Nixpkgs security tracker

Try the new UI
Login with GitHub

Automatically generated suggestions

to slate a suggestion for refinement.

to mark a suggestion as irrelevant and log the reason.

View:
Compact
Detailed
created 5 days, 3 hours ago Activity log
  • Created suggestion
Incorrect authorization in ORB in Google Chrome prior to 153.0.8010.52 …

Incorrect authorization in ORB in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

Affected products

Chrome
  • <153.0.8010.52

Matching in nixpkgs

pkgs.netflix

Open Netflix in Google Chrome app mode

  • nixos-unstable -
    • nixos-unstable-small
  • nixos-26.05 -
    • nixos-26.05-small

pkgs.mkchromecast

Cast macOS and Linux Audio/Video to your Google Cast and Sonos Devices

pkgs.chrome-export

Scripts to save Google Chrome's bookmarks and history as HTML bookmarks files

  • nixos-unstable -
    • nixos-unstable-small 2.0.2
  • nixos-26.05 -
    • nixos-26.05-small 2.0.2

pkgs.go-chromecast

CLI for Google Chromecast, Home devices and Cast Groups

  • nixos-unstable -
    • nixos-unstable-small 0.3.4
  • nixos-26.05 -
    • nixos-26.05-small 0.3.4

pkgs.xf86videoopenchrome

VIA Technologies UniChrome and Chrome9 IGP video driver for the Xorg X server

  • nixos-unstable -
  • nixos-26.05 -

pkgs.chrome-token-signing

Chrome and Firefox extension for signing with your eID on the web

  • nixos-unstable -
    • nixos-unstable-small 1.1.5
  • nixos-26.05 -
    • nixos-26.05-small 1.1.5

pkgs.electron-chromedriver

WebDriver server for running Selenium tests on Chrome

  • nixos-unstable -
  • nixos-26.05 -

pkgs.xf86-video-openchrome

VIA Technologies UniChrome and Chrome9 IGP video driver for the Xorg X server

  • nixos-unstable -
  • nixos-26.05 -

pkgs.gnomeExtensions.monochrome-toggle

Quick Settings toggle for monochrome, desatured or sepia tinted display. Based on Achroma.

  • nixos-unstable -
    • nixos-unstable-small 1
created 5 days, 3 hours ago Activity log
  • Created suggestion
Use after free in Extensions in Google Chrome prior to …

Use after free in Extensions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: High)

Affected products

Chrome
  • <153.0.8010.52

Matching in nixpkgs

pkgs.netflix

Open Netflix in Google Chrome app mode

  • nixos-unstable -
    • nixos-unstable-small
  • nixos-26.05 -
    • nixos-26.05-small

pkgs.mkchromecast

Cast macOS and Linux Audio/Video to your Google Cast and Sonos Devices

pkgs.chrome-export

Scripts to save Google Chrome's bookmarks and history as HTML bookmarks files

  • nixos-unstable -
    • nixos-unstable-small 2.0.2
  • nixos-26.05 -
    • nixos-26.05-small 2.0.2

pkgs.go-chromecast

CLI for Google Chromecast, Home devices and Cast Groups

  • nixos-unstable -
    • nixos-unstable-small 0.3.4
  • nixos-26.05 -
    • nixos-26.05-small 0.3.4

pkgs.xf86videoopenchrome

VIA Technologies UniChrome and Chrome9 IGP video driver for the Xorg X server

  • nixos-unstable -
  • nixos-26.05 -

pkgs.chrome-token-signing

Chrome and Firefox extension for signing with your eID on the web

  • nixos-unstable -
    • nixos-unstable-small 1.1.5
  • nixos-26.05 -
    • nixos-26.05-small 1.1.5

pkgs.electron-chromedriver

WebDriver server for running Selenium tests on Chrome

  • nixos-unstable -
  • nixos-26.05 -

pkgs.xf86-video-openchrome

VIA Technologies UniChrome and Chrome9 IGP video driver for the Xorg X server

  • nixos-unstable -
  • nixos-26.05 -

pkgs.gnomeExtensions.monochrome-toggle

Quick Settings toggle for monochrome, desatured or sepia tinted display. Based on Achroma.

