Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Suggestions search

With package: lua54Packages.lua-cmsgpack

Found 35 matching suggestions

View:
Compact
Detailed
Untriaged
Permalink CVE-2026-14794
5.3 MEDIUM
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): Low (L)
  • Vulnerable System Impact Integrity (VI): None (N)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Exploit Maturity (E): Not Defined (X)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
  • Modified Vulnerable System Impact Integrity (MVI): None (N)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
created 1 month, 3 weeks ago Activity log
  • Created suggestion
Craft CMS Charts Endpoint ChartsController.php actionGetNewUsersData improper authorization

A flaw has been found in Craft CMS up to 4.18.0.1. Affected by this vulnerability is the function actionGetNewUsersData of the file src/controllers/ChartsController.php of the component Charts Endpoint. This manipulation of the argument userGroupId causes improper authorization. The attack is possible to be carried out remotely. Upgrading to version 4.18.1 addresses this issue. Patch name: 9ee53efc1314e6aba32771c66a13e072a246f4ce. It is suggested to upgrade the affected component.

Affected products

CMS
  • ==4.18.0.0
  • ==4.18.1
  • ==4.18.0.1

Matching in nixpkgs

pkgs.cmst

QT GUI for Connman with system tray icon

pkgs.lcms

Color management engine

  • nixos-unstable -
    • nixos-unstable-small 2.18
  • nixos-26.05 -
    • nixos-26.05-small 2.18

pkgs.lcms1

Color management engine

  • nixos-unstable -
    • nixos-unstable-small 1.19
  • nixos-26.05 -
    • nixos-26.05-small 1.19

pkgs.lcms2

Color management engine

  • nixos-unstable -
    • nixos-unstable-small 2.18
  • nixos-26.05 -
    • nixos-26.05-small 2.18

pkgs.cppcms

High Performance C++ Web Framework

pkgs.xcmsdb

Device Color Characterization utility for X Color Management System

  • nixos-unstable -
    • nixos-unstable-small 1.0.7
  • nixos-26.05 -
    • nixos-26.05-small 1.0.7

pkgs.argyllcms

Color management system (compatible with ICC)

  • nixos-unstable -
    • nixos-unstable-small 3.4.1
  • nixos-26.05 -
    • nixos-26.05-small 3.4.1

pkgs.pcmsolver

API for the Polarizable Continuum Model

  • nixos-unstable -
    • nixos-unstable-small 1.3.0
  • nixos-26.05 -
    • nixos-26.05-small 1.3.0
Untriaged
Permalink CVE-2026-14801
4.8 MEDIUM
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): None (N)
  • Vulnerable System Impact Integrity (VI): None (N)
  • Vulnerable System Impact Availability (VA): Low (L)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Exploit Maturity (E): Not Defined (X)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): None (N)
  • Modified Vulnerable System Impact Integrity (MVI): None (N)
  • Modified Vulnerable System Impact Availability (MVA): Low (L)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
created 1 month, 3 weeks ago Activity log
  • Created suggestion
GPAC TeXML File load_text.c txtin_probe_duration divide by zero

A security vulnerability has been detected in GPAC 26.03-DEV-rev342-g80071f700-master. The impacted element is the function txtin_probe_duration of the file src/filters/load_text.c of the component TeXML File Handler. Such manipulation of the argument txml_timescale leads to divide by zero. An attack has to be approached locally. The name of the patch is 86a5191f2e750c767253e27ed6cfd6d547afebc2. A patch should be applied to remediate this issue.

