Nixpkgs security tracker

Login with GitHub

Automatically generated suggestions

to slate a suggestion for refinement.

to mark a suggestion as irrelevant and log the reason.

View:
Compact
Detailed
Permalink CVE-2026-34378
6.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): High (H)
created 1 month, 2 weeks ago Activity log
  • Created suggestion
OpenEXR has a signed integer overflow in generic_unpack() when parsing EXR files with crafted negative dataWindow.min.x

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.4.0 to before 3.4.9, a missing bounds check on the dataWindow attribute in EXR file headers allows an attacker to trigger a signed integer overflow in generic_unpack(). By setting dataWindow.min.x to a large negative value, OpenEXRCore computes an enormous image width, which is later used in a signed integer multiplication that overflows, causing the process to terminate with SIGILL via UBSan. This vulnerability is fixed in 3.4.9.

Affected products

openexr
  • ==>= 3.4.0, < 3.4.9

Matching in nixpkgs

pkgs.openexr

High dynamic-range (HDR) image file format

Package maintainers

Permalink CVE-2025-47392
8.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Adjacent (A)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Adjacent (A)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 1 month, 2 weeks ago Activity log
  • Created suggestion
Integer Overflow or Wraparound in GPS

Memory corruption when decoding corrupted satellite data files with invalid signature offsets.

Affected products

Snapdragon
  • ==Snapdragon X53 5G Modem-RF System
  • ==FastConnect 6800
  • ==Snapdragon X72 5G Modem-RF System
  • ==Snapdragon X35 5G Modem-RF System
  • ==WCD9335
  • ==WCD9395
  • ==SW5100P
  • ==WSA8815
  • ==Snapdragon 460 Mobile Platform
  • ==Snapdragon 4 Gen 1 Mobile Platform
  • ==WCN7861
  • ==WCN6755
  • ==Snapdragon 865 5G Mobile Platform
  • ==SM7550P
  • ==Milos
  • ==QCS4290
  • ==FSM20055
  • ==SDX61
  • ==SW6100
  • ==WCN3980
  • ==SW5100
  • ==WCD9375
  • ==QCN9012
  • ==QCN9024
  • ==Themisto
  • ==Snapdragon 8 Elite
  • ==SM7435
  • ==Snapdragon X65 5G Modem-RF System
  • ==FastConnect 6200
  • ==WCN7881
  • ==FastConnect 6900
  • ==FWA Gen 3 Ultra Platform
  • ==QCA8081
  • ==Snapdragon 7c+ Gen 3 Compute
  • ==SM7325P
  • ==Snapdragon 7s Gen 3 Mobile Platform
  • ==QCM2290
  • ==WCD9341
  • ==Snapdragon 480 5G Mobile Platform
  • ==Snapdragon X75 5G Modem-RF System
  • ==QMP1000
  • ==QCM5430
  • ==SM8550P
  • ==Snapdragon 888 5G Mobile Platform
  • ==QCA6698AU
  • ==WCD9371
  • ==SM6250
  • ==Orne
  • ==QFW7124
  • ==Snapdragon 685 4G Mobile Platform
  • ==WSA8835
  • ==Netrani
  • ==QCN6274
  • ==QCS8550
  • ==Snapdragon 6 Gen 4 Mobile Platform
  • ==Snapdragon 778G+ 5G Mobile Platform
  • ==Snapdragon 8+ Gen 1 Mobile Platform
  • ==WCN3988
  • ==QCA8337
  • ==SM7635P
  • ==Snapdragon 865+ 5G Mobile Platform
  • ==Snapdragon 690 5G Mobile Platform
  • ==Snapdragon Auto 5G Modem-RF Gen 2
  • ==Palawan25
  • ==FastConnect 6700
  • ==WCN3950
  • ==WSA8832
  • ==QCN9011
  • ==WCD9378
  • ==WSA8845
  • ==QCA6688AQ
  • ==SM6225P
  • ==Robotics RB2 Platform
  • ==Snapdragon 8 Gen 3 Mobile Platform
  • ==WCD9370
  • ==Snapdragon X55 5G Modem-RF System
  • ==Snapdragon 662 Mobile Platform
  • ==WCD9385
  • ==SDX57M
  • ==QCN6024
  • ==SM8635
  • ==QCA6696
  • ==Snapdragon 7+ Gen 2 Mobile Platform
  • ==WCN7860
  • ==Snapdragon X70 Modem-RF System
  • ==Snapdragon X32 5G Modem-RF System
  • ==Snapdragon 7 Gen 1 Mobile Platform
  • ==WSA8810
  • ==SD662
  • ==QCA6595AU
  • ==QCA6797AQ
  • ==SM7675P
  • ==QCA6574A
  • ==Snapdragon 8 Gen 2 Mobile Platform
  • ==SD 8 Gen1 5G
  • ==Snapdragon X80 5G Modem-RF System
  • ==QCN6224
  • ==Snapdragon 4 Gen 2 Mobile Platform
  • ==QFW7114
  • ==QCS2290
  • ==Snapdragon 480+ 5G Mobile Platform
  • ==SW6100P
  • ==WSA8830
  • ==QEP8111
  • ==QCM6490
  • ==WCD9390
  • ==WCN7880
  • ==Snapdragon 8+ Gen 2 Mobile Platform
  • ==Snapdragon 7c Gen 2 Compute Platform "Rennell Pro"
  • ==QCA6174A
  • ==SM8650Q
  • ==SM8635P
  • ==CSRA6620
  • ==G1 Gen 1
  • ==5G Fixed Wireless Access Platform
  • ==AR8035
  • ==SM6650P
  • ==FastConnect 7800
  • ==Snapdragon 778G 5G Mobile Platform
  • ==WCD9360
  • ==WCN6650
  • ==WSA8840
  • ==QCS4490
  • ==Snapdragon 888+ 5G Mobile Platform
  • ==Snapdragon 870 5G Mobile Platform
  • ==Snapdragon Auto 5G Modem-RF
  • ==WCN3910
  • ==Snapdragon W5+ Gen 1 Wearable Platform
  • ==QCC710
  • ==WSA8845H
  • ==SM8475P
  • ==Snapdragon 7c Compute Platform
  • ==Snapdragon 8 Gen 1 Mobile Platform
  • ==WCD9380
  • ==Snapdragon 6 Gen 1 Mobile Platform
  • ==QCA6698AQ
  • ==Snapdragon 680 4G Mobile Platform
  • ==Snapdragon 695 5G Mobile Platform
  • ==SM8750P
  • ==QCM4490
  • ==QCA6574AU
  • ==SM7675
  • ==Qualcomm Video Collaboration VC3 Platform
  • ==FSM200 Platform
  • ==SM7550
  • ==QCM4325
  • ==QCA6584AU
  • ==QCA6678AQ
  • ==CSRA6640
  • ==Snapdragon 6 Gen 3 Mobile Platform
  • ==WCD9340
  • ==QCA6391
  • ==SDX71M
  • ==Snapdragon 782G Mobile Platform

