Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Suggestions search

With package: ncmpcpp

Found 11 matching suggestions

View:
Compact
Detailed
Untriaged
Permalink CVE-2026-13415
7.2 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 1 day, 14 hours ago Activity log
  • Created suggestion
CMP - Coming Soon & Maintenance < 4.1.18 - Editor+ Privilege Escalation via cmp_ajax_import_settings

The CMP WordPress plugin before 4.1.18 does not enforce an option-name allow-list when importing settings via one of its AJAX actions, allowing users with the Editor role (when the administrator has granted the Editor role access to the CMP WordPress plugin before 4.1.18's admin-bar controls) to update arbitrary WordPress options, including options that lead to privilege escalation to Administrator.

References

Affected products

CMP
  • <4.1.18

Matching in nixpkgs

pkgs.cmph

Free minimal perfect hash C library, providing several algorithms in the literature in a consistent, ease to use, API

pkgs.dtcmp

MPI datatype comparison library

pkgs.ncmpc

Curses-based interface for MPD (music player daemon)

  • nixos-unstable 0.52
    • nixpkgs-unstable 0.52
    • nixos-unstable-small 0.54
  • nixos-26.05 0.52
    • nixos-26.05-small 0.52
    • nixpkgs-26.05-darwin 0.52

pkgs.rnxcmp

Compression/restoration of RINEX observation files developed by Y. Hatanaka of GSI

pkgs.critcmp

Command line tool for comparing benchmarks run by Criterion

pkgs.fstrcmp

Make fuzzy comparisons of strings and byte arrays

  • nixos-unstable 0.7
    • nixpkgs-unstable 0.7
    • nixos-unstable-small 0.7
  • nixos-26.05 0.7
    • nixos-26.05-small 0.7
    • nixpkgs-26.05-darwin 0.7

pkgs.scmpuff

Numeric file shortcuts for common git commands

pkgs.luaPackages.nvim-cmp

A completion plugin for neovim

  • nixos-unstable 1
    • nixpkgs-unstable 1
    • nixos-unstable-small 1
  • nixos-26.05 1
    • nixos-26.05-small 1
    • nixpkgs-26.05-darwin 1

pkgs.haskellPackages.funcmp

Functional MetaPost is a Haskell frontend to the MetaPost language

  • nixos-unstable 1.9
    • nixpkgs-unstable 1.9
    • nixos-unstable-small 1.9
  • nixos-26.05 1.9
    • nixos-26.05-small 1.9
    • nixpkgs-26.05-darwin 1.9

pkgs.lua51Packages.nvim-cmp

A completion plugin for neovim

  • nixos-unstable 1
    • nixpkgs-unstable 1
    • nixos-unstable-small 1
  • nixos-26.05 1
    • nixos-26.05-small 1
    • nixpkgs-26.05-darwin 1

pkgs.lua52Packages.nvim-cmp

A completion plugin for neovim

  • nixos-unstable 1
    • nixpkgs-unstable 1
    • nixos-unstable-small 1
  • nixos-26.05 1
    • nixos-26.05-small 1
    • nixpkgs-26.05-darwin 1

pkgs.lua53Packages.nvim-cmp

A completion plugin for neovim

  • nixos-unstable 1
    • nixpkgs-unstable 1
    • nixos-unstable-small 1
  • nixos-26.05 1
    • nixos-26.05-small 1
    • nixpkgs-26.05-darwin 1

pkgs.luajitPackages.nvim-cmp

A completion plugin for neovim

  • nixos-unstable 1
    • nixpkgs-unstable 1
    • nixos-unstable-small 1
  • nixos-26.05 1
    • nixos-26.05-small 1
    • nixpkgs-26.05-darwin 1
Untriaged
Permalink CVE-2026-13414
4.8 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
created 1 day, 14 hours ago Activity log
  • Created suggestion
CMP - Coming Soon & Maintenance < 4.1.18 - Unauthenticated Maintenance Mode Disable via cmp_disable_comingsoon_ajax

The CMP WordPress plugin before 4.1.18 does not perform authorization checks on one of its AJAX actions and relies on a nonce that is skipped for certain (and exposed to anonymous visitors on others), allowing unauthenticated attackers to disable the site's maintenance/coming-soon mode under a non-default countdown configuration.

