Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Suggestions search

With package: gpd-pocket-4-pipewire

Found 4 matching suggestions

View:
Compact
Detailed
Permalink CVE-2026-82090
9.2 CRITICAL
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): Present (P)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): High (H)
  • Vulnerable System Impact Integrity (VI): High (H)
  • Vulnerable System Impact Availability (VA): High (H)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): Present (P)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): High (H)
  • Modified Vulnerable System Impact Integrity (MVI): High (H)
  • Modified Vulnerable System Impact Availability (MVA): High (H)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 2 days, 1 hour ago Activity log
  • Created suggestion
Pocket through 8.33.0.0 allows XSS because "Save to Pocket" injects …

Pocket through 8.33.0.0 allows XSS because "Save to Pocket" injects external HTML into the DOM.  JavaScript code can alter the application state via native bridge methods.

References

Affected products

com.ideashower.readitlater.pro
  • =<8.33.0.0

Matching in nixpkgs

pkgs.pocket-tts

Lightweight text-to-speech (TTS) application designed to run efficiently on CPUs

pkgs.pkgsRocm.pocket-tts

Lightweight text-to-speech (TTS) application designed to run efficiently on CPUs

Permalink CVE-2026-5674
8.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 1 month, 1 week ago Activity log
  • Created suggestion
Pipewire: pipewire: sandbox escape and arbitrary code execution via malicious library loading

A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed applications, such as Flatpak, by exploiting PipeWire's PulseAudio compatibility layer. An attacker with minimal permissions within a sandboxed environment can load a malicious library, leading to arbitrary code execution outside the sandbox and potential compromise of the user's system.

References

Affected products

firefox
libkrun
pipewire
pipewire0.2

Matching in nixpkgs

pkgs.libkrun

Dynamic library providing Virtualization-based process isolation capabilities

pkgs.pipewire

Server and user space API to deal with multimedia pipelines

pkgs.libkrunfw

Dynamic library bundling the guest payload consumed by libkrun

pkgs.libkrun-efi

EFI variant of Libkrun, a dynamic library providing Virtualization-based process isolation capabilities

pkgs.libkrun-sev

Dynamic library providing Virtualization-based process isolation capabilities

pkgs.libkrun-tdx

Dynamic library providing Virtualization-based process isolation capabilities

pkgs.faust2firefox

The faust2firefox script, part of faust functional programming language for realtime audio signal processing

pkgs.firefox_decrypt

Tool to extract passwords from profiles of Mozilla Firefox and derivates

pkgs.firefox-devtools-mcp

Model Context Protocol server for Firefox DevTools automation

  • nixos-unstable -
    • nixos-unstable-small 0.9.9

pkgs.gnomeExtensions.firefox-profiles

Easily launch Firefox with your favorite profile right from the indicator menu!

  • nixos-unstable 7
    • nixpkgs-unstable 7
    • nixos-unstable-small 7
  • nixos-26.05 7
    • nixos-26.05-small 7
    • nixpkgs-26.05-darwin 7

pkgs.gnomeExtensions.pipewire-settings

Top bar menu to set Pipewire's buffer size and samplerate

  • nixos-unstable 9
    • nixpkgs-unstable 9
    • nixos-unstable-small 9
  • nixos-26.05 9
    • nixos-26.05-small 9
    • nixpkgs-26.05-darwin 9

pkgs.gnomeExtensions.pipewire-airplay-toggle

Quick Setting menu toggle to enable/disable the RAOP Discover Module in PipeWire, allowing users to quickly and easily show or hide their AirPlay enabled speakers. This extension now also supports PulseAudio starting from version 8. For full details and dependency information, please review the GitHub repository wiki.

  • nixos-unstable 12
    • nixpkgs-unstable 12
    • nixos-unstable-small 12
  • nixos-26.05 12
    • nixos-26.05-small 12
    • nixpkgs-26.05-darwin 12

pkgs.gnomeExtensions.firefox-pip-always-on-top

Automatically sets Picture-in-Picture windows to always be on top and visible on all workspaces

  • nixos-unstable 4
    • nixpkgs-unstable 4
    • nixos-unstable-small 4
  • nixos-26.05 4
    • nixos-26.05-small 4
    • nixpkgs-26.05-darwin 4

Package maintainers

Permalink CVE-2026-14330
5.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): High (H)
created 1 month, 4 weeks ago Activity log
  • Created suggestion
Pipewire: pulse server alloca stack overflow

Multiple unbounded alloca() calls in the PulseAudio protocol server.

