Nixpkgs security tracker

Login with GitHub

Automatically generated suggestions

to slate a suggestion for refinement.

to mark a suggestion as irrelevant and log the reason.

View:
Compact
Detailed
created 5 months ago Activity log
  • Created suggestion
pyload-ng: Authentication Bypass via Host Header Injection in ClickNLoad

pyLoad is a free and open-source download manager written in Python. From version 0.4.20 to before version 0.5.0b3.dev97, the local_check decorator in pyLoad's ClickNLoad feature can be bypassed by any remote attacker through HTTP Host header spoofing. This allows unauthenticated remote users to access localhost-restricted endpoints, enabling them to inject arbitrary downloads, write files to the storage directory, and execute JavaScript code. This issue has been patched in version 0.5.0b3.dev97.

Affected products

pyload
  • ==>= 0.4.20, < 0.5.0b3.dev97

Matching in nixpkgs

pkgs.pyload-ng

Free and open-source download manager with support for 1-click-hosting sites

Package maintainers

Permalink CVE-2026-4722
8.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 5 months ago Activity log
  • Created suggestion
Privilege escalation in the IPC component

Privilege escalation in the IPC component. This vulnerability affects Firefox < 149 and Thunderbird < 149.

Affected products

Firefox
  • <149
Thunderbird
  • <149

Matching in nixpkgs

pkgs.faust2firefox

The faust2firefox script, part of faust functional programming language for realtime audio signal processing

  • nixos-unstable -

pkgs.firefox_decrypt

Tool to extract passwords from profiles of Mozilla Firefox and derivates

  • nixos-unstable -
    • nixpkgs-unstable 1.1.3
    • nixos-unstable-small 1.1.3

pkgs.firefox-sync-client

Commandline-utility to list/view/edit/delete entries in a firefox-sync account

  • nixos-unstable -
    • nixpkgs-unstable 1.9.0
    • nixos-unstable-small 1.9.0

pkgs.pkgsRocm.firefoxpwa

Tool to install, manage and use Progressive Web Apps (PWAs) in Mozilla Firefox (native component)

  • nixos-unstable -

pkgs.firefoxpwa-unwrapped

Tool to install, manage and use Progressive Web Apps (PWAs) in Mozilla Firefox (native component)

  • nixos-unstable -

pkgs.gnomeExtensions.firefox-profiles

Easily launch Firefox with your favorite profile right from the indicator menu!

  • nixos-unstable -
    • nixpkgs-unstable 6
    • nixos-unstable-small 6

Package maintainers

created 5 months ago Activity log
  • Created suggestion
league/commonmark has an embed extension allowed_domains bypass

league/commonmark is a PHP Markdown parser. From version 2.3.0 to before version 2.8.2, the DomainFilteringAdapter in the Embed extension is vulnerable to an allowlist bypass due to a missing hostname boundary assertion in the domain-matching regex. An attacker-controlled domain like youtube.com.evil passes the allowlist check when youtube.com is an allowed domain. This issue has been patched in version 2.8.2.

Affected products

commonmark
  • ==>= 2.3.0, < 2.8.2

Matching in nixpkgs

created 5 months ago Activity log
  • Created suggestion
Vikunja has a Link Share Delete IDOR — Missing Project Ownership Check Allows Cross-Project Link Share Deletion

Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, the `DELETE /api/v1/projects/:project/shares/:share` endpoint does not verify that the link share belongs to the project specified in the URL. An attacker with admin access to any project can delete link shares from other projects by providing their own project ID combined with the target share ID. Version 2.2.1 patches the issue.

Affected products

vikunja
  • ==< 2.2.1

Matching in nixpkgs

pkgs.vikunja

Todo-app to organize your life

  • nixos-unstable -
    • nixpkgs-unstable 2.1.0
    • nixos-unstable-small 2.2.0

pkgs.vikunja-desktop

Desktop App of the Vikunja to-do list app

  • nixos-unstable -
    • nixpkgs-unstable 2.1.0
    • nixos-unstable-small 2.2.0

Package maintainers

created 5 months ago Activity log
  • Created suggestion
Heap Buffer Over-Write Vulenrabilty in timeplus-io/proton

Out-of-bounds Write vulnerability in timeplus-io proton (base/poco/Foundation/src‎ modules). This vulnerability is associated with program files inflate.C. This issue affects proton: before 1.6.16.

