Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Dismissed suggestions

These automatic suggestions were dismissed after initial triaging.

to select a suggestion for revision.

View:
Compact
Detailed
Dismissed
(no matching packages found)
Permalink CVE-2026-8470
7.4 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Langflow is affected by weaknesses in secret handling and sensitive configuration access

IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 use Python's non-cryptographic random module for generating Fernet encryption keys from user secrets under 32 characters. The deterministic Mersenne Twister PRNG produces identical keys for identical seeds, allowing attackers to reproduce encryption keys and decrypt stored API keys and authentication tokens.

References

Affected products

Langflow OSS
  • =<1.10.3
Dismissed
(no matching packages found)
Permalink CVE-2026-16605
7.2 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
MultiVendorX < 5.0.11 - Store Owner+ Cross-Vendor Store Takeover and Deletion via Missing Authorization

The MultiVendorX WordPress plugin before 5.0.11 does not verify that the store targeted through its REST API belongs to the requesting vendor, allowing an authenticated vendor (Store Owner and above) to view, take over, permanently delete, or modify any other vendor's store on the marketplace.

References

Affected products

MultiVendorX
  • <5.0.11
Dismissed
(no matching packages found)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
PathTravelsal Vulnerability in com.talpa.hibrowser

Path Traversal in Download File Feature in com.talpa.hibrowser 2.23.1.1 on Android allows arbitrary file write via directory traversal sequences in the filename.

Affected products

com.talpa.hibrowser
  • ==2.23.1.1
Dismissed
(no matching packages found)
Permalink CVE-2026-20268
8.6 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): High (H)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Cisco IOS XE Software Security Hardening Release

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20268 are related to issues with improper restriction of operations within the bounds of a memory buffer that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-119.

