Nixpkgs security tracker

Try the new UI
Login with GitHub

Automatically generated suggestions

to slate a suggestion for refinement.

to mark a suggestion as irrelevant and log the reason.

View:
Compact
Detailed
Permalink CVE-2026-35536
7.2 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
updated 2 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    7 packages
    • python312Packages.pytest-tornado
    • python312Packages.sockjs-tornado
    • python314Packages.tornado
    • python313Packages.pytest-tornado
    • python314Packages.sockjs-tornado
    • python314Packages.pytest-tornado
    • python313Packages.sockjs-tornado
  • @LeSuisse restored package python314Packages.tornado
In Tornado before 6.5.5, cookie attribute injection could occur because …

In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.

Affected products

Tornado
  • <6.5.5

Matching in nixpkgs

Ignored packages (4)

pkgs.python313Packages.pytest-tornado

Py.test plugin providing fixtures and markers to simplify testing of asynchronous tornado applications

  • nixos-unstable -
    • nixos-unstable-small 0.8.1
  • nixos-26.05 -
    • nixos-26.05-small 0.8.1

pkgs.python314Packages.pytest-tornado

Py.test plugin providing fixtures and markers to simplify testing of asynchronous tornado applications

  • nixos-unstable -
    • nixos-unstable-small 0.8.1
  • nixos-26.05 -
    • nixos-26.05-small 0.8.1
created 5 months, 2 weeks ago Activity log
  • Created suggestion
Discourse: Hidden tag visibility bypass on tag routes

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, an authorization bypass vulnerability allows unauthenticated or unauthorized users to view hidden (staff-only) tags and its associated data. All Discourse instances with tagging enabled and staff-only tag groups configured are impacted. This issue has been patched in versions 2026.1.3, 2026.2.2, and 2026.3.0.

Affected products

discourse
  • ==>= 2026.3.0-latest, < 2026.3.0
  • ==>= 2026.2.0-latest, < 2026.2.2
  • ==>= 2026.1.0-latest, < 2026.1.3

Matching in nixpkgs

pkgs.discourse

Open source discussion platform

  • nixos-unstable -
  • nixos-26.05 -

pkgs.discourse-mail-receiver

Helper program which receives incoming mail for Discourse

  • nixos-unstable -
    • nixos-unstable-small 4.1.0
  • nixos-26.05 -
    • nixos-26.05-small 4.1.0

Package maintainers

created 5 months, 2 weeks ago Activity log
  • Created suggestion
Discourse: Staged user custom fields are exposed on public invite pages

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, staged user custom fields and username are exposed on public invite pages without email verification. This issue has been patched in versions 2026.1.3, 2026.2.2, and 2026.3.0.

Affected products

discourse
  • ==>= 2026.3.0-latest, < 2026.3.0
  • ==>= 2026.2.0-latest, < 2026.2.2
  • ==>= 2026.1.0-latest, < 2026.1.3

Matching in nixpkgs

pkgs.discourse

Open source discussion platform

  • nixos-unstable -
  • nixos-26.05 -

pkgs.discourse-mail-receiver

Helper program which receives incoming mail for Discourse

  • nixos-unstable -
    • nixos-unstable-small 4.1.0
  • nixos-26.05 -
    • nixos-26.05-small 4.1.0

Package maintainers

Permalink CVE-2026-5484
5.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Exploit Code Maturity (E): Proof-of-Concept (P)
  • Remediation Level (RL): Official Fix (O)
  • Report Confidence (RC): Confirmed (C)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
created 5 months, 2 weeks ago Activity log
  • Created suggestion
BookStackApp BookStack Chapter Export ExportFormatter.php chapterToMarkdown access control

A weakness has been identified in BookStackApp BookStack up to 26.03. Affected is the function chapterToMarkdown of the file app/Exports/ExportFormatter.php of the component Chapter Export Handler. Executing a manipulation of the argument pages can lead to improper access controls. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 26.03.1 is able to address this issue. This patch is called 8a59895ba063040cc8dafd82e94024c406df3d04. It is advisable to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

