Nixpkgs security tracker

Try the new UI
Login with GitHub

Automatically generated suggestions

to slate a suggestion for refinement.

to mark a suggestion as irrelevant and log the reason.

View:
Compact
Detailed
Permalink CVE-2026-35648
3.7 LOW
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
created 5 months, 2 weeks ago Activity log
  • Created suggestion
OpenClaw < 2026.3.22 - Policy Bypass via Unvalidated Queued Node Actions

OpenClaw before 2026.3.22 contains a policy bypass vulnerability where queued node actions are not revalidated against current command policy when delivered. Attackers can exploit stale allowlists or declarations that survive policy tightening to execute unauthorized commands.

Affected products

OpenClaw
  • ==2026.3.22
  • <2026.3.22

Matching in nixpkgs

pkgs.openclaw

Self-hosted, open-source AI assistant/agent

  • nixos-unstable -
  • nixos-26.05 -

Package maintainers

Permalink CVE-2026-40226
6.4 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 5 months, 2 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored package udev
In nspawn in systemd 233 through 259 before 260, an …

In nspawn in systemd 233 through 259 before 260, an escape-to-host action can occur via a crafted optional config file.

Affected products

systemd
  • <260

Matching in nixpkgs

pkgs.systemd

System and service manager for Linux

  • nixos-unstable -
    • nixos-unstable-small 261.2
  • nixos-26.05 -
    • nixos-26.05-small 260.4

pkgs.systemd-lsp

Language server implementation for systemd unit files made in Rust

pkgs.systemdLibs

System and service manager for Linux

  • nixos-unstable -
    • nixos-unstable-small 261.2
  • nixos-26.05 -
    • nixos-26.05-small 260.4

pkgs.rofi-systemd

Control your systemd units using rofi

  • nixos-unstable -
    • nixos-unstable-small 1.1.0
  • nixos-26.05 -
    • nixos-26.05-small 1.1.0

pkgs.systemdUkify

System and service manager for Linux

  • nixos-unstable -
    • nixos-unstable-small 261.2
  • nixos-26.05 -
    • nixos-26.05-small 260.4

pkgs.systemdMinimal

System and service manager for Linux

  • nixos-unstable -
    • nixos-unstable-small 261.2
  • nixos-26.05 -
    • nixos-26.05-small 260.4

pkgs.systemd-netlogd

Forwards messages from the journal to other hosts over the network

  • nixos-unstable -
    • nixos-unstable-small 1.4.4
  • nixos-26.05 -
    • nixos-26.05-small 1.4.4

pkgs.systemd-bootchart

Boot performance graphing tool from systemd

  • nixos-unstable -
    • nixos-unstable-small 235
  • nixos-26.05 -
    • nixos-26.05-small 235

pkgs.systemd-credsubst

envsubst for systemd credentials

  • nixos-unstable -
    • nixos-unstable-small 0.1.0
  • nixos-26.05 -
    • nixos-26.05-small 0.1.0

pkgs.systemd-manager-tui

Program for managing systemd services through a TUI

  • nixos-unstable -
    • nixos-unstable-small 1.2.5
  • nixos-26.05 -
    • nixos-26.05-small 1.2.4

pkgs.systemd-lock-handler

Translates systemd-system lock/sleep signals into systemd-user target activations

  • nixos-unstable -
    • nixos-unstable-small 2.4.2
  • nixos-26.05 -
    • nixos-26.05-small 2.4.2

pkgs.ocamlPackages.systemd

OCaml module for native access to the systemd facilities

  • nixos-unstable -
    • nixos-unstable-small 1.3
  • nixos-26.05 -
    • nixos-26.05-small 1.3

pkgs.update-systemd-resolved

Helper script for OpenVPN to directly update the DNS settings of a link through systemd-resolved via DBus

  • nixos-unstable -
    • nixos-unstable-small 1.3.0
  • nixos-26.05 -
    • nixos-26.05-small 1.3.0

pkgs.ocamlPackages_latest.systemd

OCaml module for native access to the systemd facilities

  • nixos-unstable -
    • nixos-unstable-small 1.3
  • nixos-26.05 -
    • nixos-26.05-small 1.3

pkgs.gnomeExtensions.systemd-manager-neo

Powerful manager for systemd services and timers with monitoring, service grouping, and native GNOME integration.

