Nixpkgs Security Tracker

Login with GitHub

Dismissed suggestions

These automatic suggestions were dismissed after initial triaging.

to select a suggestion for revision.

View:
Compact
Detailed
Permalink CVE-2026-3192
5.6 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV):
  • Attack complexity (AC):
  • Privileges required (PR):
  • User interaction (UI):
  • Scope (S):
  • Confidentiality impact (C):
  • Integrity impact (I):
  • Availability impact (A):
updated 2 weeks ago by @mweinelt Activity log
  • Created automatic suggestion
  • @mweinelt removed
    15 packages
    • python312Packages.blockchain
    • python312Packages.python-blockchain-api
    • python313Packages.python-blockchain-api
    • python314Packages.python-blockchain-api
    • haskellPackages.amazonka-managedblockchain
    • python312Packages.mypy-boto3-managedblockchain
    • python313Packages.mypy-boto3-managedblockchain
    • python314Packages.mypy-boto3-managedblockchain
    • python312Packages.mypy-boto3-managedblockchain-query
    • python313Packages.mypy-boto3-managedblockchain-query
    • python314Packages.mypy-boto3-managedblockchain-query
    • python312Packages.types-aiobotocore-managedblockchain
    • python313Packages.types-aiobotocore-managedblockchain
    • python312Packages.types-aiobotocore-managedblockchain-query
    • python313Packages.types-aiobotocore-managedblockchain-query
  • @mweinelt dismissed
Chia Blockchain RPC Credential rpc_server_base.py _authenticate improper authentication

A security vulnerability has been detected in Chia Blockchain 2.1.0. This issue affects the function _authenticate of the file rpc_server_base.py of the component RPC Credential Handler. The manipulation leads to improper authentication. The attack is possible to be carried out remotely. The attack is considered to have high complexity. The exploitability is assessed as difficult. The exploit has been disclosed publicly and may be used. The vendor was informed early via email. A separate report via bugbounty was rejected with the reason "This is by design. The user is responsible for host security".

Affected products

Blockchain
  • ==2.1.0
Ignored packages (15)
Not in nixpkgs
updated 2 weeks ago by @mweinelt Activity log
  • Created automatic suggestion
  • @mweinelt removed package florist
  • @mweinelt dismissed
LORIS media module vulnerable to remote code execution

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. Prior to versions 26.0.5, 27.0.2, and 28.0.0, an authenticated user with sufficient privileges can exploit a path traversal vulnerability to upload a malicious file to an arbitrary location on the server. Once uploaded, the file can be used to achieve remote code execution (RCE). An attacker must be authenticated and have the appropriate permissions to exploit this issue. If the server is configured as read-only, remote code execution (RCE) is not possible; however, the malicious file upload may still be achievable. This problem is fixed in LORIS v26.0.5 and above, v27.0.2 and above, and v28.0.0 and above. As a workaround, LORIS administrators can disable the media module if it is not being used.

Affected products

Loris
  • ==< 26.0.5
  • ==>= 27.0.0, < 27.0.2
Ignored packages (1)

pkgs.florist

Posix Ada Bindings

  • nixos-unstable 24.2
  • nixos-25.11 -
    • nixos-25.11-small
    • nixpkgs-25.11-darwin
Not in nixpkgs
Permalink CVE-2026-3193
3.1 LOW
  • CVSS version: 3.1
  • Attack vector (AV):
  • Attack complexity (AC):
  • Privileges required (PR):
  • User interaction (UI):
  • Scope (S):
  • Confidentiality impact (C):
  • Integrity impact (I):
  • Availability impact (A):
updated 2 weeks ago by @mweinelt Activity log
  • Created automatic suggestion
  • @mweinelt removed
    15 packages
    • python312Packages.blockchain
    • python312Packages.python-blockchain-api
    • python313Packages.python-blockchain-api
    • python314Packages.python-blockchain-api
    • haskellPackages.amazonka-managedblockchain
    • python312Packages.mypy-boto3-managedblockchain
    • python313Packages.mypy-boto3-managedblockchain
    • python314Packages.mypy-boto3-managedblockchain
    • python312Packages.mypy-boto3-managedblockchain-query
    • python313Packages.mypy-boto3-managedblockchain-query
    • python314Packages.mypy-boto3-managedblockchain-query
    • python312Packages.types-aiobotocore-managedblockchain
    • python313Packages.types-aiobotocore-managedblockchain
    • python312Packages.types-aiobotocore-managedblockchain-query
    • python313Packages.types-aiobotocore-managedblockchain-query
  • @mweinelt dismissed
Chia Blockchain send_transaction cross-site request forgery

A vulnerability was detected in Chia Blockchain 2.1.0. Impacted is an unknown function of the file /send_transaction. The manipulation results in cross-site request forgery. The attack may be performed from remote. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit is now public and may be used. The vendor was informed early via email. A separate report via bugbounty was rejected with the reason "This is by design. The user is responsible for host security".