  • nixos-unstable -
    • nixos-unstable-small 1
Permalink CVE-2026-92839
4.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
created 5 days, 3 hours ago Activity log
  • Created suggestion
Canva Desktop before v1.125.0 performed double decoding in the deeplink …

Canva Desktop before v1.125.0 performed double decoding in the deeplink handler. A threat actor could cause the application to load arbitrary same-origin content under the user’s session.

Affected products

Canva
  • <1.125.0

Matching in nixpkgs

pkgs.goocanvas2

Canvas widget for GTK based on the the Cairo 2D library

  • nixos-unstable -
    • nixos-unstable-small 2.0.4
  • nixos-26.05 -
    • nixos-26.05-small 2.0.4

pkgs.goocanvas3

Canvas widget for GTK based on the the Cairo 2D library

  • nixos-unstable -
    • nixos-unstable-small 3.0.0
  • nixos-26.05 -
    • nixos-26.05-small 3.0.0

pkgs.goocanvas_2

Canvas widget for GTK based on the the Cairo 2D library

  • nixos-unstable -
    • nixos-unstable-small 2.0.4
  • nixos-26.05 -
    • nixos-26.05-small 2.0.4

pkgs.goocanvas_3

Canvas widget for GTK based on the the Cairo 2D library

  • nixos-unstable -
    • nixos-unstable-small 3.0.0
  • nixos-26.05 -
    • nixos-26.05-small 3.0.0

pkgs.goocanvasmm2

C++ bindings for GooCanvas

  • nixos-unstable -
  • nixos-26.05 -

pkgs.perlPackages.GooCanvas2

Perl binding for GooCanvas2 widget using Glib::Object::Introspection

  • nixos-unstable -
    • nixos-unstable-small 0.06
  • nixos-26.05 -
    • nixos-26.05-small 0.06

pkgs.perl5Packages.GooCanvas2

Perl binding for GooCanvas2 widget using Glib::Object::Introspection

  • nixos-unstable -
    • nixos-unstable-small 0.06
  • nixos-26.05 -
    • nixos-26.05-small 0.06
Permalink CVE-2026-92860
9.4 CRITICAL
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): High (H)
  • Vulnerable System Impact Integrity (VI): High (H)
  • Vulnerable System Impact Availability (VA): High (H)
  • Subsequent System Impact Confidentiality (SC): High (H)
  • Subsequent System Impact Integrity (SI): High (H)
  • Subsequent System Impact Availability (SA): High (H)
  • Exploit Maturity (E): Not Defined (X)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): High (H)
  • Modified Vulnerable System Impact Integrity (MVI): High (H)
  • Modified Vulnerable System Impact Availability (MVA): High (H)
  • Modified Subsequent System Impact Confidentiality (MSC): High (H)
  • Modified Subsequent System Impact Integrity (MSI): High (H)
  • Modified Subsequent System Impact Availability (MSA): High (H)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
created 5 days, 3 hours ago Activity log
  • Created suggestion
rcourtman Pulse Quick Security Setup quick-setup fmt.Sprintf input validation

A security flaw has been discovered in rcourtman Pulse up to 6.0.4/6.1.0-rc.4. Affected by this issue is the function fmt.Sprintf of the file /api/security/quick-setup of the component Quick Security Setup Handler. The manipulation of the argument Username results in improper input validation. The attack may be performed from remote. Upgrading the affected component is advised.

Affected products

Pulse
  • ==6.0.0
  • ==6.1.0-rc.4
  • ==6.1.0-rc.1
  • ==6.1.0-rc.2
  • ==6.0.3
  • ==6.0.4
  • ==6.0.1
  • ==6.1.0-rc.3
  • ==6.0.2
  • ==6.1.0-rc.0