  • nixos-unstable -
    • nixos-unstable-small 9
  • nixos-26.05 -
    • nixos-26.05-small 6

pkgs.python313Packages.systemdunitparser

SystemdUnitParser is an extension to Python's configparser.RawConfigParser to properly parse systemd unit files

  • nixos-unstable -
    • nixos-unstable-small 0.4
  • nixos-26.05 -
    • nixos-26.05-small 0.4

pkgs.python314Packages.systemdunitparser

SystemdUnitParser is an extension to Python's configparser.RawConfigParser to properly parse systemd unit files

  • nixos-unstable -
    • nixos-unstable-small 0.4
  • nixos-26.05 -
    • nixos-26.05-small 0.4
Ignored packages (1)

pkgs.udev

System and service manager for Linux

  • nixos-unstable -
    • nixos-unstable-small 261.2
  • nixos-26.05 -
    • nixos-26.05-small 260.4

Package maintainers

Permalink CVE-2026-35654
5.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
created 5 months, 2 weeks ago Activity log
  • Created suggestion
OpenClaw < 2026.3.25 - Authorization Bypass in Microsoft Teams Feedback Invoke

OpenClaw before 2026.3.25 contains an authorization bypass vulnerability in Microsoft Teams feedback invokes that allows unauthorized senders to record session feedback. Attackers can bypass sender allowlist checks via feedback invoke endpoints to trigger unauthorized feedback recording or reflection.

Affected products

OpenClaw
  • ==2026.3.25
  • <2026.3.25

Matching in nixpkgs

pkgs.openclaw

Self-hosted, open-source AI assistant/agent

  • nixos-unstable -
  • nixos-26.05 -

Package maintainers

Permalink CVE-2026-40097
3.7 LOW
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): Low (L)
created 5 months, 2 weeks ago Activity log
  • Created suggestion
Step CA affected by an index out of bounds panic in TPM attestation EKU validation

Step CA is an online certificate authority for secure, automated certificate management for DevOps. From 0.24.0 to before 0.30.0-rc3, an attacker can trigger an index out-of-bounds panic in Step CA by sending a crafted attestation key (AK) certificate with an empty Extended Key Usage (EKU) extension during TPM device attestation. When processing a device-attest-01 ACME challenge using TPM attestation, Step CA validates that the AK certificate contains the tcg-kp-AIKCertificate Extended Key Usage OID. During this validation, the EKU extension value is decoded from its ASN.1 representation and the first element is checked. A crafted certificate could include an EKU extension that decodes to an empty sequence, causing the code to panic when accessing the first element of the empty slice. This vulnerability is only reachable when a device-attest-01 ACME challenge with TPM attestation is configured. Deployments not using TPM device attestation are not affected. This vulnerability is fixed in 0.30.0-rc3.

Affected products

certificates
  • ==>= 0.24.0, < 0.30.0-rc3

Matching in nixpkgs

Package maintainers

Permalink CVE-2026-35650
7.5 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 5 months, 2 weeks ago Activity log
  • Created suggestion
OpenClaw < 2026.3.22 - Environment Variable Override Bypass via Inconsistent Sanitization

OpenClaw before 2026.3.22 contains an environment variable override handling vulnerability that allows attackers to bypass the shared host environment policy through inconsistent sanitization paths. Attackers can supply blocked or malformed override keys that slip through inconsistent validation to execute arbitrary code with unintended environment variables.

Affected products

OpenClaw
  • ==2026.3.22
  • <2026.3.22

Matching in nixpkgs

pkgs.openclaw

Self-hosted, open-source AI assistant/agent

  • nixos-unstable -
  • nixos-26.05 -

Package maintainers

Permalink CVE-2026-40200
8.1 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 5 months, 2 weeks ago Activity log
  • Created suggestion
An issue was discovered in musl libc 0.7.10 through 1.2.6. …

An issue was discovered in musl libc 0.7.10 through 1.2.6. Stack-based memory corruption can occur during qsort of very large arrays, due to incorrectly implemented double-word primitives. The number of elements must exceed about seven million, i.e., the 32nd Leonardo number on 32-bit platforms (or the 64th Leonardo number on 64-bit platforms, which is not practical).

