Nixpkgs security tracker

Try the new UI
Login with GitHub

Automatically generated suggestions

to slate a suggestion for refinement.

to mark a suggestion as irrelevant and log the reason.

View:
Compact
Detailed
Permalink CVE-2026-57842
7.3 HIGH
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): High (H)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): High (H)
  • Vulnerable System Impact Integrity (VI): High (H)
  • Vulnerable System Impact Availability (VA): High (H)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): High (H)
  • Modified Vulnerable System Impact Integrity (MVI): High (H)
  • Modified Vulnerable System Impact Availability (MVA): High (H)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 2 weeks, 3 days ago Activity log
  • Created suggestion
NetBSD COMPAT_NETBSD32 Double Free / Use-After-Free via recvmsg() msg_iovlen

NetBSD contains a use-after-free and double-free vulnerability in msg_recv_copyin() within the COMPAT_NETBSD32 compatibility layer due to a missing return statement before the cleanup label on the success path. Any local user able to execute a 32-bit binary on a 64-bit NetBSD system can trigger a kernel panic or memory corruption by calling recvmsg() with msg_iovlen between 9 and IOV_MAX, causing the kernel to access a freed iovec buffer and subsequently free the same allocation a second time.

Affected products

NetBSD
  • <9.5
  • =<10.1
  • =<8.3

Matching in nixpkgs

Package maintainers

Permalink CVE-2026-54241
7.4 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): High (H)
created 2 weeks, 3 days ago Activity log
  • Created suggestion
libde265: SAO sequential filter heap buffer overflow via signed integer overflow

libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.1.1 use signed 32-bit arithmetic to calculate the sample adaptive offset input-buffer size, allowing a crafted HEVC stream with large dimensions and 16-bit luma samples to cause an integer overflow, an undersized allocation, and an out-of-bounds heap read that may expose heap data in decoded output or crash the decoder. Version 1.1.1 contains a patch.

Affected products

libde265
  • ==< 1.1.1

Matching in nixpkgs

pkgs.libde265

Open h.265 video codec implementation

  • nixos-unstable -
    • nixos-unstable-small 1.1.2
  • nixos-26.05 -
    • nixos-26.05-small 1.1.2
Permalink CVE-2026-18495
6.1 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): High (H)
created 2 weeks, 3 days ago Activity log
  • Created suggestion
Libtiff: libtiff: heap-buffer overflow via numeric truncation in the jpeg raw passthrough

A flaw was found in libtiff. A heap-buffer overflow vulnerability exists in the `tiff2pdf` utility due to an integer truncation error when processing crafted BigTIFF files. An attacker can provide a specially crafted BigTIFF file, causing a 64-bit `StripByteCounts` value to be truncated to a 32-bit integer. This leads to an undersized memory allocation and a subsequent out-of-bounds memory copy, resulting in a crash and severe memory corruption.

Affected products

ceph
boost
libtiff
libtiff-main
  • *
mingw-libtiff
compat-libtiff3

Matching in nixpkgs

pkgs.ceph

Distributed storage system

  • nixos-unstable -
  • nixos-26.05 -

pkgs.boost

Collection of C++ libraries

  • nixos-unstable -
  • nixos-26.05 -

pkgs.booster

Fast and secure initramfs generator

  • nixos-unstable -
    • nixos-unstable-small 0.12
  • nixos-26.05 -
    • nixos-26.05-small 0.12

pkgs.calceph

C library for interacting with binary planetary ephemeris files, such INPOPxx, JPL DExxx and SPICE

  • nixos-unstable -
    • nixos-unstable-small 5.0.1
  • nixos-26.05 -
    • nixos-26.05-small 4.0.5

pkgs.libceph

Distributed storage system

  • nixos-unstable -
  • nixos-26.05 -

pkgs.libtiff

Library and utilities for working with the TIFF image file format

  • nixos-unstable -
    • nixos-unstable-small 4.7.2
  • nixos-26.05 -
    • nixos-26.05-small 4.7.2

pkgs.xgboost

Scalable, Portable and Distributed Gradient Boosting (GBDT, GBRT or GBM) Library

  • nixos-unstable -
    • nixos-unstable-small 3.0.5
  • nixos-26.05 -
    • nixos-26.05-small 3.0.5

