Nixpkgs security tracker

Login with GitHub

Dismissed suggestions

These automatic suggestions were dismissed after initial triaging.

to select a suggestion for revision.

View:
Compact
Detailed
Permalink CVE-2026-3975
8.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Exploit Code Maturity (E): Proof-of-Concept (P)
  • Remediation Level (RL): Not Defined (X)
  • Report Confidence (RC): Reasonable (R)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 2 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    35 packages
    • gaw
    • w3m
    • Xaw3d
    • pw3270
    • revpfw3
    • w3m-nox
    • libxaw3d
    • w3m-full
    • sparrow3d
    • w3m-batch
    • libgtkflow3
    • w3m-nographics
    • python312Packages.w3lib
    • python313Packages.w3lib
    • python314Packages.w3lib
    • tests.fetchzip.postFetch
    • perlPackages.W3CLinkChecker
    • perl5Packages.W3CLinkChecker
    • tests.fetchurl.hashedMirrors
    • tests.fetchgit.sparseCheckout
    • perl538Packages.W3CLinkChecker
    • perl540Packages.W3CLinkChecker
    • tests.fetchFromGitHub.leave-git
    • perlPackages.DateTimeFormatW3CDTF
    • ocamlPackages.lablgtk3-sourceview3
    • perl5Packages.DateTimeFormatW3CDTF
    • chickenPackages_5.chickenEggs.glfw3
    • perl538Packages.DateTimeFormatW3CDTF
    • perl540Packages.DateTimeFormatW3CDTF
    • perlPackages.WebServiceValidatorHTMLW3C
    • perl5Packages.WebServiceValidatorHTMLW3C
    • ocamlPackages_latest.lablgtk3-sourceview3
    • perl538Packages.WebServiceValidatorHTMLW3C
    • perl540Packages.WebServiceValidatorHTMLW3C
    • haskellPackages.hs-opentelemetry-propagator-w3c
  • @LeSuisse dismissed
Tenda W3 POST Parameter WifiMacFilterGet formWifiMacFilterGet stack-based overflow

A security flaw has been discovered in Tenda W3 1.0.0.3(2204). This issue affects the function formWifiMacFilterGet of the file /goform/WifiMacFilterGet of the component POST Parameter Handler. Performing a manipulation of the argument wl_radio results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks.

Affected products

W3
  • ==1.0.0.3(2204)
Ignored packages (35)

pkgs.w3m

Text-mode web browser

pkgs.Xaw3d

3D widget set based on the Athena Widget set

pkgs.revpfw3

Reverse proxy to bypass the need for port forwarding

pkgs.libxaw3d

3D appearance variant of the X Athena Widget Set

Not present in nixpkgs
Permalink CVE-2026-3973
8.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Exploit Code Maturity (E): Proof-of-Concept (P)
  • Remediation Level (RL): Not Defined (X)
  • Report Confidence (RC): Reasonable (R)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 2 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    35 packages
    • gaw
    • w3m
    • Xaw3d
    • pw3270
    • revpfw3
    • w3m-nox
    • libxaw3d
    • w3m-full
    • sparrow3d
    • w3m-batch
    • libgtkflow3
    • w3m-nographics
    • python312Packages.w3lib
    • python313Packages.w3lib
    • python314Packages.w3lib
    • tests.fetchzip.postFetch
    • perlPackages.W3CLinkChecker
    • perl5Packages.W3CLinkChecker
    • tests.fetchurl.hashedMirrors
    • tests.fetchgit.sparseCheckout
    • perl538Packages.W3CLinkChecker
    • perl540Packages.W3CLinkChecker
    • tests.fetchFromGitHub.leave-git
    • perlPackages.DateTimeFormatW3CDTF
    • ocamlPackages.lablgtk3-sourceview3
    • perl5Packages.DateTimeFormatW3CDTF
    • chickenPackages_5.chickenEggs.glfw3
    • perl538Packages.DateTimeFormatW3CDTF
    • perl540Packages.DateTimeFormatW3CDTF
    • perlPackages.WebServiceValidatorHTMLW3C
    • perl5Packages.WebServiceValidatorHTMLW3C
    • ocamlPackages_latest.lablgtk3-sourceview3
    • perl538Packages.WebServiceValidatorHTMLW3C
    • perl540Packages.WebServiceValidatorHTMLW3C
    • haskellPackages.hs-opentelemetry-propagator-w3c
  • @LeSuisse dismissed
Tenda W3 POST Parameter setAutoPing formSetAutoPing stack-based overflow

A vulnerability was determined in Tenda W3 1.0.0.3(2204). This affects the function formSetAutoPing of the file /goform/setAutoPing of the component POST Parameter Handler. This manipulation of the argument ping1/ping2 causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.