Matching in nixpkgs

pkgs.apulse

PulseAudio emulation for ALSA

  • nixos-unstable -
  • nixos-26.05 -

pkgs.pulseaudio

Sound server for POSIX and Win32 systems

  • nixos-unstable -
    • nixos-unstable-small 17.0
  • nixos-26.05 -
    • nixos-26.05-small 17.0

pkgs.pulsemixer

Cli and curses mixer for pulseaudio

  • nixos-unstable -
    • nixos-unstable-small 1.5.1
  • nixos-26.05 -
    • nixos-26.05-small 1.5.1

pkgs.pulsemeeter

Pulseaudio and pipewire audio mixer inspired by voicemeeter

  • nixos-unstable -
    • nixos-unstable-small 2.2.0
  • nixos-26.05 -
    • nixos-26.05-small 2.0.0

pkgs.libpulseaudio

Sound server for POSIX and Win32 systems

  • nixos-unstable -
    • nixos-unstable-small 17.0
  • nixos-26.05 -
    • nixos-26.05-small 17.0

pkgs.pulseaudio-ctl

Control pulseaudio volume from the shell or mapped to keyboard shortcuts. No need for alsa-utils

  • nixos-unstable -
    • nixos-unstable-small 1.70
  • nixos-26.05 -
    • nixos-26.05-small 1.70

pkgs.pulseaudioFull

Sound server for POSIX and Win32 systems

  • nixos-unstable -
    • nixos-unstable-small 17.0
  • nixos-26.05 -
    • nixos-26.05-small 17.0

pkgs.pulseaudio-dlna

Lightweight streaming server which brings DLNA / UPNP and Chromecast support to PulseAudio and Linux

pkgs.pulse-visualizer

Real-time audio visualizer inspired by MiniMeters

  • nixos-unstable -
    • nixos-unstable-small 1.3.9
  • nixos-26.05 -
    • nixos-26.05-small 1.3.9

pkgs.rofi-pulse-select

Rofi-based interface to select source/sink (aka input/output) with PulseAudio

  • nixos-unstable -
    • nixos-unstable-small 0.2.0
  • nixos-26.05 -
    • nixos-26.05-small 0.2.0

pkgs.xfce4-volumed-pulse

Volume keys control daemon for Xfce using pulseaudio

  • nixos-unstable -
    • nixos-unstable-small 0.3.0
  • nixos-26.05 -
    • nixos-26.05-small 0.3.0

pkgs.pulseaudio-module-xrdp

xrdp sink/source pulseaudio modules

  • nixos-unstable -
    • nixos-unstable-small 0.8
  • nixos-26.05 -
    • nixos-26.05-small 0.8

pkgs.xfce4-pulseaudio-plugin

Adjust the audio volume of the PulseAudio sound system

  • nixos-unstable -
    • nixos-unstable-small 0.5.1
  • nixos-26.05 -
    • nixos-26.05-small 0.5.1

pkgs.polybar-pulseaudio-control

Polybar module to control PulseAudio devices, also known as Pavolume

  • nixos-unstable -
    • nixos-unstable-small 3.1.1
  • nixos-26.05 -
    • nixos-26.05-small 3.1.1

pkgs.python313Packages.aiopulse

Python Rollease Acmeda Automate Pulse hub protocol implementation

  • nixos-unstable -
    • nixos-unstable-small 0.4.7
  • nixos-26.05 -
    • nixos-26.05-small 0.4.7

pkgs.python313Packages.libpulse

Asyncio interface to the Pulseaudio and Pipewire pulse library

  • nixos-unstable -
    • nixos-unstable-small 0.7
  • nixos-26.05 -
    • nixos-26.05-small 0.7

pkgs.python314Packages.aiopulse

Python Rollease Acmeda Automate Pulse hub protocol implementation

  • nixos-unstable -
    • nixos-unstable-small 0.4.7
  • nixos-26.05 -
    • nixos-26.05-small 0.4.7

pkgs.python314Packages.libpulse

Asyncio interface to the Pulseaudio and Pipewire pulse library

  • nixos-unstable -
    • nixos-unstable-small 0.7
  • nixos-26.05 -
    • nixos-26.05-small 0.7

Package maintainers

created 5 days, 3 hours ago Activity log
  • Created suggestion
Information leak in Permissions in Google Chrome prior to 153.0.8010.52 …

Information leak in Permissions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

