoopenchrome
    • chrome-token-signing
    • chrome-pak-customizer
    • xf86-video-openchrome
    • xorg.xf86videoopenchrome
    • ocamlPackages.chrome-trace
    • noto-fonts-monochrome-emoji
    • python312Packages.pychromecast
    • python313Packages.pychromecast
    • python314Packages.pychromecast
    • ocamlPackages_latest.chrome-trace
    • python312Packages.undetected-chromedriver
    • python313Packages.undetected-chromedriver
    • python314Packages.undetected-chromedriver
    • grafanaPlugins.ventura-psychrometric-panel
  • @pyrox0 dismissed
Heap buffer overflow in Media in Google Chrome prior to …

Heap buffer overflow in Media in Google Chrome prior to 145.0.7632.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

Affected products

Chrome
  • <145.0.7632.109

Matching in nixpkgs

Ignored packages (19)

pkgs.netflix

Open Netflix in Google Chrome app mode

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small

pkgs.chrome-export

Scripts to save Google Chrome's bookmarks and history as HTML bookmarks files

pkgs.go-chromecast

CLI for Google Chromecast, Home devices and Cast Groups

Package maintainers

Does not apply to nixpkgs versions
updated 5 months, 1 week ago by @pyrox0 Activity log
  • Created suggestion
  • @pyrox0 ignored package vtsls
  • @pyrox0 dismissed
Integer overflow in Trihedral Engineering VTScada (formerly VTS) 6.5 through …

Integer overflow in Trihedral Engineering VTScada (formerly VTS) 6.5 through 9.x before 9.1.20, 10.x before 10.2.22, and 11.x before 11.1.07 allows remote attackers to cause a denial of service (server crash) via a crafted request, which triggers a large memory allocation.

Affected products

VTS
  • <9.1.19
  • <10.2.21
n/a
  • ==n/a
Ignored packages (1)

pkgs.vtsls

LSP wrapper for typescript extension of vscode

Does not apply to nixpkgs
updated 5 months, 1 week ago by @pyrox0 Activity log
  • Created suggestion
  • @pyrox0 dismissed
duplicity 0.6.24 has improper verification of SSL certificates

duplicity 0.6.24 has improper verification of SSL certificates

Affected products

duplicity
  • ==0.6.24

Matching in nixpkgs

pkgs.duplicity

Encrypted bandwidth-efficient backup using the rsync algorithm

Package maintainers

Does not affect current versions
updated 5 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @pyrox0 ignored
    2 packages
    • jboss_mysql_jdbc
    • jboss
  • @pyrox0 accepted
  • @LeSuisse dismissed
A missing permission check was found in The CLI in …

A missing permission check was found in The CLI in JBoss Operations Network before 2.3.1 does not properly check permissions, which allows JBoss ON users to perform management tasks and configuration changes with the privileges of the administrator user.

References

Affected products

JBoss
  • ==2.3.1
Ignored packages (2)
Only affects up to version 2.3.1
updated 5 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @pyrox0 ignored package smiley-sans
  • @pyrox0 accepted
  • @LeSuisse dismissed
Cross-site scripting (XSS) vulnerability in the Smiley module 6.x-1.x versions …

Cross-site scripting (XSS) vulnerability in the Smiley module 6.x-1.x versions prior to 6.x-1.1 and Smileys module 6.x-1.x versions prior to 6.x-1.1 for Drupal allows remote authenticated users with the "administer smiley" permission to inject arbitrary web script or HTML via a smiley acronym.

References

Affected products

Smiley
  • ==6.x-1.x versions prior to 6.x-1.1
Smileys
  • ==6.x-1.x versions prior to 6.x-1.1
Ignored packages (1)

pkgs.smiley-sans

Condensed and oblique Chinese typeface seeking a visual balance between the humanist and the geometric

Does not apply to the font.
updated 5 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    5 packages
    • terraform-providers.keycloak
    • python312Packages.python-keycloak
    • python313Packages.python-keycloak
    • python314Packages.python-keycloak
    • terraform-providers.keycloak_keycloak
  • @LeSuisse dismissed
JBoss KeyCloak is vulnerable to soft token deletion via CSRF

JBoss KeyCloak is vulnerable to soft token deletion via CSRF

References

Affected products

KeyCloak
  • ==Fixed in version 1.1.0-Alpha1

Matching in nixpkgs

pkgs.keycloak

Identity and access management for modern applications and services

Ignored packages (5)

Package maintainers

Current stable branch was never impacted

https://github.com/NixOS/nixpkgs/commit/efc7ecaf9c79f655737104ecabaea761afe81a7b
Permalink CVE-2026-2665
6.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): Low (L)
  • Exploit Code Maturity (E): Proof-of-Concept (P)
  • Remediation Level (RL): Not Defined (X)
  • Report Confidence (RC): Reasonable (R)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): Low (L)
updated 5 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    2 packages
    • python312Packages.firebase-admin
    • python313Packages.firebase-admin
  • @LeSuisse dismissed
huanzi-qch base-admin JSP Parser SysFileController.java upload unrestricted upload

A vulnerability was detected in huanzi-qch base-admin up to 57a8126bb3353a004f3c7722089e3b926ea83596. Impacted is the function Upload of the file SysFileController.java of the component JSP Parser. Performing a manipulation of the argument File results in unrestricted upload. The attack can be initiated remotely. The exploit is now public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.

Affected products

base-admin
  • ==57a8126bb3353a004f3c7722089e3b926ea83596
Ignored packages (2)
Not present in nixpkgs
Permalink CVE-2025-15114
9.8 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 5 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    5 packages
    • flaresolverr
    • tests.arrayUtilities.isDeclaredMap.sameScopeDeclareSingletonMap
    • tests.arrayUtilities.isDeclaredArray.sameScopeDeclareSingletonArray
    • tests.arrayUtilities.isDeclaredMap.previousScopeDeclareSingletonMapFails
    • tests.arrayUtilities.isDeclaredArray.previousScopeDeclareSingletonArrayFails
  • @LeSuisse dismissed
Ksenia Security Lares 4.0 Home Automation 1.6 PIN Exposure Vulnerability

Ksenia Security Lares 4.0 Home Automation version 1.6 contains a critical security flaw that exposes the alarm system PIN in the 'basisInfo' XML file after authentication. Attackers can retrieve the PIN from the server response to bypass security measures and disable the alarm system without additional authentication.

Affected products

lares
  • ==1.0.0.15
  • ==1.6
Ksenia Security Lares 4.0 Home Automation
  • ==1.0.0.15
  • ==1.6
Ignored packages (5)

pkgs.flaresolverr

Proxy server to bypass Cloudflare protection

Not present in nixpkgs
updated 5 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    6 packages
    • python312Packages.openshift
    • python313Packages.openshift
    • python314Packages.openshift
    • python312Packages.azure-mgmt-redhatopenshift
    • python313Packages.azure-mgmt-redhatopenshift
    • python314Packages.azure-mgmt-redhatopenshift
  • @LeSuisse dismissed
Openshift has shell command injection flaws due to unsanitized data …

Openshift has shell command injection flaws due to unsanitized data being passed into shell commands.

References

Affected products

Openshift
  • ==through 2014-04-03

Matching in nixpkgs

Ignored packages (6)

Package maintainers

Current stable branch was never impacted.

https://github.com/NixOS/nixpkgs/commit/ce3dd652234318508da37f8cbc7d69ace7b098ef