Affected products

BookStack
  • ==26.03
  • ==26.03.1

Matching in nixpkgs

pkgs.bookstack

Platform to create documentation/wiki content built with PHP & Laravel

  • nixos-unstable -
  • nixos-26.05 -

Package maintainers

Permalink CVE-2026-34607
7.2 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 5 months, 2 weeks ago Activity log
  • Created suggestion
Emlog: Path Traversal in emUnZip() allows arbitrary file write leading to RCE

Emlog is an open source website building system. In versions 2.6.2 and prior, a path traversal vulnerability exists in the emUnZip() function (include/lib/common.php:793). When extracting ZIP archives (plugin/template uploads, backup imports), the function calls $zip->extractTo($path) without sanitizing ZIP entry names. An authenticated admin can upload a crafted ZIP containing entries with ../ sequences to write arbitrary files to the server filesystem, including PHP webshells, achieving Remote Code Execution (RCE). At time of publication, there are no publicly available patches.

Affected products

emlog
  • ==<= 2.6.2

Matching in nixpkgs

Package maintainers

Permalink CVE-2026-5473
4.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): Low (L)
  • Exploit Code Maturity (E): Proof-of-Concept (P)
  • Remediation Level (RL): Not Defined (X)
  • Report Confidence (RC): Reasonable (R)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): Low (L)
created 5 months, 2 weeks ago Activity log
  • Created suggestion
NASA cFS Pickle pickle.load deserialization

A vulnerability has been found in NASA cFS up to 7.0.0. The impacted element is the function pickle.load of the component Pickle Module. Such manipulation leads to deserialization. The attack needs to be performed locally. The attack requires a high level of complexity. The exploitability is regarded as difficult. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Affected products

cFS
  • ==7.0

Matching in nixpkgs

pkgs.cfssl

Cloudflare's PKI and TLS toolkit

  • nixos-unstable -
    • nixos-unstable-small 1.6.5
  • nixos-26.05 -
    • nixos-26.05-small 1.6.5

pkgs.cpcfs

Manipulating CPC dsk images and files

  • nixos-unstable -
  • nixos-26.05 -

pkgs.encfs

None

  • nixos-26.05 -
    • nixos-26.05-small 1.9.5

pkgs.lxcfs

FUSE filesystem for LXC

  • nixos-unstable -
    • nixos-unstable-small 7.0.0
  • nixos-26.05 -
    • nixos-26.05-small 7.0.0

pkgs.gencfsm

None

  • nixos-26.05 -
    • nixos-26.05-small 1.9

pkgs.cfspeedtest

Unofficial CLI for speed.cloudflare.com

  • nixos-unstable -
    • nixos-unstable-small 2.2.2
  • nixos-26.05 -
    • nixos-26.05-small 2.2.2

pkgs.cfs-zen-tweaks

Tweak Linux CPU scheduler for desktop responsiveness

  • nixos-unstable -
    • nixos-unstable-small 1.3.0
  • nixos-26.05 -
    • nixos-26.05-small 1.3.0

pkgs.ocamlPackages.cfstream

Simple Core-inspired wrapper for standard library Stream module

  • nixos-unstable -
    • nixos-unstable-small 1.3.2
  • nixos-26.05 -
    • nixos-26.05-small 1.3.2
Permalink CVE-2026-35545
5.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
created 5 months, 2 weeks ago Activity log
  • Created suggestion
An issue was discovered in Roundcube Webmail before 1.5.15 and …

An issue was discovered in Roundcube Webmail before 1.5.15 and 1.6.15. The remote image blocking feature can be bypassed via SVG content in an e-mail message. This may lead to information disclosure or access-control bypass. This involves the animate element with attributeName=fill/filter/stroke.