Matching in nixpkgs

created 1 month, 2 weeks ago Activity log
  • Created suggestion
WeGIA - Open Redirect - IsaidaControle - listarId() - Unvalidated $_GET['nextPage']

WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, an Open Redirect vulnerability was identified in the /WeGIA/controle/control.php endpoint of the WeGIA application, specifically through the nextPage parameter when combined with metodo=listarId and nomeClasse=IsaidaControle. The application fails to validate or restrict the nextPage parameter, allowing attackers to redirect users to arbitrary external websites. This can be abused for phishing attacks, credential theft, malware distribution, and social engineering using the trusted WeGIA domain. This vulnerability is fixed in 3.6.9.

Affected products

WeGIA
  • ==< 3.6.9

Matching in nixpkgs

Permalink CVE-2025-47390
7.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 1 month, 2 weeks ago Activity log
  • Created suggestion
Buffer Over-read in Camera

Memory corruption while preprocessing IOCTL request in JPEG driver.

Affected products

Snapdragon
  • ==X2000092
  • ==QCM5430
  • ==X2000090
  • ==FastConnect 7800
  • ==WSA8840
  • ==XG101039
  • ==Snapdragon 8cx Gen 3 Compute Platform
  • ==WSA8835
  • ==XG101032
  • ==X2000094
  • ==WSA8845H
  • ==WCD9380
  • ==FastConnect 6700
  • ==X2000086
  • ==QCA0000
  • ==WSA8845
  • ==WCD9378C
  • ==Qualcomm Video Collaboration VC3 Platform
  • ==WCD9375
  • ==WSA8830
  • ==Cologne
  • ==XG101002
  • ==SC8380XP
  • ==X2000077
  • ==QCM6490
  • ==WCD9370
  • ==FastConnect 6900
  • ==Snapdragon 7c+ Gen 3 Compute
  • ==WCD9385

Matching in nixpkgs

Permalink CVE-2026-29047
7.2 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 1 month, 2 weeks ago Activity log
  • Created suggestion
GLPI has an Authenticated SQL Injection via log exports

GLPI is a free asset and IT management software package. From 10.0.0 to before 10.0.24 and 11.0.6, an authenticated user can perform a SQL injection via the logs export feature. This vulnerability is fixed in 10.0.24 and 11.0.6.

Affected products

glpi
  • ==>= 10.0.0, 10.0.24
  • ==>= 11.0.0-alpha, < 11.0.6

Matching in nixpkgs

pkgs.glpi-agent

GLPI unified Agent for UNIX, Linux, Windows and MacOSX

  • nixos-unstable 1.16
    • nixpkgs-unstable 1.16
    • nixos-unstable-small 1.16
  • nixos-25.11 1.16
    • nixos-25.11-small 1.16
    • nixpkgs-25.11-darwin 1.16

Package maintainers

Permalink CVE-2026-35172
7.5 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
created 1 month, 2 weeks ago Activity log
  • Created suggestion
Distribution has stale blob access resurrection via repo-scoped redis descriptor cache invalidation

Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.0, distribution can restore read access in repo a after an explicit delete when storage.cache.blobdescriptor: redis and storage.delete.enabled: true are both enabled. The delete path clears the shared digest descriptor but leaves stale repo-scoped membership behind, so a later Stat or Get from repo b repopulates the shared descriptor and makes the deleted blob readable from repo a again. This vulnerability is fixed in 3.1.0.