Affected products

Cisco IOS XE Software
  • ==17.15.1y
  • ==17.3.1x
  • ==16.12.1z1
  • ==16.6.5b
  • ==16.12.9
  • ==16.9.2s
  • ==16.12.1s
  • ==17.18.1
  • ==17.15.4
  • ==16.6.5
  • ==17.12.1z2
  • ==17.12.1x
  • ==16.9.3h
  • ==16.9.7
  • ==17.1.2
  • ==16.8.1a
  • ==17.12.5
  • ==17.12.4b
  • ==17.7.1a
  • ==17.2.1
  • ==16.7.1
  • ==16.10.1a
  • ==16.12.4
  • ==17.3.1w
  • ==17.3.3
  • ==17.6.8
  • ==16.12.13
  • ==16.6.6
  • ==16.10.1d
  • ==16.9.1b
  • ==17.10.1b
  • ==16.9.8
  • ==17.9.6a
  • ==17.11.1a
  • ==17.9.1
  • ==17.12.1z5
  • ==16.12.7
  • ==17.9.4a
  • ==16.12.5
  • ==17.6.1x
  • ==17.15.4a
  • ==16.10.3
  • ==17.12.3a
  • ==16.10.1s
  • ==16.12.4a
  • ==17.2.1r
  • ==17.7.1b
  • ==17.12.7
  • ==16.12.2a
  • ==17.3.6
  • ==16.12.2
  • ==17.4.2
  • ==17.9.5b
  • ==16.9.1d
  • ==17.9.1y1
  • ==17.1.1a
  • ==17.1.3
  • ==17.3.5a
  • ==16.11.1s
  • ==17.15.4b
  • ==16.12.1c
  • ==16.9.5
  • ==16.6.5a
  • ==17.18.3a
  • ==17.15.1b
  • ==17.12.4a
  • ==17.3.5
  • ==16.12.1t
  • ==16.6.4a
  • ==17.6.4
  • ==17.9.5d
  • ==17.12.1y
  • ==16.7.4
  • ==17.11.1
  • ==17.17.1
  • ==16.12.8
  • ==17.18.1y
  • ==16.9.8b
  • ==16.9.1a
  • ==17.9.5c
  • ==16.6.3
  • ==17.9.1w
  • ==17.9.7b
  • ==17.12.1
  • ==17.7.1
  • ==17.13.1a
  • ==17.9.2a
  • ==17.6.7
  • ==17.15.3a
  • ==17.15.5
  • ==17.3.8
  • ==17.4.1
  • ==17.9.3a
  • ==17.5.1a
  • ==17.9.5a
  • ==17.15.2c
  • ==17.3.2
  • ==17.12.1z4
  • ==17.4.1c
  • ==16.10.1c
  • ==17.14.1a
  • ==16.12.10a
  • ==16.9.3
  • ==17.1.1s
  • ==17.6.6a
  • ==17.3.4c
  • ==17.8.1
  • ==16.12.1z2
  • ==17.6.2
  • ==17.9.4
  • ==16.12.15
  • ==17.12.6a
  • ==17.3.1
  • ==17.4.1b
  • ==17.4.1a
  • ==17.12.3
  • ==17.18.3
  • ==17.15.4c
  • ==16.12.1w
  • ==16.12.1
  • ==16.12.6a
  • ==17.6.1z
  • ==17.12.1z
  • ==17.15.3b
  • ==16.12.1x
  • ==16.9.6
  • ==17.14.1
  • ==17.15.1
  • ==16.6.8
  • ==16.12.11
  • ==17.6.3
  • ==17.18.1a
  • ==17.9.5e
  • ==17.15.1x
  • ==17.3.1z
  • ==16.10.1
  • ==17.10.1a
  • ==16.6.4s
  • ==17.3.8a
  • ==17.9.7
  • ==17.12.5d
  • ==16.9.8a
  • ==16.8.1c
  • ==16.6.7a
  • ==16.9.3a
  • ==16.8.1e
  • ==16.10.2
  • ==16.6.9
  • ==17.2.1a
  • ==16.9.5f
  • ==17.18.2
  • ==17.1.1t
  • ==17.15.2b
  • ==17.18.1w
  • ==16.9.2
  • ==17.2.2
  • ==17.9.2
  • ==16.9.1
  • ==17.3.5b
  • ==16.9.4
  • ==16.6.7
  • ==16.10.1e
  • ==17.6.1a
  • ==17.12.1z1
  • ==17.12.6b
  • ==17.6.6
  • ==16.11.1b
  • ==16.8.1
  • ==16.11.2
  • ==17.15.2
  • ==17.18.1z
  • ==17.9.3
  • ==16.9.2a
  • ==17.6.1
  • ==17.12.1a
  • ==16.7.3
  • ==17.10.1
  • ==17.12.1z6
  • ==17.15.7
  • ==16.7.2
  • ==16.8.1b
  • ==16.10.1f
  • ==16.12.1z
  • ==17.3.2a
  • ==16.12.6
  • ==17.15.4s1
  • ==16.12.2t
  • ==17.7.2
  • ==16.12.2s
  • ==17.3.7
  • ==17.9.1x1
  • ==16.12.3
  • ==17.3.4b
  • ==16.12.16
  • ==16.6.2
  • ==17.15.5a
  • ==17.12.2
  • ==17.6.8a
  • ==17.9.7a
  • ==16.8.1d
  • ==16.12.1y
  • ==17.1.1
  • ==17.3.4
  • ==17.6.5a
  • ==17.12.5a
  • ==17.12.2a
  • ==16.11.1
  • ==17.6.5
  • ==17.15.3
  • ==17.15.1a
  • ==16.12.12
  • ==17.15.4d
  • ==17.12.7b
  • ==17.3.4a
  • ==16.9.3s
  • ==16.7.1a
  • ==16.12.3a
  • ==16.11.1c
  • ==17.3.3a
  • ==16.12.1a
  • ==17.9.1x
  • ==17.9.1a
  • ==17.8.1a
  • ==16.10.1b
  • ==16.9.1c
  • ==17.9.5f
  • ==17.6.1z1
  • ==16.12.14
  • ==16.11.1a
  • ==16.8.1s
  • ==17.12.1w
  • ==16.12.10
  • ==17.2.1v
  • ==16.6.10
  • ==17.12.6
  • ==17.9.8
  • ==17.4.2a
  • ==17.15.1w
  • ==17.15.2a
  • ==17.9.1y
  • ==16.12.5a
  • ==17.12.1z3
  • ==16.10.1g
  • ==17.2.3
  • ==16.8.3
  • ==17.16.1a
  • ==16.9.1s
  • ==16.12.5b
  • ==16.9.4c
  • ==16.6.4
  • ==17.12.5b
  • ==17.5.1
  • ==16.12.3s
  • ==17.12.5c
  • ==17.9.9
  • ==17.6.3a
  • ==17.12.7a
  • ==26.1.1a
  • ==17.12.4
  • ==26.1.1
  • ==17.9.5
  • ==17.3.1a
  • ==17.16.1
  • ==17.18.1x
  • ==17.9.6
  • ==17.13.1
  • ==16.8.2
  • ==16.7.1b
Dismissed
(no matching packages found)
Permalink CVE-2026-71242
8.3 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): Low (L)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Crater: Cross-Company IDOR on Notes via Missing Company-Ownership Check in NotePolicy

Crater's NotePolicy checks only a blanket Bouncer ability (manage-all-notes / view-all-notes) with no company-ownership comparison, unlike InvoicePolicy and other sibling policies which additionally verify $user->hasCompany($model->company_id). NotesController's show(), update(), and destroy() actions authorize via $this->authorize('view notes'/'manage notes') without passing the target Note model, and Note's company-scoping (scopeWhereCompany) is applied only in the list endpoint, not in show/update/destroy. Any authenticated user of one company can read, edit, or delete another company's notes by ID. This is a distinct finding from the previously reported CustomerPolicy company-ownership omission (a different policy class and controller).