Affected products

Chrome
  • <153.0.8010.52

Matching in nixpkgs

pkgs.netflix

Open Netflix in Google Chrome app mode

  • nixos-unstable -
    • nixos-unstable-small
  • nixos-26.05 -
    • nixos-26.05-small

pkgs.mkchromecast

Cast macOS and Linux Audio/Video to your Google Cast and Sonos Devices

pkgs.chrome-export

Scripts to save Google Chrome's bookmarks and history as HTML bookmarks files

  • nixos-unstable -
    • nixos-unstable-small 2.0.2
  • nixos-26.05 -
    • nixos-26.05-small 2.0.2

pkgs.go-chromecast

CLI for Google Chromecast, Home devices and Cast Groups

  • nixos-unstable -
    • nixos-unstable-small 0.3.4
  • nixos-26.05 -
    • nixos-26.05-small 0.3.4

pkgs.xf86videoopenchrome

VIA Technologies UniChrome and Chrome9 IGP video driver for the Xorg X server

  • nixos-unstable -
  • nixos-26.05 -

pkgs.chrome-token-signing

Chrome and Firefox extension for signing with your eID on the web

  • nixos-unstable -
    • nixos-unstable-small 1.1.5
  • nixos-26.05 -
    • nixos-26.05-small 1.1.5

pkgs.electron-chromedriver

WebDriver server for running Selenium tests on Chrome

  • nixos-unstable -
  • nixos-26.05 -

pkgs.xf86-video-openchrome

VIA Technologies UniChrome and Chrome9 IGP video driver for the Xorg X server

  • nixos-unstable -
  • nixos-26.05 -

pkgs.gnomeExtensions.monochrome-toggle

Quick Settings toggle for monochrome, desatured or sepia tinted display. Based on Achroma.

  • nixos-unstable -
    • nixos-unstable-small 1
created 5 days, 3 hours ago Activity log
  • Created suggestion
Buffer overflow in WebGL in Google Chrome on on Android …

Buffer overflow in WebGL in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

Affected products

Chrome
  • <153.0.8010.52

Matching in nixpkgs

pkgs.netflix

Open Netflix in Google Chrome app mode

  • nixos-unstable -
    • nixos-unstable-small
  • nixos-26.05 -
    • nixos-26.05-small

pkgs.mkchromecast

Cast macOS and Linux Audio/Video to your Google Cast and Sonos Devices

pkgs.chrome-export

Scripts to save Google Chrome's bookmarks and history as HTML bookmarks files

  • nixos-unstable -
    • nixos-unstable-small 2.0.2
  • nixos-26.05 -
    • nixos-26.05-small 2.0.2

pkgs.go-chromecast

CLI for Google Chromecast, Home devices and Cast Groups

  • nixos-unstable -
    • nixos-unstable-small 0.3.4
  • nixos-26.05 -
    • nixos-26.05-small 0.3.4

pkgs.xf86videoopenchrome

VIA Technologies UniChrome and Chrome9 IGP video driver for the Xorg X server

  • nixos-unstable -
  • nixos-26.05 -

pkgs.chrome-token-signing

Chrome and Firefox extension for signing with your eID on the web

  • nixos-unstable -
    • nixos-unstable-small 1.1.5
  • nixos-26.05 -
    • nixos-26.05-small 1.1.5

pkgs.electron-chromedriver

WebDriver server for running Selenium tests on Chrome

  • nixos-unstable -
  • nixos-26.05 -

pkgs.xf86-video-openchrome

VIA Technologies UniChrome and Chrome9 IGP video driver for the Xorg X server

  • nixos-unstable -
  • nixos-26.05 -

pkgs.gnomeExtensions.monochrome-toggle

Quick Settings toggle for monochrome, desatured or sepia tinted display. Based on Achroma.

  • nixos-unstable -
    • nixos-unstable-small 1
created 5 days, 3 hours ago Activity log
  • Created suggestion
Improper state validation in Skia in Google Chrome prior to …

Improper state validation in Skia in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)