Affected products

W3
  • ==1.0.0.3(2204)
Ignored packages (35)

pkgs.w3m

Text-mode web browser

pkgs.Xaw3d

3D widget set based on the Athena Widget set

pkgs.revpfw3

Reverse proxy to bypass the need for port forwarding

pkgs.libxaw3d

3D appearance variant of the X Athena Widget Set

Not present in nixpkgs
updated 2 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    9 packages
    • lxd-ui
    • lxd-lts
    • lxd-image-server
    • lxd-unwrapped-lts
    • python312Packages.pylxd
    • python313Packages.pylxd
    • python314Packages.pylxd
    • terraform-providers.lxd
    • terraform-providers.terraform-lxd_lxd
  • @LeSuisse dismissed
Authenticated RCE via unsanitized compression_algorithm

An improper sanitization of the compression_algorithm parameter in Canonical LXD allows an authenticated, unprivileged user to execute commands as the LXD daemon on the LXD server via API calls to the image and backup endpoints. This issue affected LXD from 4.12 through 6.6 and was fixed in the snap versions 5.0.6-e49d9f4 (channel 5.0/stable), 5.21.4-1374f39 (channel 5.21/stable), and 6.7-1f11451 (channel 6.0 stable). The channel 4.0/stable is not affected as it contains version 4.0.10.

Affected products

lxd
  • <6.7
  • <5.21.4
  • ==4.12
  • <5.0.6
Ignored packages (9)

pkgs.lxd-ui

Web user interface for LXD

pkgs.lxd-lts

Daemon based on liblxc offering a REST API to manage containers

pkgs.lxd-image-server

Creates and manages a simplestreams lxd image server on top of nginx

pkgs.lxd-unwrapped-lts

Daemon based on liblxc offering a REST API to manage containers

Not present in nixpkgs
Permalink CVE-2026-32442
4.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
updated 2 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored package haskellPackages.line2pdf
  • @LeSuisse dismissed
WordPress e2pdf plugin <= 1.28.15 - Broken Access Control vulnerability

Missing Authorization vulnerability in E2Pdf e2pdf e2pdf allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects e2pdf: from n/a through <= 1.28.15.

Affected products

e2pdf
  • =<<= 1.28.15
Ignored packages (1)
Not present in nixpkgs
updated 2 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    8 packages
    • python312Packages.vertica-python
    • python313Packages.vertica-python
    • python314Packages.vertica-python
    • gnomeExtensions.vertical-app-grid
    • gnomeExtensions.vertical-workspaces
    • gnomeExtensions.vertical-window-list
    • obs-studio-plugins.obs-vertical-canvas
    • kakounePlugins.kakoune-vertical-selection
  • @LeSuisse dismissed
Improper neutralization of input during web page generation vulnerability has been discovered in OpenText™ Vertica.

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText™ Vertica allows Reflected XSS.  The vulnerability could lead to Reflected XSS attack of cross-site scripting in Vertica management console application.This issue affects Vertica: from 10.0 through 10.X, from 11.0 through 11.X, from 12.0 through 12.X, from 23.0 through 23.X, from 24.0 through 24.X, from 25.1.0 through 25.1.X, from 25.2.0 through 25.2.X, from 25.3.0 through 25.3.X.

Affected products

Vertica
  • =<25.1.x
  • =<25.3.x
  • =<24.x
  • =<12.x
  • =<10.x
  • =<23.x
  • =<11.x
  • =<25.2.x
Ignored packages (8)

pkgs.gnomeExtensions.vertical-workspaces

V-Shell is designed to enhance and customize the user experience by providing flexible workspace orientations and a variety of interface adjustments, including application grid customization and productivity improvements.

