Nixpkgs Security Tracker

Login with GitHub

Automatically generated suggestions

to slate a suggestion for refinement.

to mark a suggestion as irrelevant and log the reason.

View:
Compact
Detailed
Permalink CVE-2024-8373
4.8 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): HIGH
  • Privileges required (PR): NONE
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): NONE
  • Integrity impact (I): LOW
  • Availability impact (A): LOW
created 6 months ago
AngularJS improper sanitization in '<source>' element

Improper sanitization of the value of the [srcset] attribute in <source> HTML elements in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing . This issue affects all versions of AngularJS. Note: The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status .

Affected products

angular
  • ==>=0.0.0
AngularJS
  • *
  • ==>=0.0.0
angular.js
  • *

Matching in nixpkgs

Package maintainers

Permalink CVE-2025-0716
4.8 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): HIGH
  • Privileges required (PR): NONE
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): NONE
  • Integrity impact (I): LOW
  • Availability impact (A): LOW
created 6 months ago
AngularJS improper sanitization in SVG '<image>' element

Improper sanitization of the value of the 'href' and 'xlink:href' attributes in '<image>' SVG elements in AngularJS allows attackers to bypass common image source restrictions. This can lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing  and also negatively affect the application's performance and behavior by using too large or slow-to-load images. This issue affects all versions of AngularJS. Note: The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status .

Affected products

angular
  • ==>=0.0.0
AngularJS
  • ==>=0.0.0

Matching in nixpkgs

Package maintainers

Permalink CVE-2025-5278
4.4 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): REQUIRED
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): NONE
  • Availability impact (A): LOW
created 6 months ago
Coreutils: heap buffer under-read in gnu coreutils sort via key specification

A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a crash or leak sensitive data.

References

Affected products

rhcos
coreutils
  • <9.8

Matching in nixpkgs

pkgs.coreutils

GNU Core Utilities

  • nixos-unstable -

Package maintainers

Permalink CVE-2025-48796
7.3 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): REQUIRED
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): HIGH
created 6 months ago
Gimp: stack-based buffer overflows in file-ico

A flaw was found in GIMP. The GIMP ani_load_image() function is vulnerable to a stack-based overflow. If a user opens.ANI files, GIMP may be used to store more information than the capacity allows. This flaw allows a malicious ANI file to trigger arbitrary code execution.

References

Affected products

gimp
  • <2.99.16
gimp:2.8/gimp

Matching in nixpkgs

pkgs.zigimports

Automatically remove unused imports and globals from Zig files

  • nixos-unstable -

pkgs.gimpPlugins.gmic

GIMP plugin for the G'MIC image processing framework

  • nixos-unstable -

Package maintainers

Permalink CVE-2025-48797
7.3 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): REQUIRED
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): HIGH
created 6 months ago
Gimp: multiple heap buffer overflows in tga parser

A flaw was found in GIMP when processing certain TGA image files. If a user opens one of these image files that has been specially crafted by an attacker, GIMP can be tricked into making serious memory errors, potentially leading to crashes and causing a heap buffer overflow.

References

Affected products

gimp
  • <3.0.0
  • *
gimp:2.8
  • *
gimp:2.8/gimp

Matching in nixpkgs

pkgs.zigimports

Automatically remove unused imports and globals from Zig files

  • nixos-unstable -

pkgs.gimpPlugins.gmic

GIMP plugin for the G'MIC image processing framework

  • nixos-unstable -

Package maintainers

Permalink CVE-2025-48798
7.3 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): REQUIRED
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): HIGH
created 6 months ago
Gimp: multiple use after free in xcf parser

A flaw was found in GIMP when processing XCF image files. If a user opens one of these image files that has been specially crafted by an attacker, GIMP can be tricked into making serious memory errors, potentially leading to crashes and causing use-after-free issues.

References

Affected products

gimp
  • <3.0.0
  • *
gimp:2.8
  • *
gimp:2.8/gimp

Matching in nixpkgs

pkgs.zigimports

Automatically remove unused imports and globals from Zig files

  • nixos-unstable -

pkgs.gimpPlugins.gmic

GIMP plugin for the G'MIC image processing framework

  • nixos-unstable -

Package maintainers

Permalink CVE-2025-5222
7.0 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): HIGH
  • Privileges required (PR): NONE
  • User interaction (UI): REQUIRED
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): HIGH
created 6 months ago
Icu: stack buffer overflow in the srbroot::addtag function

A stack buffer overflow was found in Internationl components for unicode (ICU ). While running the genrb binary, the 'subtag' struct overflowed at the SRBRoot::addTag function. This issue may lead to memory corruption and local arbitrary code execution.