Affected products

Chrome
  • <153.0.8010.52

Matching in nixpkgs

pkgs.netflix

Open Netflix in Google Chrome app mode

  • nixos-unstable -
    • nixos-unstable-small
  • nixos-26.05 -
    • nixos-26.05-small

pkgs.mkchromecast

Cast macOS and Linux Audio/Video to your Google Cast and Sonos Devices

pkgs.chrome-export

Scripts to save Google Chrome's bookmarks and history as HTML bookmarks files

  • nixos-unstable -
    • nixos-unstable-small 2.0.2
  • nixos-26.05 -
    • nixos-26.05-small 2.0.2

pkgs.go-chromecast

CLI for Google Chromecast, Home devices and Cast Groups

  • nixos-unstable -
    • nixos-unstable-small 0.3.4
  • nixos-26.05 -
    • nixos-26.05-small 0.3.4

pkgs.xf86videoopenchrome

VIA Technologies UniChrome and Chrome9 IGP video driver for the Xorg X server

  • nixos-unstable -
  • nixos-26.05 -

pkgs.chrome-token-signing

Chrome and Firefox extension for signing with your eID on the web

  • nixos-unstable -
    • nixos-unstable-small 1.1.5
  • nixos-26.05 -
    • nixos-26.05-small 1.1.5

pkgs.electron-chromedriver

WebDriver server for running Selenium tests on Chrome

  • nixos-unstable -
  • nixos-26.05 -

pkgs.xf86-video-openchrome

VIA Technologies UniChrome and Chrome9 IGP video driver for the Xorg X server

  • nixos-unstable -
  • nixos-26.05 -

pkgs.gnomeExtensions.monochrome-toggle

Quick Settings toggle for monochrome, desatured or sepia tinted display. Based on Achroma.

  • nixos-unstable -
    • nixos-unstable-small 1
Permalink CVE-2026-45726
7.6 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Adjacent (A)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): Required (R)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Adjacent (A)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 5 days, 3 hours ago Activity log
  • Created suggestion
Omni: Reader-level users can retrieve imported cluster CA keys via ResourceService

Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. From 1.3.0 until 1.6.6 and 1.7.3, importing a standalone Talos cluster creates an ImportedClusterSecrets resource containing the cluster's complete CA secrets bundle. The access rules in internal/backend/runtime/omni/state_access.go allow an authenticated user with the Reader role to retrieve the resource through ResourceService if the importing actor has not rotated those secrets, exposing Kubernetes, Talos, and etcd CA private keys plus the service-account key. The Kubernetes CA private key permits certificate signing for privileged identities such as system:masters and provides control of the imported cluster outside Omni's authorization boundary, including its workloads, credentials, and secrets. This issue is fixed in versions 1.6.6 and 1.7.3.

Affected products

omni
  • ==>= 1.3.0, < 1.6.6

Matching in nixpkgs

pkgs.omnix

Nix companion to improve developer experience

  • nixos-unstable -
    • nixos-unstable-small 1.3.2
  • nixos-26.05 -
    • nixos-26.05-small 1.3.2

pkgs.omniwm

MacOS Niri and Hyprland inspired tiling window manager

  • nixos-unstable -
    • nixos-unstable-small 0.6.8

pkgs.omnictl

CLI for the Sidero Omni Kubernetes management platform

  • nixos-unstable -
  • nixos-26.05 -
    • nixos-26.05-small 1.7.3

pkgs.omniorb

Robust high performance CORBA ORB for C++ and Python

  • nixos-unstable -
    • nixos-unstable-small 4.3.4
  • nixos-26.05 -
    • nixos-26.05-small 4.3.3

pkgs.sbomnix

Utilities to help with software supply chain challenges on nix targets

  • nixos-unstable -
    • nixos-unstable-small 1.8.0
  • nixos-26.05 -
    • nixos-26.05-small 1.7.6

pkgs.insomnia

Open-source, cross-platform API client for GraphQL, REST, WebSockets, SSE and gRPC, with Cloud, Local and Git storage

  • nixos-unstable -
  • nixos-26.05 -

pkgs.omnissa-horizon-client

Allows you to connect to your Omnissa Horizon virtual desktop

  • nixos-unstable -
    • nixos-unstable-small 2606
  • nixos-26.05 -
    • nixos-26.05-small 2606

pkgs.gnomeExtensions.omnipanel

OmniPanel is a Multi-Monitor advanced window management solution for productivity, featuring configurable zones for windows, smart auto-placement, and automatic tiling.