References

Affected products

libkrun
pipewire
pipewire0.2

Matching in nixpkgs

pkgs.libkrun

Dynamic library providing Virtualization-based process isolation capabilities

  • nixos-unstable -
  • nixos-26.05 -

pkgs.pipewire

Server and user space API to deal with multimedia pipelines

  • nixos-unstable -
    • nixos-unstable-small 1.6.5
  • nixos-26.05 -
    • nixos-26.05-small 1.6.5

pkgs.libkrunfw

Dynamic library bundling the guest payload consumed by libkrun

  • nixos-unstable -
    • nixos-unstable-small 5.5.0
  • nixos-26.05 -
    • nixos-26.05-small 5.3.0

pkgs.libkrun-efi

EFI variant of Libkrun, a dynamic library providing Virtualization-based process isolation capabilities

  • nixos-unstable -
  • nixos-26.05 -

pkgs.libkrun-sev

Dynamic library providing Virtualization-based process isolation capabilities

  • nixos-unstable -
  • nixos-26.05 -

pkgs.libkrun-tdx

Dynamic library providing Virtualization-based process isolation capabilities

  • nixos-unstable -
  • nixos-26.05 -

pkgs.kdePackages.kpipewire

Components relating to Flatpak 'pipewire' use in Plasma.

  • nixos-unstable -
    • nixos-unstable-small 6.7.0
  • nixos-26.05 -
    • nixos-26.05-small 6.6.5

pkgs.wayland-pipewire-idle-inhibit

Suspends automatic idling of Wayland compositors when media is being played through Pipewire

  • nixos-unstable -
    • nixos-unstable-small 0.7.1
  • nixos-26.05 -
    • nixos-26.05-small 0.7.1

pkgs.gnomeExtensions.pipewire-airplay-toggle

Quick Setting menu toggle to enable/disable the RAOP Discover Module in PipeWire, allowing users to quickly and easily show or hide their AirPlay enabled speakers. This extension now also supports PulseAudio starting from version 8. For full details and dependency information, please review the GitHub repository wiki.

  • nixos-unstable -
    • nixos-unstable-small 12
  • nixos-26.05 -
    • nixos-26.05-small 12
Permalink CVE-2026-14324
6.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Adjacent (A)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Adjacent (A)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): High (H)
created 1 month, 4 weeks ago Activity log
  • Created suggestion
Pipewire: raop rtsp null deref

RAOP module accepts unbounded Content-Length values and does not check the pw_array_add() return.

References

Affected products

libkrun
pipewire
pipewire0.2

Matching in nixpkgs

pkgs.libkrun

Dynamic library providing Virtualization-based process isolation capabilities

  • nixos-unstable -
  • nixos-26.05 -

pkgs.pipewire

Server and user space API to deal with multimedia pipelines

  • nixos-unstable -
    • nixos-unstable-small 1.6.5
  • nixos-26.05 -
    • nixos-26.05-small 1.6.5

pkgs.libkrunfw

Dynamic library bundling the guest payload consumed by libkrun

  • nixos-unstable -
    • nixos-unstable-small 5.5.0
  • nixos-26.05 -
    • nixos-26.05-small 5.3.0

pkgs.libkrun-efi

EFI variant of Libkrun, a dynamic library providing Virtualization-based process isolation capabilities

  • nixos-unstable -
  • nixos-26.05 -

pkgs.libkrun-sev

Dynamic library providing Virtualization-based process isolation capabilities

  • nixos-unstable -
  • nixos-26.05 -

pkgs.libkrun-tdx

Dynamic library providing Virtualization-based process isolation capabilities

  • nixos-unstable -
  • nixos-26.05 -

pkgs.kdePackages.kpipewire

Components relating to Flatpak 'pipewire' use in Plasma.

  • nixos-unstable -
    • nixos-unstable-small 6.7.0
  • nixos-26.05 -
    • nixos-26.05-small 6.6.5

pkgs.wayland-pipewire-idle-inhibit

Suspends automatic idling of Wayland compositors when media is being played through Pipewire

  • nixos-unstable -
    • nixos-unstable-small 0.7.1
  • nixos-26.05 -
    • nixos-26.05-small 0.7.1

pkgs.gnomeExtensions.pipewire-airplay-toggle

Quick Setting menu toggle to enable/disable the RAOP Discover Module in PipeWire, allowing users to quickly and easily show or hide their AirPlay enabled speakers. This extension now also supports PulseAudio starting from version 8. For full details and dependency information, please review the GitHub repository wiki.

  • nixos-unstable -
    • nixos-unstable-small 12
  • nixos-26.05 -
    • nixos-26.05-small 12