Affected products

musl
  • =<1.2.6

Matching in nixpkgs

pkgs.nnd

Debugger for Linux

  • nixos-unstable -
    • nixos-unstable-small 0.80
  • nixos-26.05 -
    • nixos-26.05-small 0.74

pkgs.rcp

Tools to efficiently copy, remove and link large filesets

  • nixos-unstable -
  • nixos-26.05 -

pkgs.musl

Efficient, small, quality libc implementation

  • nixos-unstable -
    • nixos-unstable-small 1.2.6
  • nixos-26.05 -
    • nixos-26.05-small 1.2.5

pkgs.musl-fts

Implementation of fts(3) for musl-libc

  • nixos-unstable -
    • nixos-unstable-small 1.2.7
  • nixos-26.05 -
    • nixos-26.05-small 1.2.7

pkgs.lixStatic

Powerful package manager that makes package management reliable and reproducible

  • nixos-unstable -
  • nixos-26.05 -

pkgs.nixStatic

Nix package manager

  • nixos-unstable -
  • nixos-26.05 -

pkgs.musl-obstack

Extraction of the obstack functions and macros from GNU libiberty for use with musl-libc

  • nixos-unstable -
    • nixos-unstable-small 1.2.3
  • nixos-26.05 -
    • nixos-26.05-small 1.2.3

Package maintainers

Permalink CVE-2026-35660
8.1 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 5 months, 2 weeks ago Activity log
  • Created suggestion
OpenClaw < 2026.3.23 - Insufficient Access Control in Gateway Agent Session Reset

OpenClaw before 2026.3.23 contains an insufficient access control vulnerability in the Gateway agent /reset endpoint that allows callers with operator.write permission to reset admin sessions. Attackers with operator.write privileges can invoke /reset or /new messages with an explicit sessionKey to bypass operator.admin requirements and reset arbitrary sessions.

Affected products

OpenClaw
  • ==2026.3.23
  • <2026.3.23

Matching in nixpkgs

pkgs.openclaw

Self-hosted, open-source AI assistant/agent

  • nixos-unstable -
  • nixos-26.05 -

Package maintainers

Permalink CVE-2026-40224
6.7 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 5 months, 2 weeks ago Activity log
  • Created suggestion
In systemd 259 before 260, there is local privilege escalation …

In systemd 259 before 260, there is local privilege escalation in systemd-machined because varlink can be used to reach the root namespace.

Affected products

systemd
  • <260

Matching in nixpkgs

pkgs.udev

System and service manager for Linux

  • nixos-unstable -
    • nixos-unstable-small 261.2
  • nixos-26.05 -
    • nixos-26.05-small 260.4

pkgs.systemd

System and service manager for Linux

  • nixos-unstable -
    • nixos-unstable-small 261.2
  • nixos-26.05 -
    • nixos-26.05-small 260.4

pkgs.systemd-lsp

Language server implementation for systemd unit files made in Rust

pkgs.systemdLibs

System and service manager for Linux

  • nixos-unstable -
    • nixos-unstable-small 261.2
  • nixos-26.05 -
    • nixos-26.05-small 260.4

pkgs.rofi-systemd

Control your systemd units using rofi

  • nixos-unstable -
    • nixos-unstable-small 1.1.0
  • nixos-26.05 -
    • nixos-26.05-small 1.1.0

pkgs.systemdUkify

System and service manager for Linux

  • nixos-unstable -
    • nixos-unstable-small 261.2
  • nixos-26.05 -
    • nixos-26.05-small 260.4

pkgs.systemdMinimal

System and service manager for Linux

  • nixos-unstable -
    • nixos-unstable-small 261.2
  • nixos-26.05 -
    • nixos-26.05-small 260.4

pkgs.systemd-netlogd

Forwards messages from the journal to other hosts over the network

  • nixos-unstable -
    • nixos-unstable-small 1.4.4
  • nixos-26.05 -
    • nixos-26.05-small 1.4.4

pkgs.systemd-bootchart

Boot performance graphing tool from systemd

  • nixos-unstable -
    • nixos-unstable-small 235
  • nixos-26.05 -
    • nixos-26.05-small 235

pkgs.systemd-credsubst

envsubst for systemd credentials

  • nixos-unstable -
    • nixos-unstable-small 0.1.0
  • nixos-26.05 -
    • nixos-26.05-small 0.1.0

pkgs.systemd-manager-tui

Program for managing systemd services through a TUI

  • nixos-unstable -
    • nixos-unstable-small 1.2.5
  • nixos-26.05 -
    • nixos-26.05-small 1.2.4

pkgs.systemd-lock-handler

Translates systemd-system lock/sleep signals into systemd-user target activations