Affected products

proton
  • <1.6.16

Matching in nixpkgs

pkgs.proton-vpn

Official Proton VPN client

  • nixos-unstable -

pkgs.protonplus

Simple Wine and Proton-based compatibility tools manager

  • nixos-unstable -

pkgs.proton-pass

Desktop application for Proton Pass

  • nixos-unstable -

pkgs.protonup-ng

CLI program and API to automate the installation and update of GloriousEggroll's Proton-GE

  • nixos-unstable -
    • nixpkgs-unstable 0.2.1
    • nixos-unstable-small 0.2.1

pkgs.protonup-qt

Install and manage Proton-GE and Luxtorpeda for Steam and Wine-GE for Lutris with this graphical user interface

  • nixos-unstable -

pkgs.protonup-rs

Rust app to install and update GE-Proton for Steam, and Wine-GE for Lutris

  • nixos-unstable -

pkgs.protontricks

Simple wrapper for running Winetricks commands for Proton-enabled games

  • nixos-unstable -

pkgs.vkd3d-proton

Fork of VKD3D, which aims to implement the full Direct3D 12 API on top of Vulkan

  • nixos-unstable -

pkgs.proton-ge-bin

Compatibility tool for Steam Play based on Wine and additional components. (This is intended for use in the `programs.steam.extraCompatPackages` option only.)

  • nixos-unstable -
    • nixpkgs-unstable 32
    • nixos-unstable-small 33

pkgs.git-protonmail

Git helper to use ProtonMail API to send emails

  • nixos-unstable -
    • nixpkgs-unstable 5.6.2
    • nixos-unstable-small 5.6.2

pkgs.proton-vpn-cli

Official ProtonVPN CLI Linux app

  • nixos-unstable -
    • nixpkgs-unstable 0.1.6
    • nixos-unstable-small 0.1.6

pkgs.proton-pass-cli

Command-line interface for managing your Proton Pass vaults, items, and secrets

  • nixos-unstable -
    • nixpkgs-unstable 1.6.1
    • nixos-unstable-small 1.6.1

pkgs.protonmail-bridge

Use your ProtonMail account with your local e-mail client

  • nixos-unstable -

pkgs.protonmail-export

Export your Proton Mail emails as eml files

  • nixos-unstable -
    • nixpkgs-unstable 1.0.5
    • nixos-unstable-small 1.0.5

pkgs.protonmail-desktop

Desktop application for Mail and Calendar, made with Electron

  • nixos-unstable -

pkgs.protonmail-bridge-gui

Qt-based GUI to use your ProtonMail account with your local e-mail client

  • nixos-unstable -

Package maintainers

created 5 months ago Activity log
  • Created suggestion
Vikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID Connect

Vikunja is an open-source self-hosted task management platform. Starting in version 0.18.0 and prior to version 2.2.1, when a user account is disabled or locked, the status check is only enforced on the local login and JWT token refresh paths. Three other authentication paths — API tokens, CalDAV basic auth, and OpenID Connect — do not verify user status, allowing disabled or locked users to continue accessing the API and syncing data. Version 2.2.1 patches the issue.

Affected products

vikunja
  • ==>= 0.18.0, < 2.2.1

Matching in nixpkgs

pkgs.vikunja

Todo-app to organize your life

  • nixos-unstable -
    • nixpkgs-unstable 2.1.0
    • nixos-unstable-small 2.2.0

pkgs.vikunja-desktop

Desktop App of the Vikunja to-do list app

  • nixos-unstable -
    • nixpkgs-unstable 2.1.0
    • nixos-unstable-small 2.2.0

Package maintainers

created 5 months ago Activity log
  • Created suggestion
Incorrect boundary conditions in the Graphics component

Incorrect boundary conditions in the Graphics component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.

Affected products

Firefox
  • <149
Firefox ESR
  • <140.9
Thunderbird
  • <149
  • <140.9

Matching in nixpkgs

pkgs.faust2firefox

The faust2firefox script, part of faust functional programming language for realtime audio signal processing

  • nixos-unstable -

pkgs.firefox_decrypt

Tool to extract passwords from profiles of Mozilla Firefox and derivates

  • nixos-unstable -
    • nixpkgs-unstable 1.1.3
    • nixos-unstable-small 1.1.3

pkgs.firefox-sync-client

Commandline-utility to list/view/edit/delete entries in a firefox-sync account

  • nixos-unstable -
    • nixpkgs-unstable 1.9.0
    • nixos-unstable-small 1.9.0

pkgs.pkgsRocm.firefoxpwa

Tool to install, manage and use Progressive Web Apps (PWAs) in Mozilla Firefox (native component)

  • nixos-unstable -

pkgs.firefoxpwa-unwrapped

Tool to install, manage and use Progressive Web Apps (PWAs) in Mozilla Firefox (native component)

  • nixos-unstable -

pkgs.gnomeExtensions.firefox-profiles

Easily launch Firefox with your favorite profile right from the indicator menu!

