Nixpkgs security tracker

Login with GitHub

Dismissed suggestions

These automatic suggestions were dismissed after initial triaging.

to select a suggestion for revision.

View:
Compact
Detailed
Permalink CVE-2025-47378
7.1 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): None (N)
updated 4 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored package snapdragon-profiler
  • @LeSuisse dismissed
Exposure of Sensitive System Information to an Unauthorized Control Sphere in HLOS

Cryptographic Issue when a shared VM reference allows HLOS to boot loader and access cert chain.

Affected products

Snapdragon
  • ==QAMSRV1H
  • ==WSA8835
  • ==Cologne
  • ==SD865 5G
  • ==SXR2250P
  • ==WCD9385
  • ==QCA6595
  • ==Snapdragon 865+ 5G Mobile Platform
  • ==WCN7861
  • ==WSA8845
  • ==QPA1083BD
  • ==Snapdragon XR2 5G Platform
  • ==XG101002
  • ==WSA8830
  • ==XG101032
  • ==QCA6391
  • ==SAR1250P
  • ==SA8620P
  • ==QXM1096
  • ==Snapdragon AR1+ Gen 1 Platform
  • ==QAM8255P
  • ==X2000077
  • ==FastConnect 6800
  • ==FastConnect 6700
  • ==SRV1H
  • ==X2000094
  • ==QXM1093
  • ==QXM1095
  • ==Snapdragon X55 5G Modem-RF System
  • ==Snapdragon XR2+ Gen 1 Platform
  • ==Snapdragon AR1 Gen 1 Platform
  • ==QPA1086BD
  • ==QXM1083
  • ==LeMansAU
  • ==QXM1086
  • ==WCN7860
  • ==QCA6595AU
  • ==X2000086
  • ==WCD9378C
  • ==X2000092
  • ==FastConnect 7800
  • ==WSA8832
  • ==SA7775P
  • ==FastConnect 6900
  • ==SAR1165P
  • ==XG101039
  • ==SA8255P
  • ==Snapdragon 8 Elite Gen 5
  • ==SXR2230P
  • ==WCN3950
  • ==WSA8840
  • ==X2000090
  • ==QXM1094
  • ==QCA6696
  • ==SAR2130P
  • ==Snapdragon 865 5G Mobile Platform
  • ==SA8770P
  • ==QLN1086BD
  • ==SA9000P
  • ==SRV1M
  • ==WCD9380
  • ==WCD9395
  • ==WSA8810
  • ==WSA8815
  • ==QAMSRV1M
  • ==Pandeiro
  • ==SAR2230P
  • ==Snapdragon 870 5G Mobile Platform
  • ==QCA6797AQ
  • ==QCA6698AQ
  • ==SA7255P
  • ==WSA8845H
  • ==QLN1083BD
  • ==LeMans_AU_LGIT
Ignored packages (1)
Not present in nixpkgs
Permalink CVE-2025-59600
7.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 4 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored package snapdragon-profiler
  • @LeSuisse dismissed
Buffer Over-read in Graphics

Memory Corruption when adding user-supplied data without checking available buffer space.

