Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Dismissed suggestions

These automatic suggestions were dismissed after initial triaging.

to select a suggestion for revision.

View:
Compact
Detailed
Dismissed
(no matching packages found)
Permalink CVE-2026-9273
9.3 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): None (N)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Membership Plugin – Kadence Memberships <= 4.0.0 - Unauthenticated Password Reset Link Poisoning to Account Takeover

The Membership Plugin – Kadence Memberships plugin for WordPress (formerly Restrict Content) is vulnerable to password reset link poisoning leading to account takeover in all versions up to, and including, 4.0.0. This is due to the legacy lost-password handler rc_process_lost_password_form() consuming the attacker-controlled rc_redirect POST parameter into two unvalidated sinks in legacy/includes/forms.php: wp_redirect( esc_url( $_POST['rc_redirect'] ) . ... ) at line 243, and add_query_arg( array( 'key' => $key, 'login' => ... ), $_POST['rc_redirect'] ) inside rc_send_password_reset_email() at line 306. The nonce required to reach the handler is broadcast by the public [login_form] shortcode at line 207 to any anonymous visitor. This makes it possible for unauthenticated attackers to issue a password-reset request for any account (including administrators) whose reset email body points the victim at an attacker-controlled host carrying a valid reset key/login. When the victim clicks the link, the reset key leaks to the attacker, who can replay it against the legitimate site to complete account takeover.

Affected products

Membership Plugin – Kadence Memberships
  • =<4.0.0
Dismissed
(no matching packages found)
Permalink CVE-2026-20269
8.6 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): High (H)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Cisco IOS XE Software Security Hardening Release

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20269 are related to issues with improper control of a resource through its lifetime that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-664.

