Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Dismissed suggestions

These automatic suggestions were dismissed after initial triaging.

to select a suggestion for revision.

View:
Compact
Detailed
Dismissed
(no matching packages found)
Permalink CVE-2026-71245
7.1 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Mautic: SQL Injection via field Parameter in Lead-by-Field-Value AJAX Endpoint

Mautic's getLeadIdsByFieldValueAction (LeadBundle/Controller/AjaxController.php) reads a field parameter from the request, sanitizes it only with InputHelper::clean() (which HTML-entity-encodes quotes and angle brackets but does not restrict other characters), and passes it into LeadRepository::buildQueryForGetLeadsByFieldValue() where it is concatenated directly as a raw SQL column identifier ($col = 'l.'.$field) rather than being validated against a whitelist of real column names or passed as a bound parameter. Since Doctrine cannot parameterize identifiers, and the sanitizer does not block spaces, parentheses, or other SQL-relevant characters, an attacker can inject SQL via the field name itself. The action requires only a valid session (any authenticated user), unlike sibling actions in the same controller that carry additional permission checks.

Affected products

mautic
  • ==0
Dismissed
(no matching packages found)
Permalink CVE-2026-71286
6.1 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Changed (C)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
ember-dynamic-render-template Client-Side Template Injection via Unsanitized templateString

The render-template component of ember-dynamic-render-template (addon/components/render-template.js) passes its `templateString` property directly into Ember/Glimmer's compileTemplate() (from @ember/template-compilation) with no sanitization, allow-listing, or validation of the input. Because compileTemplate() dynamically compiles and renders the supplied string as a live Handlebars/Glimmer template, any application that renders attacker-influenced data through this component's templateString property is exposed to client-side template injection: an attacker-controlled Handlebars expression is compiled and executed in the context of the rendering component, which can be leveraged for cross-site scripting depending on what helpers/context are exposed to the compiled template.

Affected products

ember-dynamic-render-template
  • =<0.0.6
Dismissed
(no matching packages found)
Permalink CVE-2025-15677
3.5 LOW
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
GeoDirectory < 2.8.110 - Editor+ Stored XSS via Place Categories

The GeoDirectory WordPress plugin before 2.8.110 does not sanitise and escape a place-category setting before outputting it back in an admin page, allowing high-privilege users such as editors and above to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in a multisite setup).

References

Affected products

GeoDirectory
  • <2.8.110
Dismissed
(no matching packages found)
Permalink CVE-2026-20288
6.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): None (N)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Cisco IMC Remote Code Execution Vulnerability Remote Code Execution Vulnerability

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with&nbsp;Admin privileges to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to root.&nbsp; This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by entering crafted inputs to the web-based management interface of the affected software. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system as the root user.&nbsp; Cisco has assigned this vulnerability a SIR of High rather than Medium as the score indicates because additional security implications could occur when the attacker becomes&nbsp;root.