Affected products

GPAC
  • ==26.03-DEV-rev342-g80071f700-master

Matching in nixpkgs

pkgs.gpac

Open Source multimedia framework for research and academic purposes

  • nixos-unstable -
  • nixos-26.05 -

pkgs.msgpack-c

MessagePack implementation for C

  • nixos-unstable -
    • nixos-unstable-small 7.0.1
  • nixos-26.05 -
    • nixos-26.05-small 6.1.0

pkgs.msgpack-cxx

MessagePack implementation for C++

  • nixos-unstable -
    • nixos-unstable-small 7.0.0
  • nixos-26.05 -
    • nixos-26.05-small 7.0.0

pkgs.msgpack-tools

Command-line tools for converting between MessagePack and JSON

  • nixos-unstable -
    • nixos-unstable-small 0.6
  • nixos-26.05 -
    • nixos-26.05-small 0.6

pkgs.phpExtensions.msgpack

PHP extension for interfacing with MessagePack

  • nixos-unstable -
    • nixos-unstable-small 3.0.0
  • nixos-26.05 -
    • nixos-26.05-small 3.0.0
Untriaged
Permalink CVE-2025-15668
1.9 LOW
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): None (N)
  • Vulnerable System Impact Integrity (VI): None (N)
  • Vulnerable System Impact Availability (VA): Low (L)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Exploit Maturity (E): POC (P)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): None (N)
  • Modified Vulnerable System Impact Integrity (MVI): None (N)
  • Modified Vulnerable System Impact Availability (MVA): Low (L)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
created 1 month, 3 weeks ago Activity log
  • Created suggestion
GPAC MP4Box box_code_base.c sgpd_del_entry heap-based overflow

A vulnerability was identified in GPAC up to b40ce70f5. This issue affects the function sgpd_del_entry of the file src/isomedia/box_code_base.c of the component MP4Box. Such manipulation of the argument data leads to heap-based buffer overflow. Local access is required to approach this attack. The exploit is publicly available and might be used. The name of the patch is f29f955f2a3b5e8e507caad3e52319f961bf37bf. It is advisable to implement a patch to correct this issue.

Affected products

GPAC
  • ==b40ce70f5

Matching in nixpkgs

pkgs.gpac

Open Source multimedia framework for research and academic purposes

  • nixos-unstable -
  • nixos-26.05 -

pkgs.msgpack-c

MessagePack implementation for C

  • nixos-unstable -
    • nixos-unstable-small 7.0.1
  • nixos-26.05 -
    • nixos-26.05-small 6.1.0

pkgs.msgpack-cxx

MessagePack implementation for C++

  • nixos-unstable -
    • nixos-unstable-small 7.0.0
  • nixos-26.05 -
    • nixos-26.05-small 7.0.0

pkgs.msgpack-tools

Command-line tools for converting between MessagePack and JSON

  • nixos-unstable -
    • nixos-unstable-small 0.6
  • nixos-26.05 -
    • nixos-26.05-small 0.6

pkgs.phpExtensions.msgpack

PHP extension for interfacing with MessagePack

  • nixos-unstable -
    • nixos-unstable-small 3.0.0
  • nixos-26.05 -
    • nixos-26.05-small 3.0.0
Untriaged
Permalink CVE-2026-50281
7.1 HIGH
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): None (N)
  • Vulnerable System Impact Integrity (VI): High (H)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): None (N)
  • Modified Vulnerable System Impact Integrity (MVI): High (H)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 1 month, 3 weeks ago Activity log
  • Created suggestion
Craft CMS: Mass assignment via id in newAttributes during bulk duplicate overwrites existing elements

Craft CMS is a content management system (CMS). Versions 5.7.0 and above, prior to 5.9.21 contain a mass-assignment flaw in the bulk-duplicate element action. An attacker who is only able to duplicate their own entires can submit an arbitrary id through the newAttributes request parameter. The duplication routine overrides its own id = null reset with that value and writes the attacker's attributes into the victim's existing entry row. ElementsController::beforeAction() pulls the request body into $this->_attributes and rejects requests that ship an id or canonicalId key at the top level, actionBulkDuplicate(), reads a separate newAttributes array and passes it straight through to the service layer. Elements::duplicateElement() clones the source element, sets id to null, and then hands the attacker's array to Craft::configure(), which overwrites the reset id with any numeric value inside $newAttributes. PHP Yii's saveElement() then performs an UPDATE against the row with that primary key instead of an INSERT. The attackers's title, slug, authorId, postDate, and UID land on the victim's entry. safeAttributes() on Entry includes id because the base element model exposes it, so the Collection::only() filter does not strip it. This issue has been fixed in version 5.9.21.

