Nixpkgs Security Tracker

Login with GitHub

Automatically generated suggestions

to slate a suggestion for refinement.

to mark a suggestion as irrelevant and log the reason.

View:
Compact
Detailed
created 1 month ago
Buffer overflow in the Reclaim function in Tianocore EDK2 before …

Buffer overflow in the Reclaim function in Tianocore EDK2 before SVN 16280 allows physically proximate attackers to gain privileges via a long variable name.

References

Affected products

EDK2
  • ==before SVN 16280

Matching in nixpkgs

Package maintainers

Permalink CVE-2026-2661
3.3 LOW
  • CVSS version: 3.1
  • Attack vector (AV):
  • Attack complexity (AC):
  • Privileges required (PR):
  • User interaction (UI):
  • Scope (S):
  • Confidentiality impact (C):
  • Integrity impact (I):
  • Availability impact (A):
created 1 month ago
Squirrel sqobject.h operator heap-based overflow

A security flaw has been discovered in Squirrel up to 3.2. This affects the function SQObjectPtr::operator in the library squirrel/sqobject.h. The manipulation results in heap-based buffer overflow. The attack needs to be approached locally. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

Affected products

Squirrel
  • ==3.0
  • ==3.1
  • ==3.2

Matching in nixpkgs

Package maintainers

created 1 month ago
python-dbusmock arbitrary code execution or file overwrite when templates are loaded from /tmp

python-dbusmock before version 0.15.1 AddTemplate() D-Bus method call or DBusTestCase.spawn_server_template() method could be tricked into executing malicious code if an attacker supplies a .pyc file.

Affected products

python-dbusmock
  • <0.15.1

Matching in nixpkgs

Package maintainers

Permalink CVE-2026-2654
6.3 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV):
  • Attack complexity (AC):
  • Privileges required (PR):
  • User interaction (UI):
  • Scope (S):
  • Confidentiality impact (C):
  • Integrity impact (I):
  • Availability impact (A):
created 1 month ago
huggingface smolagents LocalPythonExecutor requests.post server-side request forgery

A weakness has been identified in huggingface smolagents 1.24.0. Impacted is the function requests.get/requests.post of the component LocalPythonExecutor. Executing a manipulation can lead to server-side request forgery. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

Affected products

smolagents
  • ==1.24.0

Matching in nixpkgs

Package maintainers

created 1 month ago
libnsbmp.c in Libnsbmp 0.1.2 allows context-dependent attackers to cause a …

libnsbmp.c in Libnsbmp 0.1.2 allows context-dependent attackers to cause a denial of service (out-of-bounds read) via a crafted color table to the (1) bmp_decode_rgb or (2) bmp_decode_rle function.

Affected products

Libnsbmp
  • ==0.1.2

Matching in nixpkgs

Package maintainers

created 1 month ago
Hardcoded WSMan credentials in Intelligent Platform Management Interface (IPMI) with …

Hardcoded WSMan credentials in Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before 3.15 (SMT_X9_315) and firmware for Supermicro X8 generation motherboards before SMT X8 312.

References

Affected products

IPMI
  • ==before 3.15 (SMT_X9_315) and before SMT X8 312

Matching in nixpkgs

Package maintainers

created 1 month ago
The CentralNotice extension for MediaWiki before 1.19.9, 1.20.x before 1.20.8, …

The CentralNotice extension for MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 sets the Cache-Control header to cache session cookies when a user is autocreated, which allows remote attackers to authenticate as the created user.

References

Affected products

MediaWiki
  • ==1.20.x before 1.20.8
  • ==1.21.x before 1.21.3
  • ==before 1.19.9

Matching in nixpkgs

Package maintainers

created 1 month ago
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Shaarli allow …

Multiple cross-site scripting (XSS) vulnerabilities in index.php in Shaarli allow remote attackers to inject arbitrary web script or HTML via the URL to the (1) showRSS, (2) showATOM, or (3) showDailyRSS function; a (4) file name to the importFile function; or (5) vectors related to bookmarks.

References

Affected products

Shaarli
  • ==before 53da201749f8f362323ef278bf338f1d9f7a925a

Matching in nixpkgs

Package maintainers

created 1 month ago
File Disclosure in SMF (SimpleMachines Forum) <= 2.0.3: Forum admin …

File Disclosure in SMF (SimpleMachines Forum) <= 2.0.3: Forum admin can read files such as the database config.

Affected products

SMF
  • ==<= 2.0.3

Matching in nixpkgs

pkgs.libsmf

C library for reading and writing Standard MIDI Files

Package maintainers

created 1 month ago
The CentralAuth extension for MediaWiki before 1.19.10, 1.2x before 1.21.4, …

The CentralAuth extension for MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to obtain usernames via vectors related to writing the names to the DOM of a page.

Affected products

MediaWiki
  • ==1.2x before 1.21.4
  • ==1.22.x before 1.22.1
  • ==before 1.19.10

Matching in nixpkgs

Package maintainers