Affected products

Blockchain
  • ==2.1.0
Ignored packages (15)
Not in nixpkgs
Permalink CVE-2026-3194
4.5 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV):
  • Attack complexity (AC):
  • Privileges required (PR):
  • User interaction (UI):
  • Scope (S):
  • Confidentiality impact (C):
  • Integrity impact (I):
  • Availability impact (A):
updated 2 weeks ago by @mweinelt Activity log
  • Created automatic suggestion
  • @mweinelt removed
    15 packages
    • python312Packages.blockchain
    • python312Packages.python-blockchain-api
    • python313Packages.python-blockchain-api
    • python314Packages.python-blockchain-api
    • haskellPackages.amazonka-managedblockchain
    • python312Packages.mypy-boto3-managedblockchain
    • python313Packages.mypy-boto3-managedblockchain
    • python314Packages.mypy-boto3-managedblockchain
    • python312Packages.mypy-boto3-managedblockchain-query
    • python313Packages.mypy-boto3-managedblockchain-query
    • python314Packages.mypy-boto3-managedblockchain-query
    • python312Packages.types-aiobotocore-managedblockchain
    • python313Packages.types-aiobotocore-managedblockchain
    • python312Packages.types-aiobotocore-managedblockchain-query
    • python313Packages.types-aiobotocore-managedblockchain-query
  • @mweinelt dismissed
Chia Blockchain RPC Server Master Passphrase get_private_key missing authentication

A flaw has been found in Chia Blockchain 2.1.0. The affected element is the function send_transaction/get_private_key of the component RPC Server Master Passphrase Handler. This manipulation causes missing authentication. The attack can only be executed locally. The attack's complexity is rated as high. The exploitability is described as difficult. The exploit has been published and may be used. The vendor was informed early via email. A separate report via bugbounty was rejected with the reason "This is by design. The user is responsible for host security".

Affected products

Blockchain
  • ==2.1.0
Ignored packages (15)
Not in nixpkgs
updated 2 weeks ago by @mweinelt Activity log
  • Created automatic suggestion
  • @mweinelt removed
    31 packages
    • netflix
    • chromedriver
    • mkchromecast
    • chrome-export
    • go-chromecast
    • xf86videoopenchrome
    • chrome-token-signing
    • chrome-pak-customizer
    • electron-chromedriver
    • xf86-video-openchrome
    • curl-impersonate-chrome
    • undetected-chromedriver
    • electron-chromedriver_33
    • electron-chromedriver_34
    • electron-chromedriver_35
    • electron-chromedriver_36
    • electron-chromedriver_37
    • electron-chromedriver_38
    • electron-chromedriver_39
    • electron-chromedriver_40
    • xorg.xf86videoopenchrome
    • ocamlPackages.chrome-trace
    • noto-fonts-monochrome-emoji
    • python312Packages.pychromecast
    • python313Packages.pychromecast
    • python314Packages.pychromecast
    • ocamlPackages_latest.chrome-trace
    • python312Packages.undetected-chromedriver
    • python313Packages.undetected-chromedriver
    • python314Packages.undetected-chromedriver
    • grafanaPlugins.ventura-psychrometric-panel
  • @mweinelt dismissed
Inappropriate implementation in V8 in Google Chrome prior to 145.0.7632.159 …

Inappropriate implementation in V8 in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

Affected products

Chrome
  • <145.0.7632.159

Matching in nixpkgs

Ignored packages (31)

pkgs.netflix

Open Netflix in Google Chrome app mode

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small
  • nixos-25.11 -
    • nixos-25.11-small
    • nixpkgs-25.11-darwin

