Nixpkgs security tracker

Try the new UI
Login with GitHub

Automatically generated suggestions

to slate a suggestion for refinement.

to mark a suggestion as irrelevant and log the reason.

View:
Compact
Detailed
Permalink CVE-2026-5673
5.6 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): None (N)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): High (H)
created 5 months, 2 weeks ago Activity log
  • Created suggestion
Libtheora: libtheora: denial of service or information disclosure via malformed avi file processing

A flaw was found in libtheora. This heap-based out-of-bounds read vulnerability exists within the AVI (Audio Video Interleave) parser, specifically in the avi_parse_input_file() function. A local attacker could exploit this by tricking a user into opening a specially crafted AVI file containing a truncated header sub-chunk. This could lead to a denial-of-service (application crash) or potentially leak sensitive information from the heap.

References

Affected products

libtheora

Matching in nixpkgs

pkgs.libtheora

Library for Theora, a free and open video compression format

  • nixos-unstable -
    • nixos-unstable-small 1.2.0
  • nixos-26.05 -
    • nixos-26.05-small 1.2.0

Package maintainers

Permalink CVE-2026-26263
8.1 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 5 months, 2 weeks ago Activity log
  • Created suggestion
GLPI has an Unauthenticated SQL Injection via Search engine

GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated time-based blind SQL injection exists in GLPI's Search engine. This vulnerability is fixed in 11.0.6.

Affected products

glpi
  • ==>= 11.0.0, < 11.0.6

Matching in nixpkgs

pkgs.glpi-agent

GLPI unified Agent for UNIX, Linux, Windows and MacOSX

  • nixos-unstable -
    • nixos-unstable-small 1.19
  • nixos-26.05 -
    • nixos-26.05-small 1.19

Package maintainers

created 5 months, 2 weeks ago Activity log
  • Created suggestion
LiteLLM has an authentication bypass via OIDC userinfo cache key collision

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, when JWT authentication is enabled (enable_jwt_auth: true), the OIDC userinfo cache uses token[:20] as the cache key. JWT headers produced by the same signing algorithm generate identical first 20 characters. This configuration option is not enabled by default. Most instances are not affected. An unauthenticated attacker can craft a token whose first 20 characters match a legitimate user's cached token. On cache hit, the attacker inherits the legitimate user's identity and permissions. This affects deployments with JWT/OIDC authentication enabled. Fixed in v1.83.0.

Affected products

litellm
  • ==< 1.83.0

Matching in nixpkgs

pkgs.litellm

Use any LLM as a drop in replacement for gpt-3.5-turbo. Use Azure, OpenAI, Cohere, Anthropic, Ollama, VLLM, Sagemaker, HuggingFace, Replicate (100+ LLMs)

  • nixos-unstable -
  • nixos-26.05 -

pkgs.python313Packages.litellm

Use any LLM as a drop in replacement for gpt-3.5-turbo. Use Azure, OpenAI, Cohere, Anthropic, Ollama, VLLM, Sagemaker, HuggingFace, Replicate (100+ LLMs)

  • nixos-unstable -
  • nixos-26.05 -

pkgs.python314Packages.litellm

Use any LLM as a drop in replacement for gpt-3.5-turbo. Use Azure, OpenAI, Cohere, Anthropic, Ollama, VLLM, Sagemaker, HuggingFace, Replicate (100+ LLMs)

  • nixos-unstable -
  • nixos-26.05 -

Package maintainers

Permalink CVE-2026-5530
6.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): Low (L)
  • Exploit Code Maturity (E): Not Defined (X)
  • Remediation Level (RL): Not Defined (X)
  • Report Confidence (RC): Reasonable (R)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): Low (L)
created 5 months, 2 weeks ago Activity log
  • Created suggestion
Ollama Model Pull API download.go server-side request forgery

A flaw has been found in Ollama up to 18.1. This issue affects some unknown processing of the file server/download.go of the component Model Pull API. Executing a manipulation can lead to server-side request forgery. The attack can be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.