  • nixos-unstable -
    • nixos-unstable-small 23

pkgs.haskellPackages.omnicodec

Data encoding and decoding command line utilities

  • nixos-unstable -
    • nixos-unstable-small 0.8
  • nixos-26.05 -
    • nixos-26.05-small 0.8
Permalink CVE-2026-54354
8.2 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): Low (L)
created 5 days, 3 hours ago Activity log
  • Created suggestion
MapServer: PostGIS Numeric Filter Value SQL Injection in MapServer Runtime Query Translation

MapServer is a system for developing web-based GIS applications. Prior to 8.6.4, MapServer's PostGIS runtime filter translation in src/mappostgis.cpp and msPostGISLayerTranslateFilter() treats a filteritem as numeric when CONNECTIONTYPE POSTGIS and metadata such as gml_<item>_type=Integer are configured, but it does not verify that attacker-controlled CGI qstring or OGC API Features featureId input is a numeric literal. The unquoted input is concatenated into the generated PostgreSQL/PostGIS predicate, allowing an unauthenticated remote attacker with access to an affected query endpoint to bypass predicates, enumerate unintended records, perform boolean-based or time-based SQL injection, and increase database load. The issue does not by itself establish database modification capabilities. This issue is fixed in version 8.6.4.

Affected products

MapServer
  • ==>= 8.4.0, < 8.6.4

Matching in nixpkgs

pkgs.mapserver

Platform for publishing spatial data and interactive mapping applications to the web

  • nixos-unstable -
    • nixos-unstable-small 8.6.6
  • nixos-26.05 -
    • nixos-26.05-small 8.6.5

Package maintainers

Permalink CVE-2026-45720
7.0 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 5 days, 3 hours ago Activity log
  • Created suggestion
Omni: TOCTOU race condition allows multiple concurrent uses of a single-use SAML session token

Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.6.6 and from 1.7.0 until 1.7.3, SAML.getSession in internal/pkg/auth/interceptor/saml.go checks SAMLAssertion.Used and marks it used in separate state operations. Concurrent requests carrying the same captured saml-session token can each observe the assertion as unused and obtain authentication as the victim before either update is visible. The attacker can invoke SAML-protected gRPC endpoints, use ConfirmPublicKey to create multiple persistent credentials tied to the victim, and generate audit entries attributed to the victim, with the resulting access potentially affecting confidentiality, integrity, and availability according to the victim's privileges. This issue is fixed in versions 1.6.6 and 1.7.3.

Affected products

omni
  • ==< 1.6.6
  • ==>= 1.7.0, < 1.7.3

Matching in nixpkgs

pkgs.omnix

Nix companion to improve developer experience

  • nixos-unstable -
    • nixos-unstable-small 1.3.2
  • nixos-26.05 -
    • nixos-26.05-small 1.3.2

pkgs.omniwm

MacOS Niri and Hyprland inspired tiling window manager

  • nixos-unstable -
    • nixos-unstable-small 0.6.8

pkgs.omnictl

CLI for the Sidero Omni Kubernetes management platform

  • nixos-unstable -
  • nixos-26.05 -
    • nixos-26.05-small 1.7.3

pkgs.omniorb

Robust high performance CORBA ORB for C++ and Python

  • nixos-unstable -
    • nixos-unstable-small 4.3.4
  • nixos-26.05 -
    • nixos-26.05-small 4.3.3

pkgs.sbomnix

Utilities to help with software supply chain challenges on nix targets

  • nixos-unstable -
    • nixos-unstable-small 1.8.0
  • nixos-26.05 -
    • nixos-26.05-small 1.7.6

pkgs.insomnia

Open-source, cross-platform API client for GraphQL, REST, WebSockets, SSE and gRPC, with Cloud, Local and Git storage

  • nixos-unstable -
  • nixos-26.05 -

pkgs.omnissa-horizon-client

Allows you to connect to your Omnissa Horizon virtual desktop

  • nixos-unstable -
    • nixos-unstable-small 2606
  • nixos-26.05 -
    • nixos-26.05-small 2606

pkgs.gnomeExtensions.omnipanel

OmniPanel is a Multi-Monitor advanced window management solution for productivity, featuring configurable zones for windows, smart auto-placement, and automatic tiling.

  • nixos-unstable -
    • nixos-unstable-small 23

pkgs.haskellPackages.omnicodec

Data encoding and decoding command line utilities

  • nixos-unstable -
    • nixos-unstable-small 0.8
  • nixos-26.05 -
    • nixos-26.05-small 0.8