Package maintainers

NixOS unstable: https://github.com/nixos/nixpkgs/pull/496346
NixOS 25.11: https://github.com/NixOS/nixpkgs/pull/496393
updated 2 weeks ago by @mweinelt Activity log
  • Created automatic suggestion
  • @mweinelt removed
    31 packages
    • netflix
    • chromedriver
    • mkchromecast
    • chrome-export
    • go-chromecast
    • xf86videoopenchrome
    • chrome-token-signing
    • chrome-pak-customizer
    • electron-chromedriver
    • xf86-video-openchrome
    • curl-impersonate-chrome
    • undetected-chromedriver
    • electron-chromedriver_33
    • electron-chromedriver_34
    • electron-chromedriver_35
    • electron-chromedriver_36
    • electron-chromedriver_37
    • electron-chromedriver_38
    • electron-chromedriver_39
    • electron-chromedriver_40
    • xorg.xf86videoopenchrome
    • ocamlPackages.chrome-trace
    • noto-fonts-monochrome-emoji
    • python312Packages.pychromecast
    • python313Packages.pychromecast
    • python314Packages.pychromecast
    • ocamlPackages_latest.chrome-trace
    • python312Packages.undetected-chromedriver
    • python313Packages.undetected-chromedriver
    • python314Packages.undetected-chromedriver
    • grafanaPlugins.ventura-psychrometric-panel
  • @mweinelt dismissed
Inappropriate implementation in WebAudio in Google Chrome prior to 145.0.7632.159 …

Inappropriate implementation in WebAudio in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

Affected products

Chrome
  • <145.0.7632.159

Matching in nixpkgs

Ignored packages (31)

pkgs.netflix

Open Netflix in Google Chrome app mode

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small
  • nixos-25.11 -
    • nixos-25.11-small
    • nixpkgs-25.11-darwin

Package maintainers

NixOS unstable: https://github.com/nixos/nixpkgs/pull/496346
NixOS 25.11: https://github.com/NixOS/nixpkgs/pull/496393
updated 2 weeks ago by @mweinelt Activity log
  • Created automatic suggestion
  • @mweinelt removed
    31 packages
    • netflix
    • chromedriver
    • chrome-export
    • go-chromecast
    • mkchromecast
    • xf86videoopenchrome
    • chrome-token-signing
    • chrome-pak-customizer
    • electron-chromedriver
    • xf86-video-openchrome
    • curl-impersonate-chrome
    • undetected-chromedriver
    • electron-chromedriver_33
    • electron-chromedriver_34
    • electron-chromedriver_35
    • electron-chromedriver_36
    • electron-chromedriver_37
    • electron-chromedriver_38
    • electron-chromedriver_39
    • electron-chromedriver_40
    • xorg.xf86videoopenchrome
    • ocamlPackages.chrome-trace
    • noto-fonts-monochrome-emoji
    • python312Packages.pychromecast
    • python313Packages.pychromecast
    • python314Packages.pychromecast
    • ocamlPackages_latest.chrome-trace
    • python312Packages.undetected-chromedriver
    • python313Packages.undetected-chromedriver
    • python314Packages.undetected-chromedriver
    • grafanaPlugins.ventura-psychrometric-panel
  • @mweinelt dismissed
Object lifecycle issue in PowerVR in Google Chrome on Android …

Object lifecycle issue in PowerVR in Google Chrome on Android prior to 145.0.7632.159 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

Affected products

Chrome
  • <145.0.7632.159

Matching in nixpkgs

Ignored packages (31)

pkgs.netflix

Open Netflix in Google Chrome app mode

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small
  • nixos-25.11 -
    • nixos-25.11-small
    • nixpkgs-25.11-darwin

Package maintainers

NixOS unstable: https://github.com/nixos/nixpkgs/pull/496346
NixOS 25.11: https://github.com/NixOS/nixpkgs/pull/496393
updated 2 weeks ago by @mweinelt Activity log
  • Created automatic suggestion
  • @mweinelt removed
    31 packages
    • netflix
    • chromedriver
    • mkchromecast
    • chrome-export
    • go-chromecast
    • xf86videoopenchrome
    • chrome-token-signing
    • chrome-pak-customizer
    • electron-chromedriver
    • xf86-video-openchrome
    • curl-impersonate-chrome
    • undetected-chromedriver
    • electron-chromedriver_33
    • electron-chromedriver_34
    • electron-chromedriver_35
    • electron-chromedriver_36
    • electron-chromedriver_37
    • electron-chromedriver_38
    • electron-chromedriver_39
    • electron-chromedriver_40
    • xorg.xf86videoopenchrome
    • ocamlPackages.chrome-trace
    • noto-fonts-monochrome-emoji
    • python312Packages.pychromecast
    • python313Packages.pychromecast
    • python314Packages.pychromecast
    • ocamlPackages_latest.chrome-trace
    • python312Packages.undetected-chromedriver
    • python313Packages.undetected-chromedriver
    • python314Packages.undetected-chromedriver
    • grafanaPlugins.ventura-psychrometric-panel
  • @mweinelt dismissed
Inappropriate implementation in WebAssembly in Google Chrome prior to 145.0.7632.159 …