  • nixos-unstable -
    • nixpkgs-unstable 6
    • nixos-unstable-small 6

Package maintainers

Permalink CVE-2026-33679
6.4 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): Low (L)
  • Integrity (I): None (N)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): Low (L)
created 5 months ago Activity log
  • Created suggestion
Vikunja has SSRF via OpenID Connect Avatar Download that Bypasses Webhook SSRF Protections

Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, the `DownloadImage` function in `pkg/utils/avatar.go` uses a bare `http.Client{}` with no SSRF protection when downloading user avatar images from the OpenID Connect `picture` claim URL. An attacker who controls their OIDC profile picture URL can force the Vikunja server to make HTTP GET requests to arbitrary internal or cloud metadata endpoints. This bypasses the SSRF protections that are correctly applied to the webhook system. Version 2.2.1 patches the issue.

Affected products

vikunja
  • ==< 2.2.1

Matching in nixpkgs

pkgs.vikunja

Todo-app to organize your life

  • nixos-unstable -
    • nixpkgs-unstable 2.1.0
    • nixos-unstable-small 2.2.0

pkgs.vikunja-desktop

Desktop App of the Vikunja to-do list app

  • nixos-unstable -
    • nixpkgs-unstable 2.1.0
    • nixos-unstable-small 2.2.0

Package maintainers

created 5 months ago Activity log
  • Created suggestion
Denial-of-service in the WebRTC: Signaling component

Denial-of-service in the WebRTC: Signaling component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.

Affected products

Firefox
  • <149
Firefox ESR
  • <140.9
Thunderbird
  • <140.9
  • <149

Matching in nixpkgs

pkgs.faust2firefox

The faust2firefox script, part of faust functional programming language for realtime audio signal processing

  • nixos-unstable -

pkgs.firefox_decrypt

Tool to extract passwords from profiles of Mozilla Firefox and derivates

  • nixos-unstable -
    • nixpkgs-unstable 1.1.3
    • nixos-unstable-small 1.1.3

pkgs.firefox-sync-client

Commandline-utility to list/view/edit/delete entries in a firefox-sync account

  • nixos-unstable -
    • nixpkgs-unstable 1.9.0
    • nixos-unstable-small 1.9.0

pkgs.pkgsRocm.firefoxpwa

Tool to install, manage and use Progressive Web Apps (PWAs) in Mozilla Firefox (native component)

  • nixos-unstable -

pkgs.firefoxpwa-unwrapped

Tool to install, manage and use Progressive Web Apps (PWAs) in Mozilla Firefox (native component)

  • nixos-unstable -

pkgs.gnomeExtensions.firefox-profiles

Easily launch Firefox with your favorite profile right from the indicator menu!

  • nixos-unstable -
    • nixpkgs-unstable 6
    • nixos-unstable-small 6

Package maintainers

created 5 months ago Activity log
  • Created suggestion
Integer overflow vulnerabilities in InsightSoftwareConsortium/ITK

Integer Overflow or Wraparound vulnerability in InsightSoftwareConsortium ITK (‎Modules/ThirdParty/Expat/src/expat modules).This issue affects ITK: before 2.7.1.

Affected products

ITK
  • <2.7.1

Matching in nixpkgs

pkgs.itk

Insight Segmentation and Registration Toolkit

  • nixos-unstable -
    • nixpkgs-unstable 5.4.5
    • nixos-unstable-small 5.4.5

pkgs.itk_5

Insight Segmentation and Registration Toolkit

  • nixos-unstable -
    • nixpkgs-unstable 5.4.5
    • nixos-unstable-small 5.4.5

pkgs.itk_5_2

Insight Segmentation and Registration Toolkit

  • nixos-unstable -
    • nixpkgs-unstable 5.2.1
    • nixos-unstable-small 5.2.1

pkgs.gitkraken

Simplifying Git for any OS

  • nixos-unstable -

pkgs.simpleitk

Simplified interface to ITK

  • nixos-unstable -
    • nixpkgs-unstable 2.5.3
    • nixos-unstable-small 2.5.3

pkgs.pkgsRocm.itk

Insight Segmentation and Registration Toolkit

  • nixos-unstable -
    • nixpkgs-unstable 5.4.5
    • nixos-unstable-small 5.4.5

pkgs.pkgsRocm.itk_5

Insight Segmentation and Registration Toolkit

  • nixos-unstable -
    • nixpkgs-unstable 5.4.5
    • nixos-unstable-small 5.4.5

pkgs.pkgsRocm.itk_5_2

Insight Segmentation and Registration Toolkit

  • nixos-unstable -
    • nixpkgs-unstable 5.2.1
    • nixos-unstable-small 5.2.1

Package maintainers