Affected products

Ollama
  • ==18.1
  • ==18.0

Matching in nixpkgs

pkgs.ollama

Get up and running with large language models locally

  • nixos-unstable -
  • nixos-26.05 -

pkgs.gollama

Go manage your Ollama models

  • nixos-unstable -
    • nixos-unstable-small 2.0.5
  • nixos-26.05 -
    • nixos-26.05-small 2.0.4

pkgs.ollama-cpu

Get up and running with large language models locally

  • nixos-unstable -
  • nixos-26.05 -

pkgs.ollama-cuda

Get up and running with large language models locally, using CUDA for NVIDIA GPU acceleration

  • nixos-unstable -
  • nixos-26.05 -

pkgs.ollama-rocm

Get up and running with large language models locally, using ROCm for AMD GPU acceleration

  • nixos-unstable -
  • nixos-26.05 -

pkgs.ollama-vulkan

Get up and running with large language models locally, using Vulkan for generic GPU acceleration

  • nixos-unstable -
  • nixos-26.05 -

pkgs.pkgsRocm.ollama

Get up and running with large language models locally, using ROCm for AMD GPU acceleration

  • nixos-unstable -
  • nixos-26.05 -

pkgs.nextjs-ollama-llm-ui

Simple chat web interface for Ollama LLMs

  • nixos-unstable -
    • nixos-unstable-small 1.2.0
  • nixos-26.05 -
    • nixos-26.05-small 1.2.0

pkgs.gnomeExtensions.ollama-usage-rings

Shows your Ollama Cloud session and weekly usage as colored ring indicators in the GNOME top bar, with pace/burn-down details. Requires your own ollama.com session cookie (entered in the extension settings).

  • nixos-unstable -
    • nixos-unstable-small 3

Package maintainers

Permalink CVE-2026-34753
5.4 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): None (N)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): Low (L)
created 5 months, 2 weeks ago Activity log
  • Created suggestion
vLLM affected by Server-Side Request Forgery (SSRF) in `download_bytes_from_url `

vLLM is an inference and serving engine for large language models (LLMs). From 0.16.0 to before 0.19.0, a server-side request forgery (SSRF) vulnerability in download_bytes_from_url allows any actor who can control batch input JSON to make the vLLM batch runner issue arbitrary HTTP/HTTPS requests from the server, without any URL validation or domain restrictions. This can be used to target internal services (e.g. cloud metadata endpoints or internal HTTP APIs) reachable from the vLLM host. This vulnerability is fixed in 0.19.0.

Affected products

vllm
  • ==>= 0.16.0, < 0.19.0

Matching in nixpkgs

pkgs.vllm

High-throughput and memory-efficient inference and serving engine for LLMs

  • nixos-unstable -
  • nixos-26.05 -

pkgs.pkgsRocm.vllm

High-throughput and memory-efficient inference and serving engine for LLMs

  • nixos-unstable -
  • nixos-26.05 -

pkgs.python313Packages.vllm

High-throughput and memory-efficient inference and serving engine for LLMs

  • nixos-unstable -
  • nixos-26.05 -

Package maintainers

Permalink CVE-2025-47389
7.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 5 months, 2 weeks ago Activity log
  • Created suggestion
Buffer Copy Without Checking Size of Input in Automotive Platform

Memory corruption when buffer copy operation fails due to integer overflow during attestation report generation.