References

Affected products

CMP
  • <4.1.18

Matching in nixpkgs

pkgs.cmph

Free minimal perfect hash C library, providing several algorithms in the literature in a consistent, ease to use, API

pkgs.dtcmp

MPI datatype comparison library

pkgs.ncmpc

Curses-based interface for MPD (music player daemon)

  • nixos-unstable 0.52
    • nixpkgs-unstable 0.52
    • nixos-unstable-small 0.54
  • nixos-26.05 0.52
    • nixos-26.05-small 0.52
    • nixpkgs-26.05-darwin 0.52

pkgs.rnxcmp

Compression/restoration of RINEX observation files developed by Y. Hatanaka of GSI

pkgs.critcmp

Command line tool for comparing benchmarks run by Criterion

pkgs.fstrcmp

Make fuzzy comparisons of strings and byte arrays

  • nixos-unstable 0.7
    • nixpkgs-unstable 0.7
    • nixos-unstable-small 0.7
  • nixos-26.05 0.7
    • nixos-26.05-small 0.7
    • nixpkgs-26.05-darwin 0.7

pkgs.scmpuff

Numeric file shortcuts for common git commands

pkgs.luaPackages.nvim-cmp

A completion plugin for neovim

  • nixos-unstable 1
    • nixpkgs-unstable 1
    • nixos-unstable-small 1
  • nixos-26.05 1
    • nixos-26.05-small 1
    • nixpkgs-26.05-darwin 1

pkgs.haskellPackages.funcmp

Functional MetaPost is a Haskell frontend to the MetaPost language

  • nixos-unstable 1.9
    • nixpkgs-unstable 1.9
    • nixos-unstable-small 1.9
  • nixos-26.05 1.9
    • nixos-26.05-small 1.9
    • nixpkgs-26.05-darwin 1.9

pkgs.lua51Packages.nvim-cmp

A completion plugin for neovim

  • nixos-unstable 1
    • nixpkgs-unstable 1
    • nixos-unstable-small 1
  • nixos-26.05 1
    • nixos-26.05-small 1
    • nixpkgs-26.05-darwin 1

pkgs.lua52Packages.nvim-cmp

A completion plugin for neovim

  • nixos-unstable 1
    • nixpkgs-unstable 1
    • nixos-unstable-small 1
  • nixos-26.05 1
    • nixos-26.05-small 1
    • nixpkgs-26.05-darwin 1

pkgs.lua53Packages.nvim-cmp

A completion plugin for neovim

  • nixos-unstable 1
    • nixpkgs-unstable 1
    • nixos-unstable-small 1
  • nixos-26.05 1
    • nixos-26.05-small 1
    • nixpkgs-26.05-darwin 1

pkgs.luajitPackages.nvim-cmp

A completion plugin for neovim

  • nixos-unstable 1
    • nixpkgs-unstable 1
    • nixos-unstable-small 1
  • nixos-26.05 1
    • nixos-26.05-small 1
    • nixpkgs-26.05-darwin 1
Untriaged
Permalink CVE-2026-13416
3.5 LOW
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
created 1 day, 14 hours ago Activity log
  • Created suggestion
CMP - Coming Soon & Maintenance < 4.1.18 - Editor+ Stored XSS via niteoCS_socialmedia

The CMP WordPress plugin before 4.1.18 does not sanitise and escape a settings value before outputting it on the coming-soon page, allowing users with the Editor role (when the administrator has granted the Editor role access to the CMP WordPress plugin before 4.1.18's admin-bar controls) to inject arbitrary web scripts that execute when a visitor views the page.

References

Affected products

CMP
  • <4.1.18

Matching in nixpkgs

pkgs.cmph

Free minimal perfect hash C library, providing several algorithms in the literature in a consistent, ease to use, API

pkgs.dtcmp

MPI datatype comparison library

pkgs.ncmpc

Curses-based interface for MPD (music player daemon)

  • nixos-unstable 0.52
    • nixpkgs-unstable 0.52
    • nixos-unstable-small 0.54
  • nixos-26.05 0.52
    • nixos-26.05-small 0.52
    • nixpkgs-26.05-darwin 0.52

pkgs.rnxcmp

Compression/restoration of RINEX observation files developed by Y. Hatanaka of GSI

pkgs.critcmp

Command line tool for comparing benchmarks run by Criterion

pkgs.fstrcmp

Make fuzzy comparisons of strings and byte arrays

  • nixos-unstable 0.7
    • nixpkgs-unstable 0.7
    • nixos-unstable-small 0.7
  • nixos-26.05 0.7
    • nixos-26.05-small 0.7
    • nixpkgs-26.05-darwin 0.7

pkgs.scmpuff

Numeric file shortcuts for common git commands

pkgs.luaPackages.nvim-cmp

A completion plugin for neovim

  • nixos-unstable 1
    • nixpkgs-unstable 1
    • nixos-unstable-small 1
  • nixos-26.05 1
    • nixos-26.05-small 1
    • nixpkgs-26.05-darwin 1

pkgs.haskellPackages.funcmp

Functional MetaPost is a Haskell frontend to the MetaPost language

  • nixos-unstable 1.9
    • nixpkgs-unstable 1.9
    • nixos-unstable-small 1.9
  • nixos-26.05 1.9
    • nixos-26.05-small 1.9
    • nixpkgs-26.05-darwin 1.9

pkgs.lua51Packages.nvim-cmp

A completion plugin for neovim

  • nixos-unstable 1
    • nixpkgs-unstable 1
    • nixos-unstable-small 1
  • nixos-26.05 1
    • nixos-26.05-small 1
    • nixpkgs-26.05-darwin 1