Affected products

Snapdragon
  • ==QCA8081
  • ==SA8195P
  • ==WSA8845
  • ==Qualcomm Video Collaboration VC5 Platform
  • ==QPA1083BD
  • ==WCN6650
  • ==SM8650Q
  • ==SC8380XP
  • ==Snapdragon 480 5G Mobile Platform
  • ==WCN6755
  • ==SM8750P
  • ==LeMansAU
  • ==QMP1000
  • ==SA4155P
  • ==Snapdragon 662 Mobile Platform
  • ==SA8255P
  • ==SW6100
  • ==QCA6174A
  • ==SM7675
  • ==Snapdragon 6 Gen 3 Mobile Platform
  • ==QLN1086BD
  • ==SA9000P
  • ==QCS4290
  • ==Snapdragon 4 Gen 2 Mobile Platform
  • ==Snapdragon 6 Gen 4 Mobile Platform
  • ==WCD9395
  • ==SAR2230P
  • ==IQ9 Series Platform
  • ==QCA6698AQ
  • ==SA6150P
  • ==SA7255P
  • ==QLN1083BD
  • ==Netrani
  • ==QCN9011
  • ==QCN9012
  • ==Snapdragon 8 Gen 3 Mobile Platform
  • ==CSRA6640
  • ==Themisto
  • ==SXR2350P
  • ==SW5100
  • ==Monaco_IOT
  • ==SA8620P
  • ==QXM1096
  • ==SM6225P
  • ==QAM8255P
  • ==IQ8 Series Platform
  • ==Snapdragon 8 Elite
  • ==SW6100P
  • ==QPA1086BD
  • ==Snapdragon W5+ Gen 1 Wearable Platform
  • ==FastConnect 7800
  • ==WCN6450
  • ==QCM2290
  • ==SAR1165P
  • ==WCN7881
  • ==G1 Gen 1
  • ==Qualcomm Video Collaboration VC1 Platform
  • ==Snapdragon 8 Elite Gen 5
  • ==SA8155P
  • ==Smart Audio 400 Platform
  • ==AR8035
  • ==QCA6696
  • ==QCA2066
  • ==SRV1M
  • ==SA8770P
  • ==WSA8815
  • ==WCD9380
  • ==QCM6125
  • ==Orne
  • ==WSA8845H
  • ==WCD9335
  • ==WCN7860
  • ==Snapdragon 6 Gen 1 Mobile Platform
  • ==LeMans_AU_LGIT
  • ==WSA8835
  • ==WCN3980
  • ==SXR2250P
  • ==WCN3988
  • ==SM8635P
  • ==QCA6595
  • ==WCN7861
  • ==QCN9024
  • ==Palawan25
  • ==SDX61
  • ==SA6155P
  • ==QCM6490
  • ==Snapdragon XR2 5G Platform
  • ==SW5100P
  • ==QCA6391
  • ==SAR1250P
  • ==Snapdragon 460 Mobile Platform
  • ==Milos
  • ==QCS4490
  • ==Snapdragon 480+ 5G Mobile Platform
  • ==Snapdragon 695 5G Mobile Platform
  • ==Snapdragon 685 4G Mobile Platform
  • ==SRV1H
  • ==SM6650P
  • ==WCD9370
  • ==Snapdragon AR1 Gen 1 Platform
  • ==Snapdragon 7s Gen 3 Mobile Platform
  • ==SA6145P
  • ==QCA6574
  • ==QCA6595AU
  • ==QCM4325
  • ==Snapdragon 680 4G Mobile Platform
  • ==CSRA6620
  • ==WSA8832
  • ==FastConnect 6900
  • ==WCN7880
  • ==QCS2290
  • ==SXR2230P
  • ==FastConnect 6200
  • ==QCM5430
  • ==WCN3950
  • ==SAR2130P
  • ==QCA8337
  • ==SA4150P
  • ==QAMSRV1M
  • ==QCS8550
  • ==SXR2330P
  • ==QAMSRV1H
  • ==SD865 5G
  • ==WCN3910
  • ==WCD9385
  • ==QCA6688AQ
  • ==IQ6 Series Platform
  • ==WSA8830
  • ==QCA6574A
  • ==SD662
  • ==SM8635
  • ==WCD9390
  • ==WCD9375
  • ==Snapdragon AR1+ Gen 1 Platform
  • ==SM7435
  • ==WCD9378
  • ==FastConnect 6700
  • ==QXM1093
  • ==QCA6574AU
  • ==QXM1095
  • ==Snapdragon XR2+ Gen 1 Platform
  • ==QXM1083
  • ==QXM1086
  • ==Snapdragon X65 5G Modem-RF System
  • ==MDM9628
  • ==SA7775P
  • ==QCN6024
  • ==QCA6564A
  • ==WSA8840
  • ==QXM1094
  • ==G2 Gen 1
  • ==SM7675P
  • ==SA8145P
  • ==WSA8810
  • ==QCA6564AU
  • ==SM7635P
  • ==Pandeiro
  • ==QCM4490
  • ==Qualcomm Video Collaboration VC3 Platform
  • ==SA8150P
  • ==AR8031
  • ==Snapdragon 4 Gen 1 Mobile Platform
Ignored packages (1)
Not present in nixpkgs
Permalink CVE-2025-47386
7.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 4 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored package snapdragon-profiler
  • @LeSuisse dismissed
Use After Free in Automotive Audio

Memory Corruption while invoking IOCTL calls when concurrent access to shared buffer occurs.