Affected products

Snapdragon
  • ==Monaco_IOT
  • ==QEP8111
  • ==X2000092
  • ==SM7325P
  • ==WCN6755
  • ==QCM5430
  • ==SAR1165P
  • ==QCA6688AQ
  • ==X2000077
  • ==SA6150P
  • ==QAM8295P
  • ==Snapdragon 8 Elite
  • ==QPA1086BD
  • ==QAM8620P
  • ==SA8150P
  • ==Snapdragon 7c+ Gen 3 Compute
  • ==WCD9375
  • ==SA8620P
  • ==SM8650Q
  • ==Snapdragon X72 5G Modem-RF System
  • ==WCN6650
  • ==Snapdragon X75 5G Modem-RF System
  • ==SA6155P
  • ==Snapdragon AR1+ Gen 1 Platform
  • ==Snapdragon 460 Mobile Platform
  • ==QAM8255P
  • ==WSA8815
  • ==QMP1000
  • ==SA8295P
  • ==FWA Gen 3 Ultra Platform
  • ==Snapdragon X32 5G Modem-RF System
  • ==QAM8397P
  • ==Snapdragon 480+ 5G Mobile Platform
  • ==XG101002
  • ==QCM6125
  • ==Orne
  • ==Snapdragon 778G+ 5G Mobile Platform
  • ==XG101039
  • ==QXM1093
  • ==WCN6450
  • ==SM8635
  • ==Snapdragon X55 5G Modem-RF System
  • ==Cologne
  • ==QLN1086BD
  • ==SW6100P
  • ==CSRA6640
  • ==Snapdragon 8 Elite Gen 5
  • ==Snapdragon 4 Gen 2 Mobile Platform
  • ==QXM1096
  • ==WSA8835
  • ==SRV1H
  • ==SM7635P
  • ==WCN3988
  • ==Snapdragon 695 5G Mobile Platform
  • ==Snapdragon 865+ 5G Mobile Platform
  • ==SM8750P
  • ==SM7675P
  • ==Snapdragon 6 Gen 1 Mobile Platform
  • ==WSA8845
  • ==Snapdragon 662 Mobile Platform
  • ==Snapdragon AR1 Gen 1 Platform
  • ==SRV1M
  • ==WCN7880
  • ==WCD9378C
  • ==Palawan25
  • ==SC8380XP
  • ==Qualcomm Video Collaboration VC1 Platform
  • ==Robotics RB2 Platform
  • ==QXM1083
  • ==QXM1086
  • ==QAMSRV1M
  • ==Netrani
  • ==WCD9340
  • ==WCN3980
  • ==Snapdragon 782G Mobile Platform
  • ==QCS2290
  • ==Snapdragon 6 Gen 3 Mobile Platform
  • ==XRV9209
  • ==Milos
  • ==FastConnect 7800
  • ==Pandeiro
  • ==QCA6595AU
  • ==WSA8832
  • ==SM6650P
  • ==FastConnect 6800
  • ==WCD9370
  • ==QCA6797AQ
  • ==WCN3910
  • ==SA8770P
  • ==WCN7860
  • ==Snapdragon X53 5G Modem-RF System
  • ==Snapdragon 6 Gen 4 Mobile Platform
  • ==IQ9 Series Platform
  • ==WSA8840
  • ==IQ8 Series Platform
  • ==QPA1083BD
  • ==WSA8810
  • ==QLN1083BD
  • ==SW6100
  • ==LeMansAU
  • ==Snapdragon Auto 5G Modem-RF Gen 2
  • ==SA8195P
  • ==SA8255P
  • ==SA6145P
  • ==LeMans_AU_LGIT
  • ==QCA6391
  • ==WCD9380
  • ==QCC710
  • ==SXR2330P
  • ==Snapdragon 870 5G Mobile Platform
  • ==Snapdragon X35 5G Modem-RF System
  • ==QXM1095
  • ==Snapdragon 8 Gen 3 Mobile Platform
  • ==WCN3950
  • ==SA8155P
  • ==WSA8830
  • ==Snapdragon 888 5G Mobile Platform
  • ==SM7435
  • ==XG101032
  • ==QCA6678AQ
  • ==AR8035
  • ==QCA6584AU
  • ==Qualcomm Video Collaboration VC3 Platform
  • ==QCA6174A
  • ==Snapdragon 888+ 5G Mobile Platform
  • ==FastConnect 6700
  • ==G2 Gen 1
  • ==SXR2350P
  • ==QCA6595
  • ==SA7255P
  • ==WCD9385
  • ==QCM6490
  • ==QCA6574
  • ==QCM2290
  • ==QAMSRV1H
  • ==Snapdragon 778G 5G Mobile Platform
  • ==WCN7861
  • ==Snapdragon XR2+ Gen 1 Platform
  • ==QCA6698AQ
  • ==WCD9335
  • ==Snapdragon 7s Gen 3 Mobile Platform
  • ==X2000090
  • ==QCA8081
  • ==X2000086
  • ==QFW7124
  • ==Snapdragon 4 Gen 1 Mobile Platform
  • ==SA8540P
  • ==XRV7209
  • ==SA9000P
  • ==WSA8845H
  • ==QCA6574A
  • ==Snapdragon 480 5G Mobile Platform
  • ==SA8145P
  • ==WCD9395
  • ==QCA8695AU
  • ==Snapdragon 690 5G Mobile Platform
  • ==QXM1094
  • ==CSRA6620
  • ==WCD9390
  • ==QCN6274
  • ==SM7675
  • ==Snapdragon XR2 5G Platform
  • ==FastConnect 6200
  • ==X2000094
  • ==FastConnect 6900
  • ==SRV1L
  • ==QCA6696
  • ==SM8635P
  • ==IQ6 Series Platform
  • ==Snapdragon 865 5G Mobile Platform
  • ==SD865 5G
  • ==QFW7114
  • ==QCA6574AU
  • ==QCA8337
  • ==WCN7881
  • ==WCD9378
  • ==SA7775P
  • ==Themisto
  • ==QCN6224

Matching in nixpkgs

Permalink CVE-2026-35209
7.5 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): High (H)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): None (N)
created 5 months, 2 weeks ago Activity log
  • Created suggestion
defu: Prototype pollution via `__proto__` key in defaults argument

defu is software that allows uers to assign default properties recursively. Prior to version 6.1.5, applications that pass unsanitized user input (e.g. parsed JSON request bodies, database records, or config files from untrusted sources) as the first argument to `defu()` are vulnerable to prototype pollution. A crafted payload containing a `__proto__` key can override intended default values in the merged resul. The internal `_defu` function used `Object.assign({}, defaults)` to copy the defaults object. `Object.assign` invokes the `__proto__` setter, which replaces the resulting object's `[[Prototype]]` with attacker-controlled values. Properties inherited from the polluted prototype then bypass the existing `__proto__` key guard in the `for...in` loop and land in the final result. Version 6.1.5 replaces `Object.assign({}, defaults)` with object spread (`{ ...defaults }`), which uses `[[DefineOwnProperty]]` and does not invoke the `__proto__` setter.