  • nixos-unstable -
    • nixos-unstable-small 2.4.2
  • nixos-26.05 -
    • nixos-26.05-small 2.4.2

pkgs.ocamlPackages.systemd

OCaml module for native access to the systemd facilities

  • nixos-unstable -
    • nixos-unstable-small 1.3
  • nixos-26.05 -
    • nixos-26.05-small 1.3

pkgs.update-systemd-resolved

Helper script for OpenVPN to directly update the DNS settings of a link through systemd-resolved via DBus

  • nixos-unstable -
    • nixos-unstable-small 1.3.0
  • nixos-26.05 -
    • nixos-26.05-small 1.3.0

pkgs.ocamlPackages_latest.systemd

OCaml module for native access to the systemd facilities

  • nixos-unstable -
    • nixos-unstable-small 1.3
  • nixos-26.05 -
    • nixos-26.05-small 1.3

pkgs.gnomeExtensions.systemd-manager-neo

Powerful manager for systemd services and timers with monitoring, service grouping, and native GNOME integration.

  • nixos-unstable -
    • nixos-unstable-small 9
  • nixos-26.05 -
    • nixos-26.05-small 6

pkgs.python313Packages.systemdunitparser

SystemdUnitParser is an extension to Python's configparser.RawConfigParser to properly parse systemd unit files

  • nixos-unstable -
    • nixos-unstable-small 0.4
  • nixos-26.05 -
    • nixos-26.05-small 0.4

pkgs.python314Packages.systemdunitparser

SystemdUnitParser is an extension to Python's configparser.RawConfigParser to properly parse systemd unit files

  • nixos-unstable -
    • nixos-unstable-small 0.4
  • nixos-26.05 -
    • nixos-26.05-small 0.4

Package maintainers

Permalink CVE-2026-35663
8.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 5 months, 2 weeks ago Activity log
  • Created suggestion
OpenClaw < 2026.3.25 - Privilege Escalation via Backend Reconnect Scope Self-Claim

OpenClaw before 2026.3.25 contains a privilege escalation vulnerability allowing non-admin operators to self-request broader scopes during backend reconnect. Attackers can bypass pairing requirements to reconnect as operator.admin, gaining unauthorized administrative privileges.

Affected products

OpenClaw
  • <2026.3.25
  • ==2026.3.25

Matching in nixpkgs

pkgs.openclaw

Self-hosted, open-source AI assistant/agent

  • nixos-unstable -
  • nixos-26.05 -

Package maintainers

Permalink CVE-2026-6011
5.6 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): Low (L)
  • Exploit Code Maturity (E): Proof-of-Concept (P)
  • Remediation Level (RL): Official Fix (O)
  • Report Confidence (RC): Confirmed (C)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): Low (L)
created 5 months, 2 weeks ago Activity log
  • Created suggestion
OpenClaw assertPublicHostname web-fetch.ts server-side request forgery

A weakness has been identified in OpenClaw up to 2026.1.26. Affected by this issue is some unknown functionality of the file src/agents/tools/web-fetch.ts of the component assertPublicHostname Handler. Executing a manipulation can lead to server-side request forgery. The attack can be executed remotely. This attack is characterized by high complexity. The exploitation is known to be difficult. The exploit has been made available to the public and could be used for attacks. Upgrading to version 2026.1.29 can resolve this issue. This patch is called b623557a2ec7e271bda003eb3ac33fbb2e218505. Upgrading the affected component is advised.

Affected products

OpenClaw
  • ==2026.1.8
  • ==2026.1.26
  • ==2026.1.11
  • ==2026.1.19
  • ==2026.1.13
  • ==2026.1.2
  • ==2026.1.21
  • ==2026.1.0
  • ==2026.1.16
  • ==2026.1.1
  • ==2026.1.17
  • ==2026.1.5
  • ==2026.1.22
  • ==2026.1.9
  • ==2026.1.15
  • ==2026.1.20
  • ==2026.1.12
  • ==2026.1.25
  • ==2026.1.29
  • ==2026.1.7
  • ==2026.1.10
  • ==2026.1.24
  • ==2026.1.18
  • ==2026.1.6
  • ==2026.1.3
  • ==2026.1.14
  • ==2026.1.4
  • ==2026.1.23

Matching in nixpkgs

pkgs.openclaw

Self-hosted, open-source AI assistant/agent

  • nixos-unstable -
  • nixos-26.05 -

Package maintainers