Affected products

distribution
  • ==< 3.1.0

Matching in nixpkgs

pkgs.distribution

Toolkit to pack, ship, store, and deliver container content

Package maintainers

Permalink CVE-2026-34773
4.7 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): High (H)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): None (N)
created 1 month, 2 weeks ago Activity log
  • Created suggestion
Electron: Registry key path injection in app.setAsDefaultProtocolClient on Windows

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.1, and 41.0.0, on Windows, app.setAsDefaultProtocolClient(protocol) did not validate the protocol name before writing to the registry. Apps that pass untrusted input as the protocol name may allow an attacker to write to arbitrary subkeys under HKCU\Software\Classes\, potentially hijacking existing protocol handlers. Apps are only affected if they call app.setAsDefaultProtocolClient() with a protocol name derived from external or untrusted input. Apps that use a hardcoded protocol name are not affected. This issue has been patched in versions 38.8.6, 39.8.1, 40.8.1, and 41.0.0.

Affected products

electron
  • ==>= 41.0.0-alpha.1, < 41.0.0
  • ==>= 40.0.0-alpha.1, < 40.8.1
  • ==>= 39.0.0-alpha.1, < 39.8.1
  • ==< 38.8.6

Matching in nixpkgs

pkgs.electron_36

Cross platform desktop application shell

pkgs.gfn-electron

Linux Desktop client for Nvidia's GeForce NOW game streaming service

pkgs.electron-mail

ElectronMail is an Electron-based unofficial desktop client for ProtonMail

created 1 month, 2 weeks ago Activity log
  • Created suggestion
WeGIA - Open Redirect - backup redirection — Unvalidated $_GET['redirect']

WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, the redirect parameter is taken directly from $_GET with no URL validation or whitelist check, then used verbatim in a header("Location: ...") call. This vulnerability is fixed in 3.6.9.

Affected products

WeGIA
  • ==< 3.6.9

Matching in nixpkgs

Permalink CVE-2026-33540
7.5 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
created 1 month, 2 weeks ago Activity log
  • Created suggestion
Distribution affected by pull-through cache credential exfiltration via www-authenticate bearer realm

Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.0, in pull-through cache mode, distribution discovers token auth endpoints by parsing WWW-Authenticate challenges returned by the configured upstream registry. The realm URL from a bearer challenge is used without validating that it matches the upstream registry host. As a result, an attacker-controlled upstream (or an attacker with MitM position to the upstream) can cause distribution to send the configured upstream credentials via basic auth to an attacker-controlled realm URL. This vulnerability is fixed in 3.1.0.

Affected products

distribution
  • ==< 3.1.0

Matching in nixpkgs

pkgs.distribution

Toolkit to pack, ship, store, and deliver container content

Package maintainers

Permalink CVE-2026-21376
7.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 1 month, 2 weeks ago Activity log
  • Created suggestion
Buffer Over-read in Camera

Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver.

Affected products

Snapdragon
  • ==FastConnect 6800
  • ==X2000092
  • ==QCM5430
  • ==X2000090
  • ==FastConnect 7800
  • ==Snapdragon 8cx Compute Platform "Poipu Pro"
  • ==WSA8815
  • ==Snapdragon 460 Mobile Platform
  • ==WSA8840
  • ==SM6250
  • ==WSA8810
  • ==Snapdragon 8cx Gen 3 Compute Platform
  • ==XG101039
  • ==Snapdragon 8c Compute Platform "Poipu Lite"
  • ==WSA8835
  • ==XG101032
  • ==X2000094
  • ==QCA6420
  • ==WSA8845H
  • ==WCN3988
  • ==Snapdragon 7c Compute Platform
  • ==Snapdragon 8cx Gen 2 5G Compute Platform "Poipu Pro"
  • ==WCD9380
  • ==Snapdragon 8c Compute Platform (SC8180XP-AD) "Poipu Lite"
  • ==FastConnect 6700
  • ==Snapdragon 8cx Compute Platform
  • ==X2000086
  • ==WCN3950
  • ==WSA8832
  • ==QCA0000
  • ==Snapdragon AR1 Gen 1 Platform
  • ==WSA8845
  • ==WCD9378C
  • ==Qualcomm Video Collaboration VC3 Platform
  • ==WCD9375
  • ==WSA8830
  • ==Snapdragon 8cx Gen 2 5G Compute Platform
  • ==Cologne
  • ==QCA6430
  • ==XG101002
  • ==SC8380XP
  • ==WCD9340
  • ==X2000077
  • ==FastConnect 6200
  • ==QCM6490
  • ==FastConnect 6900
  • ==QCA6391
  • ==AQT1000
  • ==Snapdragon 662 Mobile Platform
  • ==Snapdragon 7c+ Gen 3 Compute
  • ==WCD9370
  • ==WCD9385
  • ==Snapdragon 7c Gen 2 Compute Platform "Rennell Pro"
  • ==WCD9341

Matching in nixpkgs