Affected products

Snapdragon
  • ==QCA8081
  • ==SA8195P
  • ==Snapdragon X53 5G Modem-RF System
  • ==QCN6224
  • ==WSA8845
  • ==Qualcomm Video Collaboration VC5 Platform
  • ==WCN6650
  • ==SM8650Q
  • ==Snapdragon 480 5G Mobile Platform
  • ==SM8550P
  • ==MDM9250
  • ==WCN6755
  • ==LeMansAU
  • ==Snapdragon X32 5G Modem-RF System
  • ==SA4155P
  • ==WCD9371
  • ==Snapdragon 662 Mobile Platform
  • ==SA8255P
  • ==WCN3615
  • ==QCA8695AU
  • ==QCA9377
  • ==QFW7124
  • ==QCA6174A
  • ==QRB5165M
  • ==SM7550
  • ==Snapdragon 865 5G Mobile Platform
  • ==SM7675
  • ==SA9000P
  • ==Snapdragon 6 Gen 4 Mobile Platform
  • ==QCS4290
  • ==WCD9395
  • ==QCA6584AU
  • ==Snapdragon 870 5G Mobile Platform
  • ==SA7255P
  • ==QCA6698AQ
  • ==SA6150P
  • ==QCN6274
  • ==QCN9011
  • ==Snapdragon 778G+ 5G Mobile Platform
  • ==QCN9012
  • ==Snapdragon 8 Gen 3 Mobile Platform
  • ==Snapdragon X72 5G Modem-RF System
  • ==CSRA6640
  • ==Snapdragon 778G 5G Mobile Platform
  • ==QCA6678AQ
  • ==SW5100
  • ==Flight RB5 5G Platform
  • ==Snapdragon Auto 5G Modem-RF Gen 2
  • ==SA8620P
  • ==SM6225P
  • ==QAM8255P
  • ==QFW7114
  • ==Snapdragon X55 5G Modem-RF System
  • ==QCA9367
  • ==SM7550P
  • ==QRB5165N
  • ==Snapdragon W5+ Gen 1 Wearable Platform
  • ==FWA Gen 3 Ultra Platform
  • ==FastConnect 7800
  • ==WCN6450
  • ==QCM2290
  • ==G1 Gen 1
  • ==Qualcomm Video Collaboration VC1 Platform
  • ==SA8155P
  • ==Smart Audio 400 Platform
  • ==AR8035
  • ==QCA6696
  • ==QCA2066
  • ==SRV1M
  • ==SA8770P
  • ==WCN3660B
  • ==WSA8815
  • ==WCD9380
  • ==QCM6125
  • ==SA8295P
  • ==Robotics RB2 Platform
  • ==QCA6797AQ
  • ==WSA8845H
  • ==Snapdragon 8 Gen 2 Mobile Platform
  • ==Snapdragon 690 5G Mobile Platform
  • ==WCD9335
  • ==LeMans_AU_LGIT
  • ==WSA8835
  • ==WCN3980
  • ==Snapdragon 7c+ Gen 3 Compute
  • ==WCN3988
  • ==SM8635P
  • ==QCA6595
  • ==Snapdragon 865+ 5G Mobile Platform
  • ==SM7325P
  • ==Snapdragon XR2 5G Platform
  • ==SA6155P
  • ==QCM6490
  • ==SW5100P
  • ==QCA6391
  • ==Snapdragon 460 Mobile Platform
  • ==Milos
  • ==Snapdragon 480+ 5G Mobile Platform
  • ==Snapdragon 695 5G Mobile Platform
  • ==Snapdragon 685 4G Mobile Platform
  • ==SRV1H
  • ==SM6650P
  • ==WCD9326
  • ==WCD9370
  • ==Snapdragon 7s Gen 3 Mobile Platform
  • ==SA6145P
  • ==QCA6574
  • ==QCA6595AU
  • ==Snapdragon X12 LTE Modem
  • ==QCM4325
  • ==QAM8295P
  • ==Snapdragon 680 4G Mobile Platform
  • ==CSRA6620
  • ==WSA8832
  • ==FastConnect 6900
  • ==QCA6698AU
  • ==QCS2290
  • ==FastConnect 6200
  • ==QCM5430
  • ==WCN3950
  • ==Snapdragon 8+ Gen 2 Mobile Platform
  • ==QCA8337
  • ==QEP8111
  • ==SA4150P
  • ==QAMSRV1M
  • ==Robotics RB5 Platform
  • ==QCS8550
  • ==QAMSRV1H
  • ==SD865 5G
  • ==WCN3910
  • ==WCD9385
  • ==QCA6688AQ
  • ==WSA8830
  • ==QCA6574A
  • ==SD662
  • ==SM8635
  • ==WCD9390
  • ==WCD9375
  • ==WCD9378
  • ==FastConnect 6800
  • ==FastConnect 6700
  • ==Snapdragon 782G Mobile Platform
  • ==QCA6574AU
  • ==Snapdragon XR2+ Gen 1 Platform
  • ==Qualcomm 215 Mobile Platform
  • ==MDM9628
  • ==Snapdragon 888+ 5G Mobile Platform
  • ==SA7775P
  • ==SDA660
  • ==WCN3990
  • ==QCA6564A
  • ==Snapdragon X75 5G Modem-RF System
  • ==WSA8840
  • ==WCD9341
  • ==SM7675P
  • ==Snapdragon 660 Mobile Platform
  • ==SA8145P
  • ==WSA8810
  • ==QCA6564AU
  • ==SM7635P
  • ==Snapdragon 888 5G Mobile Platform
  • ==WCD9340
  • ==WCN3680B
  • ==Snapdragon Auto 5G Modem-RF
  • ==Qualcomm Video Collaboration VC3 Platform
  • ==SA8150P
  • ==Snapdragon X35 5G Modem-RF System
  • ==QCC710
  • ==AR8031
  • ==Snapdragon 4 Gen 1 Mobile Platform
Ignored packages (1)
Not present in nixpkgs
Permalink CVE-2026-3400
8.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Exploit Code Maturity (E): Proof-of-Concept (P)
  • Remediation Level (RL): Not Defined (X)
  • Report Confidence (RC): Reasonable (R)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 4 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored package vimPlugins.nvim-treesitter-parsers.regex
  • @LeSuisse dismissed
Tenda AC15 TextEditingConversion stack-based overflow