Affected products

cms
  • ==>= 5.7.0, < 5.9.21

Matching in nixpkgs

pkgs.cmst

QT GUI for Connman with system tray icon

pkgs.lcms

Color management engine

  • nixos-unstable -
    • nixos-unstable-small 2.18
  • nixos-26.05 -
    • nixos-26.05-small 2.18

pkgs.lcms1

Color management engine

  • nixos-unstable -
    • nixos-unstable-small 1.19
  • nixos-26.05 -
    • nixos-26.05-small 1.19

pkgs.lcms2

Color management engine

  • nixos-unstable -
    • nixos-unstable-small 2.18
  • nixos-26.05 -
    • nixos-26.05-small 2.18

pkgs.cppcms

High Performance C++ Web Framework

pkgs.xcmsdb

Device Color Characterization utility for X Color Management System

  • nixos-unstable -
    • nixos-unstable-small 1.0.7
  • nixos-26.05 -
    • nixos-26.05-small 1.0.7

pkgs.argyllcms

Color management system (compatible with ICC)

  • nixos-unstable -
    • nixos-unstable-small 3.4.1
  • nixos-26.05 -
    • nixos-26.05-small 3.4.1

pkgs.pcmsolver

API for the Polarizable Continuum Model

  • nixos-unstable -
    • nixos-unstable-small 1.3.0
  • nixos-26.05 -
    • nixos-26.05-small 1.3.0
Untriaged
Permalink CVE-2026-50282
4.9 MEDIUM
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): None (N)
  • Vulnerable System Impact Integrity (VI): High (H)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Exploit Maturity (E): Unreported (U)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): None (N)
  • Modified Vulnerable System Impact Integrity (MVI): High (H)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
created 1 month, 3 weeks ago Activity log
  • Created suggestion
Craft CMS: Unauthorized Deletion of Destination Folders During Forced Moves

Craft CMS is a content management system (CMS). Versions 5.0.0-RC1 and above, prior to 5.9.21 and versions 4.0.0-RC1 and above prior to 4.17.14 contain an authorization issue where a forced folder move can delete a conflicting destination folder without destination delete permission. Function craft\\controllers\\AssetsController::actionMoveFolder() supports moving an asset folder into a destination parent folder. If a folder with the same name already exists at the destination, the action can be called with force=true to overwrite the destination. This issue has been resolved in versions 5.9.21 and 4.17.14.

Affected products

cms
  • ==>= 4.0.0-RC1, <= 4.17.14
  • ==>= 5.0.0-RC1, < 5.9.21

Matching in nixpkgs

pkgs.cmst

QT GUI for Connman with system tray icon

pkgs.lcms

Color management engine

  • nixos-unstable -
    • nixos-unstable-small 2.18
  • nixos-26.05 -
    • nixos-26.05-small 2.18

pkgs.lcms1

Color management engine

  • nixos-unstable -
    • nixos-unstable-small 1.19
  • nixos-26.05 -
    • nixos-26.05-small 1.19

pkgs.lcms2

Color management engine

  • nixos-unstable -
    • nixos-unstable-small 2.18
  • nixos-26.05 -
    • nixos-26.05-small 2.18

pkgs.cppcms

High Performance C++ Web Framework

pkgs.xcmsdb

Device Color Characterization utility for X Color Management System

  • nixos-unstable -
    • nixos-unstable-small 1.0.7
  • nixos-26.05 -
    • nixos-26.05-small 1.0.7

pkgs.argyllcms

Color management system (compatible with ICC)

  • nixos-unstable -
    • nixos-unstable-small 3.4.1
  • nixos-26.05 -
    • nixos-26.05-small 3.4.1

pkgs.pcmsolver

API for the Polarizable Continuum Model

  • nixos-unstable -
    • nixos-unstable-small 1.3.0
  • nixos-26.05 -
    • nixos-26.05-small 1.3.0