Affected products

crater
  • ==6.0.6
Dismissed
(no matching packages found)
Permalink CVE-2026-55524
7.5 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
PraisonAI: SSRF in web_crawl tool via redirect-following and DNS rebinding (validate-then-fetch gap)

PraisonAI is a multi-agent teams system. In versions prior to 1.6.58, the web_crawl tool performs its SSRF check only on the initially supplied URL, allowing the protection to be bypassed so the tool connects to attacker-chosen internal destinations. The check resolves the hostname once with socket.gethostbyname and rejects private/loopback/link-local results, but then passes the URL to a fetcher using httpx.Client(follow_redirects=True) (or urllib.request.urlopen when httpx is absent, which also follows redirects) that re-resolves the hostname at connect time with no further validation. This validate-here/fetch-there gap is exploitable through both HTTP redirects and DNS rebinding. If an attacker can influence URLs passed to web_crawl(), directly or through an agent/tool workflow, they can cause the PraisonAI host to fetch loopback, private-network, or cloud metadata endpoints reachable from that host, with the response body returned in the web_crawl() result. This issue has been fixed in version 1.6.58.

Affected products

PraisonAI
  • ==< 1.6.58
Dismissed
(no matching packages found)
Permalink CVE-2026-20200
8.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Cisco Integrated Management Controller Argument Injection and Remote Code Execution Vulnerability

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with low privileges to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to root.&nbsp; This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by entering crafted inputs to the web-based management interface of the affected software. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system as the root user.&nbsp;

Affected products

Cisco Unified Computing System (Standalone)
  • ==4.3(4.242038)
  • ==4.3(5.250001)
  • ==4.3(6.260017)
  • ==6.0(1.250174)
  • ==6.0(1.250127)
  • ==4.3(5.250045)
  • ==6.0(1.250194)
  • ==4.3(4.252001)
  • ==6.0(1.250131)
  • ==4.3(5.250043)
  • ==4.3(2.240002)
  • ==4.3(1.230097)
  • ==4.3(4.241014)
  • ==4.3(6.250117)
  • ==4.3(6.250060)
  • ==4.3(3.240043)
  • ==4.3(2.230207)
  • ==4.3(5.240021)
  • ==4.3(3.240022)
  • ==4.3(6.250101)
  • ==4.3(6.250039)
  • ==4.3(1.230138)
  • ==4.3(6.260003)
  • ==6.0(1.250130)
  • ==4.3(4.242028)
  • ==4.3(4.240152)
  • ==4.3(5.250033)
  • ==4.3(4.242066)
  • ==4.3(4.240142)
  • ==4.3(2.230270)
  • ==4.3(4.241063)
  • ==4.3(6.250040)
  • ==4.3(4.252002)
  • ==6.0(1.250192)
  • ==4.3(1.230124)
  • ==4.3(6.250044)
  • ==4.3(5.250030)
  • ==4.3(6.250053)
Dismissed
(no matching packages found)
Permalink CVE-2026-71239
8.1 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): None (N)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
DjangoCRM: Server-Side Template Injection in Mass Mail Message Rendering

DjangoCRM's massmail module renders user-controlled EmlMessage fields (subject, content) through Django's Template() constructor with no sanitization, in at least three locations: message_previews.py builds an f-string embedding message.subject/message.content directly into a Template() call; email_creators.py passes eml_message.subject directly as a template string to Template(); and helpers.py contains the same f-string interpolation pattern. An authenticated user with mass-mail message edit rights can inject Django template syntax ({{ }} / {% %}) that executes at render time, enabling disclosure of other users' data and password hashes via request context variables, CSRF token forgery, and inclusion of arbitrary registered templates.

Affected products

django-crm
  • ==0
Dismissed
(no matching packages found)
Permalink CVE-2026-67863
7.5 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Complexity (AC): Low (L)
  • Attack Vector (AV): Network (N)
  • Availability (A): High (H)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Privileges Required (PR): None (N)
  • Scope (S): Unchanged (U)
  • User Interaction (UI): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): High (H)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
In open62541 1.5.5, a server-side use-after-free exists in the local …

In open62541 1.5.5, a server-side use-after-free exists in the local MonitoredItem callback path. The issue occurs when UA_Subscription_localPublish continues to use the current UA_Notification after a callback invokes UA_Server_deleteMonitoredItem for the current local MonitoredItem. This allows a remote attacker to cause a denial of service.

Affected products

n/a
  • ==n/a
Dismissed
(no matching packages found)
Permalink CVE-2026-70441
5.4 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): Required (R)
  • Scope (S): Changed (C)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Jenkins Summary Display Plugin 1.15 and earlier does not escape …

Jenkins Summary Display Plugin 1.15 and earlier does not escape the job name in a JavaScript context in build report pages, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Create or Item/Configure permission.

References

Affected products

Jenkins Summary Display Plugin
  • =<1.15