Nixpkgs security tracker

Login with GitHub

Automatically generated suggestions

to slate a suggestion for refinement.

to mark a suggestion as irrelevant and log the reason.

View:
Compact
Detailed
Permalink CVE-2025-11345
5.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): Low (L)
  • Exploit Code Maturity (E): Not Defined (X)
  • Remediation Level (RL): Official Fix (O)
  • Report Confidence (RC): Confirmed (C)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): Low (L)
created 5 months, 2 weeks ago Activity log
  • Created suggestion

ILIAS Test Import unserialize deserialization


ILIAS
  • ==8.19
  • ==9.10
  • ==9.9
  • ==8.3
  • ==8.14
  • ==8.8
  • ==9.0
  • ==9.5
  • ==9.6
  • ==8.12
  • ==8.18
  • ==8.23
  • ==9.1
  • ==8.15
  • ==9.12
  • ==8.13
  • ==9.3
  • ==8.20
  • ==9.11
  • ==8.6
  • ==8.7
  • ==10.2
  • ==9.7
  • ==8.9
  • ==8.10
  • ==10.1
  • ==9.14
  • ==8.17
  • ==9.13
  • ==9.2
  • ==8.16
  • ==8.4
  • ==8.1
  • ==9.8
  • ==8.0
  • ==9.4
  • ==8.22
  • ==10.0
  • ==8.24
  • ==8.11
  • ==8.5
  • ==8.2
  • ==8.21
created 5 months, 3 weeks ago Activity log
  • Created suggestion

OpenJPEG allows OOB heap memory write in opj_jp2_read_header


openjpeg
  • ==<= 2.5.3
  • ==>= 2.5.1, <= 2.5.3
Permalink CVE-2026-23953
8.7 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Adjacent (A)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Adjacent (A)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): None (N)
updated 5 months, 3 weeks ago by @fricklerhandwerk Activity log
  • Created suggestion
  • @fricklerhandwerk deleted maintainer @jnsgruk maintainer.delete

Incus container environment configuration newline injection


incus
  • ==<= 6.0.5
  • ==>= 6.1.0, <= 6.20.0
Permalink CVE-2025-67620
7.1 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Changed (C)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): Low (L)
created 5 months, 3 weeks ago Activity log
  • Created suggestion

WordPress Anon theme <= 2.2.10 - Reflected Cross Site Scripting (XSS) vulnerability


anon2x
  • =<<= 2.2.10
Permalink CVE-2025-13335
6.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): High (H)
created 5 months, 3 weeks ago Activity log
  • Created suggestion

Loop with Unreachable Exit Condition ('Infinite Loop') in GitLab


GitLab
  • <18.7.2
  • <18.8.2
  • <18.6.4
Permalink CVE-2026-1102
5.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): Low (L)
created 5 months, 3 weeks ago Activity log
  • Created suggestion

Allocation of Resources Without Limits or Throttling in GitLab


GitLab
  • <18.7.2
  • <18.8.2
  • <18.6.4
Permalink CVE-2025-69043
8.2 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
created 5 months, 3 weeks ago Activity log
  • Created suggestion

WordPress Rashy theme <= 1.1.3 - Local File Inclusion vulnerability


rashy
  • =<<= 1.1.3
Permalink CVE-2026-24049
7.1 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 5 months, 3 weeks ago Activity log
  • Created suggestion

wheel Allows Arbitrary File Permission Modification via Path Traversal


wheel
  • ==< 0.46.2
  • ==>= 0.40.0, < 0.46.2
Permalink CVE-2026-0723
7.4 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): None (N)
created 5 months, 3 weeks ago Activity log
  • Created suggestion

Unchecked Return Value in GitLab


GitLab
  • <18.8.2
  • <18.6.4
  • <18.7.2
created 5 months, 3 weeks ago Activity log
  • Created suggestion

Automated Logic WebCTRL and Carrier i-Vu Session Fixation


i-Vu
  • =<9.0
WebCTRL
  • =<9.0