  • nixos-unstable 108
    • nixpkgs-unstable 108
    • nixos-unstable-small 108
  • nixos-25.11 100
    • nixos-25.11-small 100
    • nixpkgs-25.11-darwin 100
Not present in nixpkgs
Permalink CVE-2026-32458
7.6 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): Low (L)
updated 2 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    20 packages
    • ecwolf
    • wolfssl
    • direwolf
    • wolfebin
    • wolf-shaper
    • wolfram-engine
    • wolfram-notebook
    • wolfstoneextract
    • direwolf-unstable
    • pkgsRocm.librewolf
    • librewolf-unwrapped
    • python312Packages.aardwolf
    • python313Packages.aardwolf
    • python314Packages.aardwolf
    • python312Packages.wolf-comm
    • python313Packages.wolf-comm
    • python314Packages.wolf-comm
    • pkgsRocm.librewolf-unwrapped
    • home-assistant-component-tests.wolflink
    • tests.home-assistant-component-tests.wolflink
  • @LeSuisse dismissed
WordPress WOLF plugin <= 1.0.8.7 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 WOLF bulk-editor allows Blind SQL Injection.This issue affects WOLF: from n/a through <= 1.0.8.7.

Affected products

bulk-editor
  • =<<= 1.0.8.7
Ignored packages (20)

pkgs.ecwolf

Enhanched SDL-based port of Wolfenstein 3D for various platforms

pkgs.wolfssl

Small, fast, portable implementation of TLS/SSL for embedded devices

pkgs.direwolf

Soundcard Packet TNC, APRS Digipeater, IGate, APRStt gateway

pkgs.wolfebin

Quick and easy file sharing

  • nixos-unstable 5.6
    • nixpkgs-unstable 5.6
    • nixos-unstable-small 5.6
  • nixos-25.11 5.6
    • nixos-25.11-small 5.6
    • nixpkgs-25.11-darwin 5.6

pkgs.wolf-shaper

Waveshaper plugin with spline-based graph editor

pkgs.wolfram-notebook

None

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small
  • nixos-25.11 -
    • nixos-25.11-small
    • nixpkgs-25.11-darwin

pkgs.wolfstoneextract

Utility to extract Wolfstone data from Wolfenstein II

  • nixos-unstable 1.2
    • nixpkgs-unstable 1.2
    • nixos-unstable-small 1.2
  • nixos-25.11 1.2
    • nixos-25.11-small 1.2
    • nixpkgs-25.11-darwin 1.2
Not present in nixpkgs
Permalink CVE-2026-32616
8.2 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
updated 2 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    4 packages
    • dovecot_pigeonhole
    • gnomeExtensions.pigeon-email-notifier
    • chickenPackages_5.chickenEggs.pigeon-hole
    • pigeon
  • @LeSuisse dismissed
Pigeon has a Host Header Injection in email verification flow

Pigeon is a message board/notepad/social system/blog. Prior to 1.0.201, the application uses $_SERVER['HTTP_HOST'] without validation to construct email verification URLs in the register and resendmail flows. An attacker can manipulate the Host header in the HTTP request, causing the verification link sent to the user's email to point to an attacker-controlled domain. This can lead to account takeover by stealing the email verification token. This vulnerability is fixed in 1.0.201.

Affected products

Pigeon
  • ==< 1.0.201
Ignored packages (4)

pkgs.pigeon

PEG parser generator for Go

Not present in nixpkgs
updated 2 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    11 packages
    • monitoring-plugins
    • perlPackages.MonitoringPlugin
    • perl5Packages.MonitoringPlugin
    • haskellPackages.gogol-monitoring
    • perl538Packages.MonitoringPlugin
    • perl540Packages.MonitoringPlugin
    • python312Packages.google-cloud-monitoring
    • python313Packages.google-cloud-monitoring
    • python314Packages.google-cloud-monitoring
    • home-assistant-component-tests.victron_remote_monitoring
    • tests.home-assistant-component-tests.victron_remote_monitoring
  • @LeSuisse dismissed
Improper Access Control in github.com/ctfer-io/monitoring

The CTFer.io Monitoring component is in charge of the collection, process and storage of various signals (i.e. logs, metrics and distributed traces). Prior to 0.2.1, due to a mis-written NetworkPolicy, a malicious actor can pivot from a component to any other namespace. This breaks the security-by-default property expected as part of the deployment program, leading to a potential lateral movement. This vulnerability is fixed in 0.2.1.

