Nixpkgs Security Tracker

Login with GitHub

Automatically generated suggestions

to slate a suggestion for refinement.

to mark a suggestion as irrelevant and log the reason.

View:
Compact
Detailed
Permalink CVE-2026-2649
8.8 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): REQUIRED
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): HIGH
created 1 month ago
Integer overflow in V8 in Google Chrome prior to 145.0.7632.109 …

Integer overflow in V8 in Google Chrome prior to 145.0.7632.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

Affected products

Chrome
  • <145.0.7632.109

Matching in nixpkgs

pkgs.netflix

Open Netflix in Google Chrome app mode

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small
  • nixos-25.11 -
    • nixos-25.11-small
    • nixpkgs-25.11-darwin
created 1 month ago
The plural form formula in ngettext family of calls in …

The plural form formula in ngettext family of calls in php-gettext before 1.0.12 allows remote attackers to execute arbitrary code.

References

Affected products

php-gettext
  • ==before 1.0.12

Matching in nixpkgs

Package maintainers

created 1 month ago
SQL injection vulnerability in Dolibarr ERP/CRM 3.3.1 allows remote attackers …

SQL injection vulnerability in Dolibarr ERP/CRM 3.3.1 allows remote attackers to execute arbitrary SQL commands via the 'pays' parameter in fiche.php.

Affected products

dolibarr
  • ==3.3.1

Matching in nixpkgs

Package maintainers

created 1 month ago
Qemu before 2.0 block driver for Hyper-V VHDX Images is …

Qemu before 2.0 block driver for Hyper-V VHDX Images is vulnerable to infinite loops and other potential issues when calculating BAT entries, due to missing bounds checks for block_size and logical_sector_size variables. These are used to derive other fields like 'sectors_per_block' etc. A user able to alter the Qemu disk image could ise this flaw to crash the Qemu instance resulting in DoS.

References

Affected products

Qemu
  • ==before 2.0

Matching in nixpkgs

Package maintainers

created 1 month ago
MediaWiki before 1.19.4 and 1.20.x before 1.20.3 allows remote attackers …

MediaWiki before 1.19.4 and 1.20.x before 1.20.3 allows remote attackers to cause a denial of service (application crash) by sending a specially crafted request.

References

Affected products

mediawiki
  • ==1.20.3
  • ==1.19.4

Matching in nixpkgs

Package maintainers

Permalink CVE-2025-0577
4.8 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): HIGH
  • Privileges required (PR): NONE
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): LOW
  • Availability impact (A): NONE
updated 1 month ago by @pyrox0 Activity log
  • Created automatic suggestion
  • @pyrox0 removed
    13 packages
    • minimal-bootstrap.glibc
    • tests.hardeningFlags.glibcxxassertionsStdenvUnsupp
    • tests.hardeningFlags.glibcxxassertionsExplicitEnabled
    • tests.hardeningFlags-gcc.glibcxxassertionsStdenvUnsupp
    • tests.hardeningFlags.glibcxxassertionsExplicitDisabled
    • tests.hardeningFlags-clang.glibcxxassertionsStdenvUnsupp
    • tests.hardeningFlags-gcc.glibcxxassertionsExplicitEnabled
    • tests.hardeningFlags.allExplicitDisabledGlibcxxAssertions
    • tests.hardeningFlags-gcc.glibcxxassertionsExplicitDisabled
    • tests.hardeningFlags-clang.glibcxxassertionsExplicitEnabled
    • tests.hardeningFlags-clang.glibcxxassertionsExplicitDisabled
    • tests.hardeningFlags-gcc.allExplicitDisabledGlibcxxAssertions
    • tests.hardeningFlags-clang.allExplicitDisabledGlibcxxAssertions
Glibc: vdso getrandom acceleration may return predictable randomness

An insufficient entropy vulnerability was found in glibc. The getrandom and arc4random family of functions may return predictable randomness if these functions are called again after the fork, which happens concurrently with a call to any of these functions.

References

Affected products

glibc
  • =<2.40-17.fc41
  • =<2.39-33.fc40

Matching in nixpkgs

pkgs.mtrace

Perl script used to interpret and provide human readable output of the trace log contained in the file mtracedata, whose contents were produced by mtrace(3)

Ignored packages (13)

Package maintainers

created 1 month ago
webauth before 4.6.1 has authentication credential disclosure

webauth before 4.6.1 has authentication credential disclosure

Affected products

webauth
  • ==4.4.1 up to 4.5.2

Matching in nixpkgs

Package maintainers

created 1 month ago
Chrony before 1.29.1 has traffic amplification in cmdmon protocol

Chrony before 1.29.1 has traffic amplification in cmdmon protocol

References

Affected products

Chrony
  • ==Fixed in 1.29.1

Matching in nixpkgs

pkgs.chrony

Sets your computer's clock from time servers on the Net

Package maintainers

created 1 month ago
Multiple integer overflows in the Pre-EFI Initialization (PEI) boot phase …

Multiple integer overflows in the Pre-EFI Initialization (PEI) boot phase in the Capsule Update feature in the UEFI implementation in EDK2 allow physically proximate attackers to bypass intended access restrictions by providing crafted data that is not properly handled during the coalescing phase.

References

Affected products

BIOS
  • ==unknown
SCT3
  • ==before 5/23/2014

Matching in nixpkgs

Package maintainers

created 1 month ago
Monkey HTTP Daemon has local security bypass

Monkey HTTP Daemon has local security bypass

Affected products

monkey
  • ==through 2013-06-14

Matching in nixpkgs

Package maintainers