Inappropriate implementation in WebAssembly in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

Affected products

Chrome
  • <145.0.7632.159

Matching in nixpkgs

Ignored packages (31)

pkgs.netflix

Open Netflix in Google Chrome app mode

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small
  • nixos-25.11 -
    • nixos-25.11-small
    • nixpkgs-25.11-darwin

Package maintainers

NixOS unstable: https://github.com/nixos/nixpkgs/pull/496346
NixOS 25.11: https://github.com/NixOS/nixpkgs/pull/496393
updated 2 weeks ago by @mweinelt Activity log
  • Created automatic suggestion
  • @mweinelt removed
    31 packages
    • netflix
    • chromedriver
    • mkchromecast
    • chrome-export
    • go-chromecast
    • xf86videoopenchrome
    • chrome-token-signing
    • chrome-pak-customizer
    • electron-chromedriver
    • xf86-video-openchrome
    • curl-impersonate-chrome
    • undetected-chromedriver
    • electron-chromedriver_33
    • electron-chromedriver_34
    • electron-chromedriver_35
    • electron-chromedriver_36
    • electron-chromedriver_37
    • electron-chromedriver_38
    • electron-chromedriver_39
    • electron-chromedriver_40
    • xorg.xf86videoopenchrome
    • ocamlPackages.chrome-trace
    • noto-fonts-monochrome-emoji
    • python312Packages.pychromecast
    • python313Packages.pychromecast
    • python314Packages.pychromecast
    • ocamlPackages_latest.chrome-trace
    • python312Packages.undetected-chromedriver
    • python313Packages.undetected-chromedriver
    • python314Packages.undetected-chromedriver
    • grafanaPlugins.ventura-psychrometric-panel
  • @mweinelt dismissed
Insufficient data validation in Navigation in Google Chrome prior to …

Insufficient data validation in Navigation in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Affected products

Chrome
  • <145.0.7632.159

Matching in nixpkgs

Ignored packages (31)

pkgs.netflix

Open Netflix in Google Chrome app mode

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small
  • nixos-25.11 -
    • nixos-25.11-small
    • nixpkgs-25.11-darwin

Package maintainers

NixOS unstable: https://github.com/nixos/nixpkgs/pull/496346
NixOS 25.11: https://github.com/NixOS/nixpkgs/pull/496393
updated 2 weeks ago by @mweinelt Activity log
  • Created automatic suggestion
  • @mweinelt removed
    31 packages
    • netflix
    • chromedriver
    • mkchromecast
    • chrome-export
    • go-chromecast
    • xf86videoopenchrome
    • chrome-token-signing
    • chrome-pak-customizer
    • electron-chromedriver
    • xf86-video-openchrome
    • curl-impersonate-chrome
    • undetected-chromedriver
    • electron-chromedriver_33
    • electron-chromedriver_34
    • electron-chromedriver_35
    • electron-chromedriver_36
    • electron-chromedriver_37
    • electron-chromedriver_38
    • electron-chromedriver_39
    • electron-chromedriver_40
    • xorg.xf86videoopenchrome
    • ocamlPackages.chrome-trace
    • noto-fonts-monochrome-emoji
    • python312Packages.pychromecast
    • python313Packages.pychromecast
    • python314Packages.pychromecast
    • ocamlPackages_latest.chrome-trace
    • python312Packages.undetected-chromedriver
    • python313Packages.undetected-chromedriver
    • python314Packages.undetected-chromedriver
    • grafanaPlugins.ventura-psychrometric-panel
  • @mweinelt dismissed
Integer overflow in Skia in Google Chrome prior to 145.0.7632.159 …

Integer overflow in Skia in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Critical)

Affected products

Chrome
  • <145.0.7632.159

Matching in nixpkgs

Ignored packages (31)

pkgs.netflix

Open Netflix in Google Chrome app mode

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small
  • nixos-25.11 -
    • nixos-25.11-small
    • nixpkgs-25.11-darwin

Package maintainers

NixOS unstable: https://github.com/nixos/nixpkgs/pull/496346
NixOS 25.11: https://github.com/NixOS/nixpkgs/pull/496393