A security flaw has been discovered in Tenda AC15 up to 15.13.07.13. Affected by this issue is some unknown functionality of the file /goform/TextEditingConversion. The manipulation of the argument wpapsk_crypto2_4g results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.

Affected products

AC15
  • ==15.13.07.4
  • ==15.13.07.10
  • ==15.13.07.2
  • ==15.13.07.1
  • ==15.13.07.3
  • ==15.13.07.11
  • ==15.13.07.8
  • ==15.13.07.7
  • ==15.13.07.0
  • ==15.13.07.9
  • ==15.13.07.6
  • ==15.13.07.5
  • ==15.13.07.13
  • ==15.13.07.12
Ignored packages (1)
Not present in nixpkgs
Permalink CVE-2026-27707
7.3 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): Low (L)
updated 4 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    7 packages
    • overseerr
    • jellyseerr
    • python312Packages.python-overseerr
    • python313Packages.python-overseerr
    • python314Packages.python-overseerr
    • home-assistant-component-tests.overseerr
    • tests.home-assistant-component-tests.overseerr
  • @LeSuisse dismissed
Plex-configured Seerr instances vulnerable to unauthenticated account registration via Jellyfin authentication endpoint

Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Starting in version 2.0.0 and prior to version 3.1.0, an authentication guard logic flaw in `POST /api/v1/auth/jellyfin` allows an unauthenticated attacker to register a new Seerr account on any Plex-configured instance by authenticating with an attacker-controlled Jellyfin server. The attacker receives an authenticated session and can immediately use the application with default permissions, including the ability to submit media requests to Radarr/Sonarr. Any Seerr deployment where all three of the following are true may be vulnerable: `settings.main.mediaServerType` is set to `PLEX` (the most common deployment).; `settings.jellyfin.ip` is set to `""` (default, meaning Jellyfin was never configured); and `settings.main.newPlexLogin` is set to `true` (default). Jellyfin-configured and Emby-configured deployments are not affected. Version 3.1.0 of Seerr fixes this issue.

Affected products

seerr
  • ==>= 2.0.0, < 3.1.0
Ignored packages (7)

pkgs.overseerr

Request management and media discovery tool for the Plex ecosystem

pkgs.jellyseerr

Fork of overseerr for jellyfin support

Not present in nixpkgs
Permalink CVE-2025-12150
3.1 LOW
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
updated 4 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    5 packages
    • terraform-providers.keycloak
    • python312Packages.python-keycloak
    • python313Packages.python-keycloak
    • terraform-providers.keycloak_keycloak
    • python314Packages.python-keycloak
  • @LeSuisse dismissed
Org.keycloak/keycloak-services: webauthn attestation statement verification bypass

A flaw was found in Keycloak’s WebAuthn registration component. This vulnerability allows an attacker to bypass the configured attestation policy and register untrusted or forged authenticators via submission of an attestation object with fmt: "none", even when the realm is configured to require direct attestation. This can lead to weakened authentication integrity and unauthorized authenticator registration.