Affected products

Cisco IOS XE Software
  • ==17.15.1y
  • ==17.3.1x
  • ==16.12.1z1
  • ==16.6.5b
  • ==16.12.9
  • ==16.9.2s
  • ==16.12.1s
  • ==17.18.1
  • ==17.15.4
  • ==17.12.1z2
  • ==16.6.5
  • ==17.12.1x
  • ==16.9.3h
  • ==16.9.7
  • ==17.1.2
  • ==16.8.1a
  • ==17.12.5
  • ==17.12.4b
  • ==17.7.1a
  • ==17.2.1
  • ==16.7.1
  • ==16.10.1a
  • ==16.12.4
  • ==17.3.1w
  • ==17.3.3
  • ==17.6.8
  • ==16.12.13
  • ==16.6.6
  • ==16.10.1d
  • ==16.9.1b
  • ==17.10.1b
  • ==16.9.8
  • ==17.9.6a
  • ==17.11.1a
  • ==17.9.1
  • ==17.12.1z5
  • ==16.12.7
  • ==17.9.4a
  • ==16.12.5
  • ==17.6.1x
  • ==17.15.4a
  • ==16.10.3
  • ==17.12.3a
  • ==16.10.1s
  • ==16.12.4a
  • ==17.2.1r
  • ==17.7.1b
  • ==17.12.7
  • ==16.12.2a
  • ==17.3.6
  • ==16.12.2
  • ==17.4.2
  • ==17.9.5b
  • ==16.9.1d
  • ==17.9.1y1
  • ==17.1.1a
  • ==17.1.3
  • ==17.3.5a
  • ==16.11.1s
  • ==17.15.4b
  • ==16.12.1c
  • ==16.9.5
  • ==16.6.5a
  • ==17.18.3a
  • ==17.15.1b
  • ==17.12.4a
  • ==17.3.5
  • ==16.12.1t
  • ==16.6.4a
  • ==17.6.4
  • ==17.9.5d
  • ==17.12.1y
  • ==16.7.4
  • ==17.11.1
  • ==17.17.1
  • ==16.12.8
  • ==17.18.1y
  • ==16.9.8b
  • ==16.9.1a
  • ==17.9.5c
  • ==16.6.3
  • ==17.9.1w
  • ==17.9.7b
  • ==17.12.1
  • ==17.7.1
  • ==17.13.1a
  • ==17.9.2a
  • ==17.6.7
  • ==17.15.3a
  • ==17.15.5
  • ==17.3.8
  • ==17.4.1
  • ==17.9.3a
  • ==17.5.1a
  • ==17.9.5a
  • ==17.15.2c
  • ==17.3.2
  • ==17.12.1z4
  • ==17.4.1c
  • ==16.10.1c
  • ==17.14.1a
  • ==16.12.10a
  • ==16.9.3
  • ==17.1.1s
  • ==17.6.6a
  • ==17.3.4c
  • ==17.8.1
  • ==16.12.1z2
  • ==17.6.2
  • ==17.9.4
  • ==16.12.15
  • ==17.12.6a
  • ==17.3.1
  • ==17.4.1b
  • ==17.4.1a
  • ==17.12.3
  • ==17.18.3
  • ==17.15.4c
  • ==16.12.1
  • ==16.12.6a
  • ==16.12.1w
  • ==17.6.1z
  • ==17.12.1z
  • ==17.15.3b
  • ==16.12.1x
  • ==16.9.6
  • ==17.14.1
  • ==17.15.1
  • ==16.12.11
  • ==17.18.1a
  • ==17.6.3
  • ==17.12.5d
  • ==17.9.5e
  • ==17.15.1x
  • ==17.3.1z
  • ==16.10.1
  • ==17.10.1a
  • ==16.6.4s
  • ==17.3.8a
  • ==17.9.7
  • ==16.9.8a
  • ==16.8.1c
  • ==16.6.7a
  • ==16.9.3a
  • ==16.8.1e
  • ==16.10.2
  • ==16.6.9
  • ==17.2.1a
  • ==16.9.5f
  • ==17.18.2
  • ==17.1.1t
  • ==17.15.2b
  • ==17.18.1w
  • ==16.9.2
  • ==17.2.2
  • ==17.9.2
  • ==16.9.1
  • ==17.3.5b
  • ==16.9.4
  • ==16.6.7
  • ==16.10.1e
  • ==17.6.1a
  • ==17.12.1z1
  • ==17.12.6b
  • ==17.6.6
  • ==16.11.1b
  • ==16.8.1
  • ==16.11.2
  • ==17.15.2
  • ==17.18.1z
  • ==17.9.3
  • ==16.9.2a
  • ==17.6.1
  • ==17.12.1a
  • ==16.7.3
  • ==17.10.1
  • ==17.12.1z6
  • ==17.15.7
  • ==16.6.8
  • ==16.7.2
  • ==16.8.1b
  • ==16.10.1f
  • ==16.12.1z
  • ==17.3.2a
  • ==16.12.6
  • ==17.15.4s1
  • ==16.12.2t
  • ==17.7.2
  • ==16.12.2s
  • ==17.3.7
  • ==17.9.1x1
  • ==16.12.3
  • ==17.3.4b
  • ==16.12.16
  • ==16.6.2
  • ==17.15.5a
  • ==17.12.2
  • ==17.6.8a
  • ==17.9.7a
  • ==16.8.1d
  • ==17.6.5a
  • ==17.1.1
  • ==17.3.4
  • ==17.12.5a
  • ==16.12.1y
  • ==17.12.2a
  • ==16.11.1
  • ==17.6.5
  • ==17.15.3
  • ==17.15.1a
  • ==16.12.12
  • ==17.15.4d
  • ==17.12.7b
  • ==17.3.4a
  • ==16.9.3s
  • ==16.7.1a
  • ==16.12.3a
  • ==16.11.1c
  • ==17.3.3a
  • ==16.12.1a
  • ==17.9.1x
  • ==17.9.1a
  • ==17.8.1a
  • ==16.10.1b
  • ==16.9.1c
  • ==17.9.5f
  • ==17.6.1z1
  • ==16.12.14
  • ==16.11.1a
  • ==16.8.1s
  • ==17.12.1w
  • ==16.12.10
  • ==17.2.1v
  • ==16.6.10
  • ==17.12.6
  • ==17.9.8
  • ==17.4.2a
  • ==17.15.1w
  • ==17.15.2a
  • ==17.9.1y
  • ==16.12.5a
  • ==17.12.1z3
  • ==16.10.1g
  • ==17.2.3
  • ==16.8.3
  • ==17.16.1a
  • ==16.9.1s
  • ==16.12.5b
  • ==16.9.4c
  • ==16.6.4
  • ==17.12.5b
  • ==17.5.1
  • ==17.12.5c
  • ==16.12.3s
  • ==17.9.9
  • ==17.6.3a
  • ==17.12.7a
  • ==26.1.1a
  • ==17.12.4
  • ==26.1.1
  • ==17.9.5
  • ==17.3.1a
  • ==17.16.1
  • ==17.18.1x
  • ==17.9.6
  • ==17.13.1
  • ==16.8.2
  • ==16.7.1b
Dismissed
(no matching packages found)
Permalink CVE-2026-39924
7.6 HIGH
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): High (H)
  • Vulnerable System Impact Integrity (VI): High (H)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): High (H)
  • Modified Vulnerable System Impact Integrity (MVI): High (H)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Flarum < 1.8.16 Session Persistence via Improper Access Token Revocation