Affected products

monitoring
  • ==< 0.2.1
Ignored packages (11)

pkgs.perlPackages.MonitoringPlugin

A family of perl modules to streamline writing Naemon, Nagios, Icinga or Shinken (and compatible) plugins

  • nixos-unstable 0.40
    • nixpkgs-unstable 0.40
    • nixos-unstable-small 0.40
  • nixos-25.11 0.40
    • nixos-25.11-small 0.40
    • nixpkgs-25.11-darwin 0.40

pkgs.perl5Packages.MonitoringPlugin

A family of perl modules to streamline writing Naemon, Nagios, Icinga or Shinken (and compatible) plugins

  • nixos-unstable 0.40
    • nixpkgs-unstable 0.40
    • nixos-unstable-small 0.40
Not present in nixpkgs
Permalink CVE-2026-32630
5.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): Low (L)
updated 2 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    4 packages
    • perlPackages.FileType
    • perl5Packages.FileType
    • perl538Packages.FileType
    • perl540Packages.FileType
  • @LeSuisse dismissed
file-type affected by ZIP Decompression Bomb DoS via [Content_Types].xml entry

file-type detects the file type of a file, stream, or data. From 20.0.0 to 21.3.1, a crafted ZIP file can trigger excessive memory growth during type detection in file-type when using fileTypeFromBuffer(), fileTypeFromBlob(), or fileTypeFromFile(). The ZIP inflate output limit is enforced for stream-based detection, but not for known-size inputs. As a result, a small compressed ZIP can cause file-type to inflate and process a much larger payload while probing ZIP-based formats such as OOXML. This vulnerability is fixed in 21.3.2.

Affected products

file-type
  • ==>= 20.0.0, < 21.3.2
Ignored packages (4)

pkgs.perlPackages.FileType

Uses magic numbers (typically at the start of a file) to determine the MIME type of that file

  • nixos-unstable 0.22
    • nixpkgs-unstable 0.22
    • nixos-unstable-small 0.22
  • nixos-25.11 0.22
    • nixos-25.11-small 0.22
    • nixpkgs-25.11-darwin 0.22

pkgs.perl5Packages.FileType

Uses magic numbers (typically at the start of a file) to determine the MIME type of that file

  • nixos-unstable 0.22
    • nixpkgs-unstable 0.22
    • nixos-unstable-small 0.22

pkgs.perl538Packages.FileType

Uses magic numbers (typically at the start of a file) to determine the MIME type of that file

  • nixos-25.11 0.22
    • nixos-25.11-small 0.22
    • nixpkgs-25.11-darwin 0.22

pkgs.perl540Packages.FileType

Uses magic numbers (typically at the start of a file) to determine the MIME type of that file

  • nixos-25.11 0.22
    • nixos-25.11-small 0.22
    • nixpkgs-25.11-darwin 0.22
Not directly present in nixpkgs
updated 2 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    8 packages
    • python312Packages.vertica-python
    • python313Packages.vertica-python
    • python314Packages.vertica-python
    • gnomeExtensions.vertical-app-grid
    • gnomeExtensions.vertical-workspaces
    • gnomeExtensions.vertical-window-list
    • obs-studio-plugins.obs-vertical-canvas
    • kakounePlugins.kakoune-vertical-selection
  • @LeSuisse dismissed
Improper neutralization of input during web page generation vulnerability has been discovered in OpenText™ Vertica.

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText™ Vertica allows Reflected XSS.  The vulnerability could lead to Reflected XSS attack of cross-site scripting in Vertica management console application.This issue affects Vertica: from 10.0 through 10.X, from 11.0 through 11.X, from 12.0 through 12.X, from 23.0 through 23.X, from 24.0 through 24.X, from 25.1.0 through 25.1.X.

Affected products

Vertica
  • =<25.1.x
  • =<24.x
  • =<12.x
  • =<10.x
  • =<23.x
  • =<11.x
Ignored packages (8)

pkgs.gnomeExtensions.vertical-workspaces

V-Shell is designed to enhance and customize the user experience by providing flexible workspace orientations and a variety of interface adjustments, including application grid customization and productivity improvements.

  • nixos-unstable 108
    • nixpkgs-unstable 108
    • nixos-unstable-small 108
  • nixos-25.11 100
    • nixos-25.11-small 100
    • nixpkgs-25.11-darwin 100
Not present in nixpkgs