Nixpkgs security tracker

Login with GitHub

Automatically generated suggestions

to slate a suggestion for refinement.

to mark a suggestion as irrelevant and log the reason.

View:
Compact
Detailed
created 5 months, 2 weeks ago Activity log
  • Created suggestion

WatchYourLAN Configuration Page Argument Injection Remote Code Execution Vulnerability


WatchYourLAN
  • ==2.1.2
created 5 months, 2 weeks ago Activity log
  • Created suggestion

Bokeh server applications have Incomplete Origin Validation in WebSockets


bokeh
  • ==< 3.8.2
created 5 months, 2 weeks ago Activity log
  • Created suggestion

email BytesGenerator header injection due to unquoted newlines


CPython
  • <3.13.12
  • <3.14.3
  • <3.15.0a6
  • <3.15.0
created 5 months, 2 weeks ago Activity log
  • Created suggestion

GIMP PSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability


GIMP
  • ==3.0.6
Permalink CVE-2026-1363
9.8 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 5 months, 2 weeks ago Activity log
  • Created suggestion

JNC|IAQS and I6 - Client-Side Enforcement of Server-Side Security


I6
  • ==0
IAQS
  • ==0
Permalink CVE-2026-0710
8.4 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 5 months, 2 weeks ago Activity log
  • Created suggestion

Sipp/sipp: sipp: denial of service and potential arbitrary code execution vulnerability


sipp
  • ==3.7.3
Permalink CVE-2025-11346
6.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): Low (L)
  • Exploit Code Maturity (E): Not Defined (X)
  • Remediation Level (RL): Official Fix (O)
  • Report Confidence (RC): Confirmed (C)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): Low (L)
created 5 months, 2 weeks ago Activity log
  • Created suggestion

ILIAS Base64 Decoding unserialize deserialization


ILIAS
  • ==8.19
  • ==9.9
  • ==8.3
  • ==8.14
  • ==9.6
  • ==8.8
  • ==9.0
  • ==9.5
  • ==9.10
  • ==8.12
  • ==8.18
  • ==8.23
  • ==9.1
  • ==8.15
  • ==8.13
  • ==9.3
  • ==9.12
  • ==8.20
  • ==8.6
  • ==8.7
  • ==9.11
  • ==10.2
  • ==9.7
  • ==8.9
  • ==8.10
  • ==10.1
  • ==9.14
  • ==8.17
  • ==9.13
  • ==9.2
  • ==8.16
  • ==8.4
  • ==8.1
  • ==9.8
  • ==8.0
  • ==9.4
  • ==8.22
  • ==10.0
  • ==8.24
  • ==8.11
  • ==8.5
  • ==8.2
  • ==8.21
Permalink CVE-2025-11344
6.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): Low (L)
  • Exploit Code Maturity (E): Not Defined (X)
  • Remediation Level (RL): Official Fix (O)
  • Report Confidence (RC): Confirmed (C)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): Low (L)
created 5 months, 2 weeks ago Activity log
  • Created suggestion

ILIAS Certificate Import Remote Code Execution


ILIAS
  • ==8.19
  • ==9.9
  • ==8.3
  • ==8.14
  • ==9.6
  • ==8.8
  • ==9.0
  • ==9.5
  • ==9.10
  • ==8.12
  • ==8.18
  • ==8.23
  • ==9.1
  • ==8.15
  • ==8.13
  • ==9.3
  • ==9.12
  • ==8.20
  • ==8.6
  • ==8.7
  • ==9.11
  • ==10.2
  • ==9.7
  • ==8.9
  • ==8.10
  • ==10.1
  • ==9.14
  • ==8.17
  • ==9.13
  • ==9.2
  • ==8.16
  • ==8.4
  • ==8.1
  • ==9.8
  • ==8.0
  • ==9.4
  • ==8.22
  • ==10.0
  • ==8.24
  • ==8.11
  • ==8.5
  • ==8.2
  • ==8.21
Permalink CVE-2026-1364
9.8 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 5 months, 2 weeks ago Activity log
  • Created suggestion

JNC|IAQS and I6 - Missing Authentication


I6
  • ==0
IAQS
  • ==0
created 5 months, 2 weeks ago Activity log
  • Created suggestion

Jans CLI stores plaintext passwords in the local cli_cmd.log file


jans
  • ==< nightly