Affected products

defu
  • ==< 6.1.5

Matching in nixpkgs

pkgs.defuddle

Command line utility to extract clean html, markdown and metadata from web pages

  • nixos-unstable -
  • nixos-26.05 -

pkgs.defuddle-cli

Command line utility to extract clean html, markdown and metadata from web pages

  • nixos-unstable -
  • nixos-26.05 -

pkgs.python313Packages.defusedcsv

Python library to protect your users from Excel injections in CSV-format exports, drop-in replacement for standard library's csv module

  • nixos-unstable -
    • nixos-unstable-small 3.0.0
  • nixos-26.05 -
    • nixos-26.05-small 3.0.0

pkgs.python314Packages.defusedcsv

Python library to protect your users from Excel injections in CSV-format exports, drop-in replacement for standard library's csv module

  • nixos-unstable -
    • nixos-unstable-small 3.0.0
  • nixos-26.05 -
    • nixos-26.05-small 3.0.0

Package maintainers

Permalink CVE-2026-5609
8.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Exploit Code Maturity (E): Proof-of-Concept (P)
  • Remediation Level (RL): Not Defined (X)
  • Report Confidence (RC): Reasonable (R)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 5 months, 2 weeks ago Activity log
  • Created suggestion
Tenda i12 Parameter wifiSSIDset formwrlSSIDset stack-based overflow

A flaw has been found in Tenda i12 1.0.0.11(3862). Affected by this vulnerability is the function formwrlSSIDset of the file /goform/wifiSSIDset of the component Parameter Handler. This manipulation of the argument index/wl_radio causes stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been published and may be used.

Affected products

i12
  • ==1.0.0.11(3862)

Matching in nixpkgs

pkgs.xf86videoi128

Number Nine I128 video driver for the Xorg X server

  • nixos-unstable -
    • nixos-unstable-small 1.4.1
  • nixos-26.05 -
    • nixos-26.05-small 1.4.1

pkgs.xf86-video-i128

Number Nine I128 video driver for the Xorg X server

  • nixos-unstable -
    • nixos-unstable-small 1.4.1
  • nixos-26.05 -
    • nixos-26.05-small 1.4.1
created 5 months, 2 weeks ago Activity log
  • Created suggestion
OpenEXR has a signed 32-bit Overflow in PIZ Decoder Leads to OOB Read/Write

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.1.0 to before 3.2.7, 3.3.9, and 3.4.9, internal_exr_undo_piz() advances the working wavelet pointer with signed 32-bit arithmetic. Because nx, ny, and wcount are int, a crafted EXR file can make this product overflow and wrap. The next channel then decodes from an incorrect address. The wavelet decode path operates in place, so this yields both out-of-bounds reads and out-of-bounds writes. This vulnerability is fixed in 3.2.7, 3.3.9, and 3.4.9.

Affected products

openexr
  • ==>= 3.3.0, < 3.3.9
  • ==>= 3.2.0, < 3.2.7
  • ==>= 3.1.0, <= 3.1.13
  • ==>= 3.4.0, < 3.4.9

Matching in nixpkgs

pkgs.openexr

High dynamic-range (HDR) image file format

  • nixos-unstable -
  • nixos-26.05 -

Package maintainers

Permalink CVE-2026-35197
6.6 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): None (N)
created 5 months, 2 weeks ago Activity log
  • Created suggestion
Code injection in dye template expressions

dye is a portable and respectful color library for shell scripts. Prior to 1.1.1, certain dye template expressions would result in execution of arbitrary code. This issue was discovered and fixed by dye's author, and is not known to be exploited. This vulnerability is fixed in 1.1.1.

Affected products

dye
  • ==< 1.1.1

Matching in nixpkgs

pkgs.andyetitmoves

Physics/Gravity Platform game

  • nixos-unstable -
    • nixos-unstable-small 1.2.2
  • nixos-26.05 -
    • nixos-26.05-small 1.2.2

Package maintainers