References

Affected products

icu
  • <78.1
  • *
rhcos
mingw-icu

Matching in nixpkgs

pkgs.icu60

Unicode and globalization support library

  • nixos-unstable -

pkgs.icu63

Unicode and globalization support library

  • nixos-unstable -

pkgs.icu64

Unicode and globalization support library

  • nixos-unstable -

pkgs.icu66

Unicode and globalization support library

  • nixos-unstable -

pkgs.icu67

Unicode and globalization support library

  • nixos-unstable -

pkgs.icu69

Unicode and globalization support library

  • nixos-unstable -

pkgs.icu70

Unicode and globalization support library

  • nixos-unstable -

pkgs.icu71

Unicode and globalization support library

  • nixos-unstable -

pkgs.icu72

Unicode and globalization support library

  • nixos-unstable -

pkgs.icu73

Unicode and globalization support library

  • nixos-unstable -

pkgs.icu74

Unicode and globalization support library

  • nixos-unstable -

pkgs.icu75

Unicode and globalization support library

  • nixos-unstable -

pkgs.icu76

Unicode and globalization support library

  • nixos-unstable -

pkgs.icu77

Unicode and globalization support library

  • nixos-unstable -

pkgs.cunicu

Zeroconf peer-to-peer mesh VPN using Wireguard® and Interactive Connectivity Establishment (ICE)

  • nixos-unstable -

pkgs.musicus

Classical music player and organizer

  • nixos-unstable -

pkgs.ploticus

Non-interactive software package for producing plots and charts

  • nixos-unstable -

pkgs.moolticute

GUI app and daemon to work with Mooltipass device via USB

  • nixos-unstable -

pkgs.wikicurses

Simple curses interface for MediaWiki sites such as Wikipedia

  • nixos-unstable -

Package maintainers

Permalink CVE-2025-23394
9.8 CRITICAL
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): HIGH
created 6 months ago
daily-backup.sh script in cyrus-imapd allows escalation from cyrus to root

A UNIX Symbolic Link (Symlink) Following vulnerability in openSUSE Tumbleweed cyrus-imapd allows escalation from cyrus to root.This issue affects openSUSE Tumbleweed cyrus-imapd before 3.8.4-2.1.

Affected products

cyrus-imapd
  • <3.8.4-2.1

Matching in nixpkgs

pkgs.cyrus-imapd

Email, contacts and calendar server

  • nixos-unstable -

Package maintainers

Permalink CVE-2025-46803
5.0 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): REQUIRED
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): NONE
  • Integrity impact (I): HIGH
  • Availability impact (A): NONE
created 6 months ago
Screen creates by default world-writable PTYs

The default mode of pseudo terminals (PTYs) allocated by Screen was changed from 0620 to 0622, thereby allowing anyone to write to any Screen PTYs in the system.

Affected products

screen
  • =<5.0.0

Matching in nixpkgs

pkgs.screen

Window manager that multiplexes a physical terminal

  • nixos-unstable -

pkgs.yascreen

Curses replacement for daemons and embedded apps

  • nixos-unstable -

pkgs.screenkey

Screencast tool to display your keys inspired by Screenflick

  • nixos-unstable -

pkgs.screentest

Simple screen testing tool

  • nixos-unstable -

pkgs.gscreenshot

Screenshot frontend (CLI and GUI) for a variety of screenshot backends

  • nixos-unstable -

pkgs.screen-pipe

Personalized AI powered by what you've seen, said, or heard

  • nixos-unstable -

pkgs.screenfetch

Fetches system/theme information in terminal for Linux desktop screenshots

  • nixos-unstable -

pkgs.screenconfig

Automatic configuration of connected screens/monitors

  • nixos-unstable -

pkgs.screenly-cli

Tools for managing digital signs and screens at scale

  • nixos-unstable -

pkgs.wl-screenrec

High performance wlroots screen recording, featuring hardware encoding

  • nixos-unstable -

pkgs.vokoscreen-ng

User friendly Open Source screencaster for Linux and Windows

  • nixos-unstable -

pkgs.gh-screensaver

gh extension with animated terminal screensavers

  • nixos-unstable -

pkgs.screen-message

Displays a short text fullscreen in an X11 window

  • nixos-unstable -

pkgs.rofi-screenshot

Use rofi to perform various types of screenshots and screen captures

pkgs.betterlockscreen

Fast and sweet looking lockscreen for linux systems with effects

  • nixos-unstable -

pkgs.gnome-screenshot

Utility used in the GNOME desktop environment for taking screenshots

  • nixos-unstable -

pkgs.budgie-screensaver

Fork of old GNOME Screensaver for purposes of providing an authentication prompt on wake

  • nixos-unstable -

pkgs.gpu-screen-recorder

Screen recorder that has minimal impact on system performance by recording a window using the GPU only

  • nixos-unstable -

pkgs.mpd-touch-screen-gui

Small MPD client that let's you view covers and has controls suitable for small touchscreens

pkgs.gnomeExtensions.screen-rotate

Enable screen rotation regardless of touch mode. Fork of Screen Autorotate by Kosmospredanie.

  • nixos-unstable -
    • nixpkgs-unstable 25

pkgs.gnomeExtensions.screenshot-tool

Conveniently create, copy, store and upload screenshots. Please log out and log in again after updating.