pkgs.boost178

Collection of C++ libraries

  • nixos-unstable -
  • nixos-26.05 -

pkgs.boost179

Collection of C++ libraries

  • nixos-unstable -
  • nixos-26.05 -

pkgs.boost180

Collection of C++ libraries

  • nixos-unstable -
  • nixos-26.05 -

pkgs.boost181

Collection of C++ libraries

  • nixos-unstable -
  • nixos-26.05 -

pkgs.boost182

Collection of C++ libraries

  • nixos-unstable -
  • nixos-26.05 -

pkgs.boost183

Collection of C++ libraries

  • nixos-unstable -
  • nixos-26.05 -

pkgs.boost186

Collection of C++ libraries

  • nixos-unstable -
  • nixos-26.05 -

pkgs.boost187

Collection of C++ libraries

  • nixos-unstable -
  • nixos-26.05 -

pkgs.boost188

Collection of C++ libraries

  • nixos-unstable -
  • nixos-26.05 -

pkgs.boost189

Collection of C++ libraries

  • nixos-unstable -
  • nixos-26.05 -

pkgs.boost190

Collection of C++ libraries

  • nixos-unstable -
  • nixos-26.05 -

pkgs.boost191

Collection of C++ libraries

  • nixos-unstable -

pkgs.catboost

High-performance library for gradient boosting on decision trees

  • nixos-unstable -
  • nixos-26.05 -

pkgs.ceph-csi

Container Storage Interface (CSI) driver for Ceph RBD and CephFS

  • nixos-unstable -
  • nixos-26.05 -

pkgs.ceph-dev

Distributed storage system

  • nixos-unstable -
  • nixos-26.05 -

pkgs.boost-sml

Header only state machine library with no dependencies

  • nixos-unstable -
    • nixos-unstable-small 1.2.0
  • nixos-26.05 -

pkgs.mev-boost

Ethereum block-building middleware

  • nixos-unstable -
    • nixos-unstable-small 1.12
  • nixos-26.05 -
    • nixos-26.05-small 1.12

pkgs.boost-build

None

  • nixos-unstable -
    • nixos-unstable-small 4.4.1
  • nixos-26.05 -
    • nixos-26.05-small 4.4.1

pkgs.ceph-client

Distributed storage system

  • nixos-unstable -
  • nixos-26.05 -

pkgs.nosql-booster

GUI tool for MongoDB Server

  • nixos-unstable -
    • nixos-unstable-small 8.1.9
  • nixos-26.05 -
    • nixos-26.05-small 8.1.9

pkgs.xgboostWithCuda

Scalable, Portable and Distributed Gradient Boosting (GBDT, GBRT or GBM) Library

  • nixos-unstable -
    • nixos-unstable-small 3.0.5
  • nixos-26.05 -
    • nixos-26.05-small 3.0.5

pkgs.emacs-lsp-booster

Emacs LSP performance booster

  • nixos-unstable -
    • nixos-unstable-small 0.2.1
  • nixos-26.05 -
    • nixos-26.05-small 0.2.1

pkgs.kubectl-rook-ceph

Krew plugin to run kubectl commands with rook-ceph

  • nixos-unstable -
    • nixos-unstable-small 0.9.6
  • nixos-26.05 -
    • nixos-26.05-small 0.9.6

pkgs.python313Packages.xgboost

Scalable, Portable and Distributed Gradient Boosting (GBDT, GBRT or GBM) Library

  • nixos-unstable -
    • nixos-unstable-small 3.0.5
  • nixos-26.05 -
    • nixos-26.05-small 3.0.5

pkgs.python314Packages.xgboost

Scalable, Portable and Distributed Gradient Boosting (GBDT, GBRT or GBM) Library

  • nixos-unstable -
    • nixos-unstable-small 3.0.5
  • nixos-26.05 -
    • nixos-26.05-small 3.0.5

Package maintainers

Permalink CVE-2026-78134
7.1 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): Low (L)
created 2 weeks, 3 days ago Activity log
  • Created suggestion
strongSwan 4.5.0 through 6.0.7 has Incorrect Access Control in the …

strongSwan 4.5.0 through 6.0.7 has Incorrect Access Control in the eap-ttls and eap-peap plugins because there can be a missing or mismatched inner EAP identity.