References

Affected products

keycloak
  • <26.4.4
rhbk/keycloak-rhel9
  • *
rhbk/keycloak-rhel9-operator
  • *
rhbk/keycloak-operator-bundle
  • *
org.keycloak/keycloak-services
Red Hat build of Keycloak 26.2.11

Matching in nixpkgs

pkgs.keycloak

Identity and access management for modern applications and services

Ignored packages (5)

Package maintainers

Not impacted
Permalink CVE-2026-28414
7.5 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
updated 4 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    8 packages
    • pkgsRocm.python3Packages.gradio-client
    • pkgsRocm.python3Packages.gradio-pdf
    • python314Packages.gradio-client
    • python313Packages.gradio-client
    • python312Packages.gradio-client
    • python314Packages.gradio-pdf
    • python312Packages.gradio-pdf
    • python313Packages.gradio-pdf
  • @LeSuisse dismissed
Gradio has Absolute Path Traversal on Windows with Python 3.13+

Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.7, Gradio apps running on Window with Python 3.13+ are vulnerable to an absolute path traversal issue that enables unauthenticated attackers to read arbitrary files from the file system. Python 3.13+ changed the definition of `os.path.isabs` so that root-relative paths like `/windows/win.ini` on Windows are no longer considered absolute paths, resulting in a vulnerability in Gradio's logic for joining paths safely. This can be exploited by unauthenticated attackers to read arbitrary files from the Gradio server, even when Gradio is set up with authentication. Version 6.7 fixes the issue.

Affected products

gradio
  • ==< 6.7

Matching in nixpkgs

Ignored packages (8)

Package maintainers

Windows only
updated 4 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    2 packages
    • malcontent
    • malcontent-ui
  • @LeSuisse dismissed
malcontent's nested archive extraction failure can drop content from scan inputs

malcontent is software for discovering supply-chain compromises through context, differential analysis, and YARA. Prior to version 1.21.0, malcontent would remove nested archives which failed to extract which could potentially leave malicious content. A better approach is to preserve these archives so that malcontent can attempt a best-effort scan of the archive bytes. Version 1.21.0 fixes the issue.

Affected products

malcontent
  • ==< 1.21.0
Ignored packages (2)
Not present in nixpkgs
Permalink CVE-2026-27793
6.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
updated 4 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    7 packages
    • overseerr
    • jellyseerr
    • python312Packages.python-overseerr
    • python313Packages.python-overseerr
    • python314Packages.python-overseerr
    • home-assistant-component-tests.overseerr
    • tests.home-assistant-component-tests.overseerr
  • @LeSuisse dismissed
Seerr has Broken Object-Level Authorization in User Profile Endpoint that Exposes Third-Party Notification Credentials

Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Prior to version 3.1.0, the `GET /api/v1/user/:id` endpoint returns the full settings object for any user, including Pushover, Pushbullet, and Telegram credentials, to any authenticated requester regardless of their privilege level. This vulnerability can be exploited alone or combined with the reported unauthenticated account creation vulnerability, CVE-2026-27707. When combined, the two vulnerabilities create a zero-prior-access chain that leaks third-party API credentials for all users, including administrators. Version 3.1.0 contains a fix for both this vulnerability and for CVE-2026-27707.

Affected products

seerr
  • ==< 3.1.0
Ignored packages (7)

pkgs.overseerr

Request management and media discovery tool for the Plex ecosystem

pkgs.jellyseerr

Fork of overseerr for jellyfin support

Not present in nixpkgs
Permalink CVE-2026-27792
5.4 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
updated 4 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    7 packages
    • overseerr
    • jellyseerr
    • python312Packages.python-overseerr
    • python313Packages.python-overseerr
    • python314Packages.python-overseerr
    • home-assistant-component-tests.overseerr
    • tests.home-assistant-component-tests.overseerr
  • @LeSuisse dismissed
Seerr missing authentication on pushSubscription endpoints

Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. A missing authorization vulnerability has been identified in the application starting in version 2.7.0 and prior to version 3.1.0. It allows authenticated users to access and modify data belonging to other users. This issue is due to the absence of the `isOwnProfileOrAdmin()` middleware on several push subscription API routes. Version 3.1.0 fixes the issue.

Affected products

seerr
  • ==>= 2.7.0, < 3.1.0
Ignored packages (7)

pkgs.overseerr

Request management and media discovery tool for the Plex ecosystem

pkgs.jellyseerr

Fork of overseerr for jellyfin support

Not present in nixpkgs