Affected products

Webmail
  • <1.6.15
  • <1.5.15

Matching in nixpkgs

pkgs.ayatana-webmail

Webmail notifications and actions for any desktop

  • nixos-unstable -
  • nixos-26.05 -

Package maintainers

Permalink CVE-2026-34824
7.5 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): High (H)
created 5 months, 2 weeks ago Activity log
  • Created suggestion
Mesop: Unbounded Thread Creation in WebSocket Handler Leads to Denial of Service

Mesop is a Python-based UI framework that allows users to build web applications. From version 1.2.3 to before version 1.2.5, an uncontrolled resource consumption vulnerability exists in the WebSocket implementation of the Mesop framework. An unauthenticated attacker can send a rapid succession of WebSocket messages, forcing the server to spawn an unbounded number of operating system threads. This leads to thread exhaustion and Out of Memory (OOM) errors, causing a complete Denial of Service (DoS) for any application built on the framework. This issue has been patched in version 1.2.5.

Affected products

mesop
  • ==>= 1.2.3, < 1.2.5

Matching in nixpkgs

pkgs.m2-mesoplanet

Macro Expander Saving Our m2-PLANET

  • nixos-unstable -
  • nixos-26.05 -
Permalink CVE-2026-34770
7.0 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 5 months, 2 weeks ago Activity log
  • Created suggestion
Electron: Use-after-free in PowerMonitor on Windows and macOS

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8, apps that use the powerMonitor module may be vulnerable to a use-after-free. After the native PowerMonitor object is garbage-collected, the associated OS-level resources (a message window on Windows, a shutdown handler on macOS) retain dangling references. A subsequent session-change event (Windows) or system shutdown (macOS) dereferences freed memory, which may lead to a crash or memory corruption. All apps that access powerMonitor events (suspend, resume, lock-screen, etc.) are potentially affected. The issue is not directly renderer-controllable. This issue has been patched in versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8.

Affected products

electron
  • ==>= 41.0.0-alpha.1, < 41.0.0-beta.8
  • ==< 38.8.6
  • ==>= 39.0.0-alpha.1, < 39.8.1
  • ==>= 40.0.0-alpha.1, < 40.8.0

Matching in nixpkgs

pkgs.electron

Cross platform desktop application shell

  • nixos-unstable -
  • nixos-26.05 -

pkgs.electron_39

Cross platform desktop application shell

  • nixos-unstable -
  • nixos-26.05 -

pkgs.electron_40

Cross platform desktop application shell

  • nixos-unstable -
  • nixos-26.05 -

pkgs.electron_41

Cross platform desktop application shell

  • nixos-unstable -
  • nixos-26.05 -

pkgs.electron_42

Cross platform desktop application shell

  • nixos-unstable -
  • nixos-26.05 -

pkgs.electron_43

Cross platform desktop application shell

  • nixos-unstable -
  • nixos-26.05 -

pkgs.electron_44

Cross platform desktop application shell

  • nixos-unstable -

pkgs.electron-bin

Cross platform desktop application shell

  • nixos-unstable -
  • nixos-26.05 -

pkgs.electron-cash

Bitcoin Cash SPV Wallet

  • nixos-unstable -
    • nixos-unstable-small 4.4.6
  • nixos-26.05 -
    • nixos-26.05-small 4.4.2

pkgs.electron-mail

Unofficial Election-based ProtonMail desktop client

  • nixos-unstable -
    • nixos-unstable-small 5.3.8
  • nixos-26.05 -
    • nixos-26.05-small 5.3.8