pkgs.lua52Packages.nvim-cmp

A completion plugin for neovim

  • nixos-unstable 1
    • nixpkgs-unstable 1
    • nixos-unstable-small 1
  • nixos-26.05 1
    • nixos-26.05-small 1
    • nixpkgs-26.05-darwin 1

pkgs.lua53Packages.nvim-cmp

A completion plugin for neovim

  • nixos-unstable 1
    • nixpkgs-unstable 1
    • nixos-unstable-small 1
  • nixos-26.05 1
    • nixos-26.05-small 1
    • nixpkgs-26.05-darwin 1

pkgs.luajitPackages.nvim-cmp

A completion plugin for neovim

  • nixos-unstable 1
    • nixpkgs-unstable 1
    • nixos-unstable-small 1
  • nixos-26.05 1
    • nixos-26.05-small 1
    • nixpkgs-26.05-darwin 1
Untriaged
Permalink CVE-2026-16524
7.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 4 weeks, 2 days ago Activity log
  • Created suggestion
Pcp: pcp linux_sockets pmda: arbitrary command execution via command injection

A command injection flaw in PCP's linux_sockets PMDA allows malicious shell metacharacters via the network.persocket.filter metric. This failed validation lets attackers execute arbitrary commands as the PMDA user when metrics refresh.

References

Affected products

pcp
rhcos

Matching in nixpkgs

Package maintainers

Untriaged
Permalink CVE-2026-16529
7.5 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): High (H)
created 4 weeks, 2 days ago Activity log
  • Created suggestion
Pcp: pcp: denial of service due to signed integer overflow

A signed integer overflow in the PCP __pmGetPDU() function can be exploited via crafted network packets during PDU processing or SASL negotiation. This permanently blinds the affected daemon, resulting in a total denial of service (DoS) for subsequent packet reads.

References

Affected products

pcp
rhcos

Matching in nixpkgs

Package maintainers

Untriaged
Permalink CVE-2026-16526
8.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 4 weeks, 2 days ago Activity log
  • Created suggestion
Pcp: pcp: privilege escalation to root via linux_sockets pmda vulnerability

A flaw in the PCP linux_sockets module exposes an unsecured internal connection. An attacker with initial code execution can exploit this to escalate privileges and execute arbitrary commands as root.

References

Affected products

pcp
rhcos

Matching in nixpkgs

Package maintainers

Untriaged
Permalink CVE-2026-16530
6.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): Low (L)
created 4 weeks, 2 days ago Activity log
  • Created suggestion
Pcp: pcp: remote denial of service and information leakage

A flaw was found in the PCP (Performance Co-Pilot) `pmproxy` service. A remote attacker can exploit a vulnerability in the `pmLogLoadInDom()` function by sending a specially crafted request. This bypasses a critical bounds check, which can lead to the `pmproxy` service crashing, causing a Denial of Service (DoS). Additionally, this flaw may enable the leakage of sensitive information from the system's memory.

References

Affected products

pcp
rhcos

Matching in nixpkgs

Package maintainers

Untriaged
Permalink CVE-2026-16527
7.3 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): Low (L)
created 4 weeks, 2 days ago Activity log
  • Created suggestion
Pcp: pcp pmproxy: unauthenticated access to /store endpoint allows bypassing pmcd access rules

An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacker to overwrite any PMDA metric, leading to arbitrary code execution and system takeover.

References

Affected products

pcp
rhcos

Matching in nixpkgs

Package maintainers

Untriaged
Permalink CVE-2026-16531
5.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
created 4 weeks, 2 days ago Activity log
  • Created suggestion
Pcp: pcp: arbitrary file creation via path traversal in pmproxy logger servlet

An unauthenticated remote attacker can exploit a path traversal vulnerability in the PCP pmproxy logger servlet using a crafted hostname. This allows arbitrary file and directory creation, potentially leading to a denial of service.

References

Affected products

pcp
rhcos

Matching in nixpkgs

Package maintainers

Dismissed
Permalink CVE-2024-45770
4.4 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
updated 1 year, 8 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed
Pcp: pmpost symlink attack allows escalating pcp to root user

A vulnerability was found in Performance Co-Pilot (PCP). This flaw can only be exploited if an attacker has access to a compromised PCP system account. The issue is related to the pmpost tool, which is used to log messages in the system. Under certain conditions, it runs with high-level privileges.

References

Affected products

pcp
  • *

Matching in nixpkgs

pkgs.pcp

Command line peer-to-peer data transfer tool based on libp2p

  • nixos-unstable -
    • nixos-unstable-small 0.4.0

pkgs.ncmpcpp

Featureful ncurses based MPD client inspired by ncmpc

  • nixos-unstable -
    • nixos-unstable-small 0.10

pkgs.libamqpcpp

Library for communicating with a RabbitMQ server

  • nixos-unstable -

Package maintainers