Affected products

Cisco Unified Computing System (Standalone)
  • ==4.0(4c)
  • ==4.0(2c)
  • ==3.1(2c)
  • ==4.2(3j)
  • ==4.0(2k)
  • ==4.0(4e)
  • ==4.2(3i)
  • ==4.3(2.240053)
  • ==3.1(3a)
  • ==4.3(6.260033)
  • ==4.3(2.250022)
  • ==3.1(3h)
  • ==4.2(3h)
  • ==4.1(1f)
  • ==4.3(6.250117)
  • ==4.2(3e)
  • ==6.0(2.260069)
  • ==4.2(3m)
  • ==4.0(2r)
  • ==4.0(4j)
  • ==4.0(4b)
  • ==4.1(2h)
  • ==4.0(2o)
  • ==4.2(1c)
  • ==3.1(2i)
  • ==4.2(3l)
  • ==4.3(5.240021)
  • ==4.1(2l)
  • ==4.3(6.260003)
  • ==4.0(1e)
  • ==6.0(1.250130)
  • ==4.3(2.250045)
  • ==4.0(2i)
  • ==4.1(1d)
  • ==4.0(2l)
  • ==3.1(3g)
  • ==4.0(2h)
  • ==4.3(6.250040)
  • ==6.0(1.250192)
  • ==4.1(3m)
  • ==4.3(2.240037)
  • ==4.3(2.240107)
  • ==4.1(2d)
  • ==4.0(2m)
  • ==3.1(3i)
  • ==4.1(3l)
  • ==4.0(4d)
  • ==4.2(1g)
  • ==4.2(1i)
  • ==3.1(3b)
  • ==3.1(3d)
  • ==4.3(6.260017)
  • ==4.1(2g)
  • ==4.0(2d)
  • ==4.0(2p)
  • ==4.3(6.250060)
  • ==3.1(2d)
  • ==4.2(1a)
  • ==4.3(2.240090)
  • ==4.1(3g)
  • ==4.1(2e)
  • ==4.0(1h)
  • ==4.2(2a)
  • ==4.3(1.230138)
  • ==4.3(6.250101)
  • ==4.1(1g)
  • ==4.0(1d)
  • ==4.2(1b)
  • ==4.3(5.250033)
  • ==4.3(4.242066)
  • ==4.3(4.240142)
  • ==4.1(3i)
  • ==4.1(2j)
  • ==4.3(2.230270)
  • ==4.3(2.240077)
  • ==4.0(4f)
  • ==4.0(2q)
  • ==4.0(4i)
  • ==4.2(2f)
  • ==4.0(4k)
  • ==4.1(3d)
  • ==4.3(5.250030)
  • ==4.3(6.250053)
  • ==4.1(2f)
  • ==4.3(5.250001)
  • ==3.1(2b)
  • ==4.0(2g)
  • ==4.1(1h)
  • ==6.0(1.250174)
  • ==4.3(5.250045)
  • ==4.3(2.260007)
  • ==4.2(1e)
  • ==4.3(5.250043)
  • ==4.3(2.240002)
  • ==4.3(4.241014)
  • ==4.2(3b)
  • ==4.0(1c)
  • ==4.1(3n)
  • ==4.1(3c)
  • ==4.2(3k)
  • ==4.1(2b)
  • ==4.3(3.240043)
  • ==4.0(4l)
  • ==4.2(3g)
  • ==4.2(3q)
  • ==4.3(3.240022)
  • ==4.3(2.250016)
  • ==4.3(4.242028)
  • ==4.2(1j)
  • ==3.1(1d)
  • ==4.0(1b)
  • ==4.0(1a)
  • ==4.3(4.240152)
  • ==4.0(2f)
  • ==4.3(1.230124)
  • ==4.3(4.241063)
  • ==4.3(2.250037)
  • ==4.2(3p)
  • ==4.3(4.252002)
  • ==4.0(2n)
  • ==4.3(6.250044)
  • ==4.1(2k)
  • ==4.0(1g)
  • ==4.1(3f)
  • ==4.3(4.242038)
  • ==4.1(1c)
  • ==4.3(2.250063)
  • ==4.1(2m)
  • ==3.1(2e)
  • ==4.0(4h)
  • ==4.2(1f)
  • ==6.0(1.250127)
  • ==3.1(3c)
  • ==4.3(4.252001)
  • ==6.0(1.250194)
  • ==6.0(1.250131)
  • ==4.3(1.230097)
  • ==3.1(3k)
  • ==4.1(2a)
  • ==4.2(2g)
  • ==4.1(3h)
  • ==4.2(3n)
  • ==4.2(3d)
  • ==4.3(2.240009)
  • ==4.2(3o)
  • ==4.0(4n)
  • ==4.3(2.230207)
  • ==4.3(2.250021)
  • ==4.3(6.250039)
  • ==3.1(3j)
  • ==4.3(3.240041)
  • ==4.0(4m)
  • ==6.0(2.260044)
  • ==4.1(3b)
  • ==3.1(2g)
  • ==4.0(1.240)
Cisco Unified Computing System E-Series Software (UCSE)
  • ==3.1.5
  • ==3.2.1
  • ==4.15.3
  • ==3.2.13.6
  • ==3.2.2
  • ==3.1.4
  • ==3.2.3
  • ==3.2.7
  • ==3.2.15.3
  • ==3.2.4
  • ==4.12.1
  • ==3.2.15
  • ==3.2.8
  • ==3.1.0
  • ==3.2.11.3
  • ==3.2.17.1
  • ==3.1.3
  • ==3.2.6
  • ==3.2.12.2
  • ==4.11.1
  • ==4.15.2
  • ==3.1.1
  • ==4.12.2
  • ==3.2.11.5
  • ==3.2.16.1
  • ==3.2.10
  • ==3.2.11.1
  • ==3.2.14
  • ==3.1.2
Dismissed
(no matching packages found)
Permalink CVE-2026-71255
8.6 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): High (H)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
nanoMODBUS Client-Side Out-of-Bounds Write via object_length in recv_read_device_identification_res()

nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modbus client-side recv_read_device_identification_res() function (FC 0x2B/MEI 0x0E, Read Device Identification) in nanomodbus.c. The server-supplied object_length field (0-246) is validated only against the remaining PDU size (res_size_left) and is never validated against the caller-supplied buffers_length parameter. After copying data with strncpy(buffers_out[buf_index], str, buffers_length), the code unconditionally writes a NUL terminator at buffers_out[buf_index][object_length]. When a malicious or compromised Modbus server sends a response with object_length greater than or equal to the client's buffers_length, this NUL write lands past the end of the caller-provided buffer, corrupting adjacent stack or heap memory on the client.