  • nixos-unstable -
    • nixpkgs-unstable 76

pkgs.gnomeExtensions.hide-screen-sharing

Hide Screen Sharing. Useful for software KVMs that always show screen sharing like Desk Flow, Input-Leap, Barrier, etc...

  • nixos-unstable -
    • nixpkgs-unstable 1

pkgs.gnomeExtensions.peek-top-bar-on-fullscreen

Show the top bar (panel) on demand while having full screen content on (like a YouTube video). Just hover the mouse cursor to the top of the screen, and the panel will show up. This way, you can quickly check the time, or swich some toggles. This is similar to what macOS offers for full screen apps.

  • nixos-unstable -
    • nixpkgs-unstable 17

pkgs.gnomeExtensions.disable-unredirect-fullscreen-windows

Disables unredirect fullscreen windows in gnome-shell to workaround a bug when clicking on full screen windows goes through to windows underneath. This also happens to fix screen tearing in full-screen windows.

  • nixos-unstable -
    • nixpkgs-unstable 12

Package maintainers

Permalink CVE-2025-46805
5.5 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): NONE
  • Integrity impact (I): NONE
  • Availability impact (A): HIGH
created 6 months ago
Screen has a TOCTOU race potentially allowing to send SIGHUP, SIGCONT to privileged processes when installed setuid-root

Screen version 5.0.0 and older version 4 releases have a TOCTOU race potentially allowing to send SIGHUP, SIGCONT to privileged processes when installed setuid-root.

Affected products

screen
  • =<4.9.1
  • =<5.0.0

Matching in nixpkgs

pkgs.screen

Window manager that multiplexes a physical terminal

  • nixos-unstable -

pkgs.yascreen

Curses replacement for daemons and embedded apps

  • nixos-unstable -

pkgs.screenkey

Screencast tool to display your keys inspired by Screenflick

  • nixos-unstable -

pkgs.screentest

Simple screen testing tool

  • nixos-unstable -

pkgs.gscreenshot

Screenshot frontend (CLI and GUI) for a variety of screenshot backends

  • nixos-unstable -

pkgs.screen-pipe

Personalized AI powered by what you've seen, said, or heard

  • nixos-unstable -

pkgs.screenfetch

Fetches system/theme information in terminal for Linux desktop screenshots

  • nixos-unstable -

pkgs.screenconfig

Automatic configuration of connected screens/monitors

  • nixos-unstable -

pkgs.screenly-cli

Tools for managing digital signs and screens at scale

  • nixos-unstable -

pkgs.wl-screenrec

High performance wlroots screen recording, featuring hardware encoding

  • nixos-unstable -

pkgs.vokoscreen-ng

User friendly Open Source screencaster for Linux and Windows

  • nixos-unstable -

pkgs.gh-screensaver

gh extension with animated terminal screensavers

  • nixos-unstable -

pkgs.screen-message

Displays a short text fullscreen in an X11 window

  • nixos-unstable -

pkgs.rofi-screenshot

Use rofi to perform various types of screenshots and screen captures

pkgs.betterlockscreen

Fast and sweet looking lockscreen for linux systems with effects

  • nixos-unstable -

pkgs.gnome-screenshot

Utility used in the GNOME desktop environment for taking screenshots

  • nixos-unstable -

pkgs.budgie-screensaver

Fork of old GNOME Screensaver for purposes of providing an authentication prompt on wake

  • nixos-unstable -

pkgs.gpu-screen-recorder

Screen recorder that has minimal impact on system performance by recording a window using the GPU only

  • nixos-unstable -

pkgs.mpd-touch-screen-gui

Small MPD client that let's you view covers and has controls suitable for small touchscreens

pkgs.gnomeExtensions.screen-rotate

Enable screen rotation regardless of touch mode. Fork of Screen Autorotate by Kosmospredanie.

  • nixos-unstable -
    • nixpkgs-unstable 25

pkgs.gnomeExtensions.screenshot-tool

Conveniently create, copy, store and upload screenshots. Please log out and log in again after updating.

  • nixos-unstable -
    • nixpkgs-unstable 76

pkgs.gnomeExtensions.hide-screen-sharing

Hide Screen Sharing. Useful for software KVMs that always show screen sharing like Desk Flow, Input-Leap, Barrier, etc...

  • nixos-unstable -
    • nixpkgs-unstable 1

pkgs.gnomeExtensions.peek-top-bar-on-fullscreen

Show the top bar (panel) on demand while having full screen content on (like a YouTube video). Just hover the mouse cursor to the top of the screen, and the panel will show up. This way, you can quickly check the time, or swich some toggles. This is similar to what macOS offers for full screen apps.

  • nixos-unstable -
    • nixpkgs-unstable 17

pkgs.gnomeExtensions.disable-unredirect-fullscreen-windows

Disables unredirect fullscreen windows in gnome-shell to workaround a bug when clicking on full screen windows goes through to windows underneath. This also happens to fix screen tearing in full-screen windows.

  • nixos-unstable -
    • nixpkgs-unstable 12

Package maintainers