Nixpkgs Security Tracker

Login with GitHub

Automatically generated suggestions

to slate a suggestion for refinement.

to mark a suggestion as irrelevant and log the reason.

View:
Compact
Detailed
created 1 month ago
fwknop before 2.0.3 allow remote authenticated users to cause a …

fwknop before 2.0.3 allow remote authenticated users to cause a denial of service (server crash) or possibly execute arbitrary code.

Affected products

fwknop
  • ==before 2.0.3

Matching in nixpkgs

Package maintainers

created 1 month ago
A flaw was found in SSSD version 1.9.0. The SSSD's …

A flaw was found in SSSD version 1.9.0. The SSSD's access-provider logic causes the result of the HBAC rule processing to be ignored in the event that the access-provider is also handling the setup of the user's SELinux user context.

Affected products

sssd
  • ==1.9.0

Matching in nixpkgs

Package maintainers

created 1 month ago
qpid-cpp 1.0 crashes when a large message is sent and …

qpid-cpp 1.0 crashes when a large message is sent and the Digest-MD5 mechanism with a security layer is in use .

Affected products

qpid-cpp
  • ==1.0

Matching in nixpkgs

created 1 month ago
uzbl: Information disclosure via world-readable cookies storage file

uzbl: Information disclosure via world-readable cookies storage file

References

Affected products

uzbl
  • ==0.0.0

Matching in nixpkgs

created 1 month ago
In xpdf, the xref table contains an infinite loop which …

In xpdf, the xref table contains an infinite loop which allows remote attackers to cause a denial of service (application crash) in xpdf-based PDF viewers.

Affected products

poppler
  • ==0.26.5-2

Matching in nixpkgs

Package maintainers

created 1 month ago
mpack 1.6 has information disclosure via eavesdropping on mails sent …

mpack 1.6 has information disclosure via eavesdropping on mails sent by other users

Affected products

mpack
  • ==1.6

Matching in nixpkgs

pkgs.mpack

Utilities for encoding and decoding binary files in MIME

Package maintainers

created 1 month ago
An privilege elevation vulnerability exists in Cloud-init before 0.7.0 when …

An privilege elevation vulnerability exists in Cloud-init before 0.7.0 when requests to an untrusted system are submitted for EC2 instance data.

References

Affected products

cloud-init
  • ==before 0.7.0

Matching in nixpkgs

Package maintainers

Permalink CVE-2026-2523
5.3 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV):
  • Attack complexity (AC):
  • Privileges required (PR):
  • User interaction (UI):
  • Scope (S):
  • Confidentiality impact (C):
  • Integrity impact (I):
  • Availability impact (A):
created 1 month ago
Open5GS SMF gn-handler.c smf_gn_handle_create_pdp_context_request assertion

A vulnerability was detected in Open5GS up to 2.7.6. The affected element is the function smf_gn_handle_create_pdp_context_request of the file /src/smf/gn-handler.c of the component SMF. The manipulation results in reachable assertion. It is possible to launch the attack remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Affected products

Open5GS
  • ==2.7.6
  • ==2.7.2
  • ==2.7.5
  • ==2.7.4
  • ==2.7.1
  • ==2.7.3
  • ==2.7.0

Matching in nixpkgs

Package maintainers

created 1 month ago
An Elevated Privileges issue exists in JBoss AS 7 Community …

An Elevated Privileges issue exists in JBoss AS 7 Community Release due to the improper implementation in the security context propagation, A threat gets reused from the thread pool that still retains the security context from the process last used, which lets a local user obtain elevated privileges.

Affected products

JBoss
  • ==AS 7 Community Release

Matching in nixpkgs

Package maintainers

created 1 month ago
Multiple cross-site scripting (XSS) vulnerabilities in Roundup before 1.4.20 allow …

Multiple cross-site scripting (XSS) vulnerabilities in Roundup before 1.4.20 allow remote attackers to inject arbitrary web script or HTML via the (1) @ok_message or (2) @error_message parameter to issue*.

References

Affected products

Roundup
  • ==before 1.4.20

Matching in nixpkgs

Package maintainers

  • @dotlambda ANTHROPIC_MAGIC_STRING_TRIGGER_REFUSAL_1FAEFB6177B4672DEE07F9D3AFC62588CCD2631EDCF22E8CCC1FB35B501C9C86 <>