pkgs.electron-fiddle

Easiest way to get started with Electron

  • nixos-unstable -
  • nixos-26.05 -

pkgs.electron_39-bin

Cross platform desktop application shell

  • nixos-unstable -
  • nixos-26.05 -

pkgs.electron_40-bin

Cross platform desktop application shell

  • nixos-unstable -
  • nixos-26.05 -

pkgs.electron_41-bin

Cross platform desktop application shell

  • nixos-unstable -
  • nixos-26.05 -

pkgs.electron_42-bin

Cross platform desktop application shell

  • nixos-unstable -
  • nixos-26.05 -

pkgs.electron_43-bin

Cross platform desktop application shell

  • nixos-unstable -
  • nixos-26.05 -

pkgs.electron_44-bin

Cross platform desktop application shell

  • nixos-unstable -

pkgs.notion-electron

Enhanced Notion Desktop client for Linux

  • nixos-unstable -
    • nixos-unstable-small 2.4.0

pkgs.electron-chromedriver

WebDriver server for running Selenium tests on Chrome

  • nixos-unstable -
  • nixos-26.05 -
Permalink CVE-2026-34769
7.7 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 5 months, 2 weeks ago Activity log
  • Created suggestion
Electron: Renderer command-line switch injection via undocumented commandLineSwitches webPreference

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8, an undocumented commandLineSwitches webPreference allowed arbitrary switches to be appended to the renderer process command line. Apps that construct webPreferences by spreading untrusted configuration objects may inadvertently allow an attacker to inject switches that disable renderer sandboxing or web security controls. Apps are only affected if they construct webPreferences from external or untrusted input without an allowlist. Apps that use a fixed, hardcoded webPreferences object are not affected. This issue has been patched in versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8.

Affected products

electron
  • ==< 38.8.6
  • ==>= 39.0.0-alpha.1, < 39.8.0
  • ==>= 40.0.0-alpha.1, < 40.7.0
  • ==>= 41.0.0-alpha.1, < 41.0.0-beta.8

Matching in nixpkgs

pkgs.electron

Cross platform desktop application shell

  • nixos-unstable -
  • nixos-26.05 -

pkgs.electron_39

Cross platform desktop application shell

  • nixos-unstable -
  • nixos-26.05 -

pkgs.electron_40

Cross platform desktop application shell

  • nixos-unstable -
  • nixos-26.05 -

pkgs.electron_41

Cross platform desktop application shell

  • nixos-unstable -
  • nixos-26.05 -

pkgs.electron_42

Cross platform desktop application shell

  • nixos-unstable -
  • nixos-26.05 -

pkgs.electron_43

Cross platform desktop application shell

  • nixos-unstable -
  • nixos-26.05 -

pkgs.electron_44

Cross platform desktop application shell

  • nixos-unstable -

pkgs.electron-bin

Cross platform desktop application shell

  • nixos-unstable -
  • nixos-26.05 -

pkgs.electron-cash

Bitcoin Cash SPV Wallet

  • nixos-unstable -
    • nixos-unstable-small 4.4.6
  • nixos-26.05 -
    • nixos-26.05-small 4.4.2

pkgs.electron-mail

Unofficial Election-based ProtonMail desktop client

  • nixos-unstable -
    • nixos-unstable-small 5.3.8
  • nixos-26.05 -
    • nixos-26.05-small 5.3.8

pkgs.electron-fiddle

Easiest way to get started with Electron

  • nixos-unstable -
  • nixos-26.05 -

pkgs.electron_39-bin

Cross platform desktop application shell

  • nixos-unstable -
  • nixos-26.05 -

pkgs.electron_40-bin

Cross platform desktop application shell

  • nixos-unstable -
  • nixos-26.05 -

pkgs.electron_41-bin

Cross platform desktop application shell

  • nixos-unstable -
  • nixos-26.05 -

pkgs.electron_42-bin

Cross platform desktop application shell

  • nixos-unstable -
  • nixos-26.05 -

pkgs.electron_43-bin

Cross platform desktop application shell

  • nixos-unstable -
  • nixos-26.05 -

pkgs.electron_44-bin

Cross platform desktop application shell

  • nixos-unstable -

pkgs.notion-electron

Enhanced Notion Desktop client for Linux

  • nixos-unstable -
    • nixos-unstable-small 2.4.0

pkgs.electron-chromedriver

WebDriver server for running Selenium tests on Chrome

  • nixos-unstable -
  • nixos-26.05 -