Affected products

strongSwan
  • <6.1.0

Matching in nixpkgs

pkgs.strongswan

OpenSource IPsec-based VPN solution

  • nixos-unstable -
    • nixos-unstable-small 6.1.0
  • nixos-26.05 -
    • nixos-26.05-small 6.1.0

pkgs.strongswanNM

OpenSource IPsec-based VPN solution

  • nixos-unstable -
    • nixos-unstable-small 6.1.0
  • nixos-26.05 -
    • nixos-26.05-small 6.1.0

pkgs.strongswanTNC

OpenSource IPsec-based VPN solution

  • nixos-unstable -
    • nixos-unstable-small 6.1.0
  • nixos-26.05 -
    • nixos-26.05-small 6.1.0

pkgs.strongswanTPM

OpenSource IPsec-based VPN solution

  • nixos-unstable -
    • nixos-unstable-small 6.1.0
  • nixos-26.05 -
    • nixos-26.05-small 6.1.0

Package maintainers

Permalink CVE-2026-54258
6.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
created 2 weeks, 3 days ago Activity log
  • Created suggestion
Cross-monitor event media authorization bypass in direct event media endpoints

ZoneMinder is a free, open source closed-circuit television software application. Versions prior to 1.36.39, 1.38.4, and 1.39.11 allow an authenticated low-privileged user with coarse `Events=View` and/or `Snapshots=View` permissions to directly fetch media for events belonging to monitors they are not allowed to access. The normal UI correctly hides the restricted monitor and its events, but direct event media views accept an arbitrary `eid` and stream media from the event path without enforcing the event/monitor-level ACL. This exposes private surveillance footage across monitor boundaries. Versions 1.36.39, 1.38.4, and 1.39.11 fix the issue.

Affected products

zoneminder
  • ==>= 1.39.0, < 1.39.11
  • ==< 1.36.39
  • ==>= 1.37.0, < 1.38.4

Matching in nixpkgs

pkgs.zoneminder

Video surveillance software system

  • nixos-unstable -
  • nixos-26.05 -

Package maintainers

Permalink CVE-2026-86779
2.7 LOW
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
created 2 weeks, 3 days ago Activity log
  • Created suggestion
Visualizer < 4.0.6 - Contributor+ Arbitrary Chart Deletion via deleteChart

The Visualizer WordPress plugin before 4.0.6 does not properly authorise chart-deletion requests, performing only a site-wide capability check with no per-object ownership verification, allowing users with the Contributor role and above to permanently delete any chart on the site, including charts created by other users such as administrators.

References

Affected products

Visualizer
  • <4.0.6

Matching in nixpkgs

pkgs.dbvisualizer

Universal database tool

  • nixos-unstable -
  • nixos-26.05 -

pkgs.midivisualizer

Small MIDI visualizer tool, using OpenGL

  • nixos-unstable -
    • nixos-unstable-small 7.3
  • nixos-26.05 -
    • nixos-26.05-small 7.3

pkgs.ttnn-visualizer

Tool for visualizing and analyzing TT-NN model execution

  • nixos-unstable -
    • nixos-unstable-small

pkgs.pulse-visualizer

Real-time audio visualizer inspired by MiniMeters

  • nixos-unstable -
    • nixos-unstable-small 1.3.9
  • nixos-26.05 -
    • nixos-26.05-small 1.3.9

pkgs.pkgsRocm.midivisualizer

Small MIDI visualizer tool, using OpenGL

  • nixos-unstable -
    • nixos-unstable-small 7.3
  • nixos-26.05 -
    • nixos-26.05-small 7.3
Permalink CVE-2026-47839
9.2 CRITICAL
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Attack Requirement (AT): Present (P)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): High (H)
  • Vulnerable System Impact Integrity (VI): High (H)
  • Vulnerable System Impact Availability (VA): High (H)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Attack Requirement (MAT): Present (P)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): High (H)
  • Modified Vulnerable System Impact Integrity (MVI): High (H)
  • Modified Vulnerable System Impact Availability (MVA): High (H)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 2 weeks, 3 days ago Activity log
  • Created suggestion
Federated OIDC Users Can Bypass externalGroupsWhitelist to Gain uaa.admin

A vulnerability allows users authenticating through a federated OIDC provider to obtain the uaa.admin scope despite operators restricting that provider through externalGroupsWhitelist configuration. The issue occurs specifically when an OIDC identity provider uses groupMappingMode: AS_SCOPES with a wildcard externalGroupsWhitelist entry.