Affected products

nanoMODBUS
  • =<1.23.0
Dismissed
(max. allowed matches exceeded)
created 1 month ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
bpf: tcp: fix double sock release on batch realloc

In the Linux kernel, the following vulnerability has been resolved: bpf: tcp: fix double sock release on batch realloc bpf_iter_tcp_batch() releases the current batch via bpf_iter_tcp_put_batch(), which drops the socket refs and rewrites each slot with the socket cookie, then grows the batch. cur_sk/end_sk are kept for bpf_iter_tcp_resume(), but on realloc failure the function returns ERR_PTR() before resume runs, leaving cur_sk < end_sk over slots that now hold cookies rather than sock pointers. bpf_iter_tcp_seq_stop() then calls bpf_iter_tcp_put_batch() again and dereferences a cookie as a struct sock. Empty the batch on the failure path so stop() does not release it again. The sockets were already freed by the first bpf_iter_tcp_put_batch(), so nothing leaks, and a later read() rescans the bucket from the start instead of skipping it. The sibling GFP_NOWAIT failure path still holds real socket references and is left for stop() to release. BUG: KASAN: null-ptr-deref in __sock_gen_cookie Read of size 8 at addr 0000000000000059 by task exploit ... __sock_gen_cookie (net/core/sock_diag.c:28) bpf_iter_tcp_put_batch (net/ipv4/tcp_ipv4.c:2918) bpf_iter_tcp_seq_stop (net/ipv4/tcp_ipv4.c:3270) bpf_seq_read (kernel/bpf/bpf_iter.c:205) vfs_read (fs/read_write.c:572) ksys_read (fs/read_write.c:716) do_syscall_64 entry_SYSCALL_64_after_hwframe Kernel panic - not syncing: Fatal exception

Affected products

Linux
  • <980a813452754f8001704744e92f7aa697c53dd3
  • =<7.1.*
  • =<*
  • <9f27c4f0ae35b5390ce4f7a54d3501144e41a54d
  • <8a726e9585ffe7bfbfad2b5279277a00973970f3
  • ==6.17
  • =<6.18.*
  • <6.17
Dismissed
(no matching packages found)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
An issue in open62541 v.1.5.5 and before allows a remote …

An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the NodeManagement type-instantiation logic component

Affected products

n/a
  • ==n/a
Dismissed
(no matching packages found)
Permalink CVE-2026-71208
6.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
KubeSphere: SSRF via Unvalidated Cluster CRD Connection Endpoint in Cluster Reconciliation

KubeSphere's cluster-controller reconciliation (pkg/utils/clusterclient/clusterclient.go, addCluster) processes every Cluster custom resource's connection configuration and immediately calls Discovery().ServerVersion() against the CRD-specified Kubernetes API endpoint, which is parsed only for URL syntax (url.Parse) with no allow/deny-list for loopback, RFC1918 private ranges, link-local, or cloud-metadata addresses (e.g. 169.254.169.254). A user able to create or update a Cluster CRD can force the controller-manager and apiserver pods to issue outbound requests to arbitrary internal or metadata endpoints.

Affected products

KubeSphere
  • =<4.1.3-rc.0
Dismissed
(no matching packages found)
Permalink CVE-2026-54416
7.2 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Pluck CMS: Unrestricted File Upload via Missing .php8 Extension in Upload Blacklist

Pluck CMS through 4.7.21 restricts dangerous file uploads in its admin file-management feature using a fixed blacklist in data/inc/files.php ('.php','php3','php4','php5','php6','php7','phtml','.phtm','.pht','.ph3','.ph4','.ph5','.asp','.cgi','.phar'), checked against the last 4-5 characters of the filename. The blacklist omits the '.php8' extension. An authenticated administrator can upload a file named e.g. shell.php8, which is stored unmodified and, on servers running PHP 8.x, is executed as PHP by the web server, resulting in remote code execution.

Affected products

Pluck CMS
  • =<4.7.21
Dismissed
(no matching packages found)
Permalink CVE-2026-16968
6.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
GeoDirectory < 2.8.168 - Contributor+ User Email Disclosure via geodir_json_search_users

The GeoDirectory WordPress plugin before 2.8.168 does not restrict a user-search handler to users allowed to list users, allowing any authenticated user with Contributor-level access or higher to retrieve the email addresses of all registered users, including administrators.

References

Affected products

GeoDirectory
  • <2.8.168