Flarum before 1.8.16 contains an improper session invalidation vulnerability that allows attackers who hold a valid session token to retain full account access after a victim changes their password, because the access_tokens table is never cleared on password change events. The TokensClearer::clearPasswordTokens() function only removes rows from the password_tokens table while leaving all active session cookies and API bearer tokens intact, including long-lived RememberAccessToken entries, and administrator-forced password resets via the user update endpoint are equally ineffective at revoking attacker-held sessions.

Affected products

Flarum Framework
  • <1.8.16
Dismissed
(no matching packages found)
Permalink CVE-2026-71267
9.8 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
microtar Stack Buffer Overflow in mtar_write_file_header() and mtar_write_dir_header()

microtar's mtar_write_file_header() and mtar_write_dir_header() functions (src/microtar.c) copy a caller-supplied entry name into the 100-byte `name` field of a stack-allocated mtar_header_t via strcpy(h.name, name), with no check that strlen(name) is less than 100 before the copy. Any application that calls these functions with an externally-influenced filename longer than 99 characters (e.g. when archiving user-supplied or attacker-controlled filenames) triggers a stack buffer overflow.

Affected products

microtar
  • =<*
Dismissed
(no matching packages found)
Permalink CVE-2026-10547
5.9 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): High (H)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): Low (L)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcement

IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate ownership in the deprecated POST /api/v1/build/{flow_id}/vertices endpoint, allowing an authenticated user to inject arbitrary graph data into a shared cache for any flow. This may result in cross-user cache pollution, unauthorized workflow execution, or denial of service.

References

Affected products

Langflow OSS
  • =<1.10.3
Dismissed
(no matching packages found)
Permalink CVE-2026-7520
8.1 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): None (N)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
MailChimp Forms by MailMunch <= 3.2.7 - Missing Authorization to Authenticated (Subscriber+) MailMunch Integration Takeover via 'sign_in' AJAX Action

The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `sign_in()` and `sign_up()` AJAX handlers in all versions up to, and including, 3.2.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to relink the site's MailMunch integration to an attacker-controlled MailMunch account by submitting attacker-supplied credentials. Once relinked, all subscriber data captured by the plugin's forms is delivered to the attacker, and the forms/landing pages rendered on the site are pulled from the attacker's MailMunch account.

Affected products

Mailmunch Forms for Mailchimp
  • =<3.2.7
Dismissed
(no matching packages found)
Permalink CVE-2026-7658
6.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): High (H)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): None (N)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcement

IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate the username field, allowing attackers to inject path traversal sequences and bypass containment checks. This enables multiple severe impacts, including arbitrary directory deletion, cross-tenant data destruction, and JWT signing key deletion leading to session invalidation.

References

Affected products

Langflow OSS
  • =<1.10.3
Dismissed
(no matching packages found)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
A heap-based buffer overflow exists in lib60870-C 2.4.0 in the …

A heap-based buffer overflow exists in lib60870-C 2.4.0 in the server-side FileSegment ASDU encoding path. The issue occurs because FileSegment_encode() validates only the standalone segment length via FileSegment_GetMaxDataSize() and does not verify the residual capacity of the current ASDU frame before encoding object fields and segment data

Affected products

n/a
  • ==n/a
Dismissed
(no matching packages found)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Apache Qpid ProtonJ2: Unbounded symbol value caching can lead to pre-authentication resource exhaustion

A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue.

Affected products

org.apache.qpid:protonj2
  • =<1.1.0
Dismissed
(no matching packages found)
Permalink CVE-2026-5108
4.4 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Super Progressive Web Apps <= 2.2.43 - Authenticated (Administrator+) Stored Cross-Site Scripting via Offline Message Setting

The Super Progressive Web Apps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `superpwa_settings[offline_message_txt]` setting in all versions up to, and including, 2.2.43. This is due to insufficient input sanitization and output escaping. The offline message value is stored without sanitization, passed to the frontend via `wp_localize_script()` without escaping, and rendered using `innerHTML` in the JavaScript snackbar component. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user triggers the offline snackbar.

Affected products

Super Progressive Web Apps
  • =<2.2.43