Affected products

UAA
  • =<77.30.0
  • ==77.31.0
cf-deployment
  • =<48.9.0
  • ==48.10.0

Matching in nixpkgs

Permalink CVE-2026-78127
3.7 LOW
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): Low (L)
created 2 weeks, 3 days ago Activity log
  • Created suggestion
libcharon in strongSwan 4.1.2 through 6.0.7 has a missing release …

libcharon in strongSwan 4.1.2 through 6.0.7 has a missing release of memory after its effective lifetime in the IKE message parser.

Affected products

strongSwan
  • <6.1.0

Matching in nixpkgs

pkgs.strongswan

OpenSource IPsec-based VPN solution

  • nixos-unstable -
    • nixos-unstable-small 6.1.0
  • nixos-26.05 -
    • nixos-26.05-small 6.1.0

pkgs.strongswanNM

OpenSource IPsec-based VPN solution

  • nixos-unstable -
    • nixos-unstable-small 6.1.0
  • nixos-26.05 -
    • nixos-26.05-small 6.1.0

pkgs.strongswanTNC

OpenSource IPsec-based VPN solution

  • nixos-unstable -
    • nixos-unstable-small 6.1.0
  • nixos-26.05 -
    • nixos-26.05-small 6.1.0

pkgs.strongswanTPM

OpenSource IPsec-based VPN solution

  • nixos-unstable -
    • nixos-unstable-small 6.1.0
  • nixos-26.05 -
    • nixos-26.05-small 6.1.0

Package maintainers

Permalink CVE-2026-90460
7.6 HIGH
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): Present (P)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): High (H)
  • Vulnerable System Impact Integrity (VI): High (H)
  • Vulnerable System Impact Availability (VA): Low (L)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): Present (P)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): High (H)
  • Modified Vulnerable System Impact Integrity (MVI): High (H)
  • Modified Vulnerable System Impact Availability (MVA): Low (L)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 2 weeks, 3 days ago Activity log
  • Created suggestion
An issue was discovered in OpenStack Keystone before 29.0.3. Tokens …

An issue was discovered in OpenStack Keystone before 29.0.3. Tokens obtained via delegated authentication methods (EC2 credentials, application credentials, OAuth1 access tokens, and trusts) are not blocked from creating, modifying, or deleting credentials via the /v3/credentials API. EC2-derived tokens can additionally read credential blobs, exposing TOTP MFA seeds and other secrets. Also, PATCH /v3/credentials does not validate the requested post-update project_id, allowing any delegated token to move a credential to an unauthorized project. All Keystone deployments using delegated authentication are affected.

Affected products

Keystone
  • <28.0.3
  • <29.0.3
  • <27.0.3

Matching in nixpkgs

pkgs.keystone

Lightweight multi-platform, multi-architecture assembler framework

  • nixos-unstable -
    • nixos-unstable-small 0.9.2
  • nixos-26.05 -
    • nixos-26.05-small 0.9.2

Package maintainers

Permalink CVE-2026-49846
7.5 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
created 2 weeks, 3 days ago Activity log
  • Created suggestion
libks has path traversal in kws HTTP parser via URI segment overflow

libks provides foundational support for signalwire C products. Prior to version 2.0.11, `clean_uri()` in libks's HTTP request parser fails to reject URIs whose path has more segments than its internal canonicalization buffer can hold. The canonicalization step silently passes such URIs through with embedded ".." sequences intact, enabling path traversal in any consumer that later joins the URI with a filesystem path. Version 2.0.11 patches the issue.

Affected products

libks
  • ==< 2.0.11

Matching in nixpkgs

pkgs.libks

Foundational support for signalwire C products

  • nixos-unstable -
  • nixos-26.05 -

pkgs.libksi

Keyless Signature Infrastructure API library

  • nixos-unstable -
  • nixos-26.05 -

pkgs.libksba

CMS and X.509 access library

  • nixos-unstable -
    • nixos-unstable-small 1.8.0
  • nixos-26.05 -
    • nixos-26.05-small 1.6.7

pkgs.kdePackages.libksane

Library providing QWidget with all the logic to interface scanners

  • nixos-unstable -
  • nixos-26.05 -

pkgs.kdePackages.libksysguard

Library to retrieve information on the current status of computer hardware

  • nixos-unstable -
    • nixos-unstable-small 6.7.5
  • nixos-26.05 -
    • nixos-26.05-small 6.6.6