Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Dismissed suggestions

These automatic suggestions were dismissed after initial triaging.

to select a suggestion for revision.

View:
Compact
Detailed
Dismissed
(max. allowed matches exceeded)
created 1 month ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
nexthop: initialize extack in nh_res_bucket_migrate()

In the Linux kernel, the following vulnerability has been resolved: nexthop: initialize extack in nh_res_bucket_migrate() nh_res_bucket_migrate() passes an uninitialized netlink_ext_ack to call_nexthop_res_bucket_notifiers(). When nh_notifier_res_bucket_info_init() fails (e.g. the kzalloc returns -ENOMEM), the error is propagated back before any notifier sets extack._msg, and the error path formats the stale pointer with pr_err_ratelimited("%s\n", extack._msg). With CONFIG_INIT_STACK_NONE this dereferences uninitialized stack memory: Oops: general protection fault, probably for non-canonical address ... KASAN: maybe wild-memory-access in range [...] RIP: 0010:string (lib/vsprintf.c:730) vsnprintf (lib/vsprintf.c:2945) _printk (kernel/printk/printk.c:2504) nh_res_bucket_migrate (net/ipv4/nexthop.c:1816) nh_res_table_upkeep (net/ipv4/nexthop.c:1866) rtm_new_nexthop (net/ipv4/nexthop.c:3323) rtnetlink_rcv_msg (net/core/rtnetlink.c:7076) netlink_sendmsg (net/netlink/af_netlink.c:1900) Kernel panic - not syncing: Fatal exception Zero-initialize extack so _msg is NULL on error paths that never set it.

Affected products

Linux
  • =<6.6.*
  • =<6.12.*
  • =<7.1.*
  • <d536bf205c71f700f6de2086038c3e1d77724715
  • <c0936c131a71657afc635d0db2ab096d15d473e1
  • =<*
  • <5.13
  • ==5.13
  • <3081702ea5aca0aeed9c1ade8eadf6cde8db6b7d
  • <6347c5314cee49f364aaf2e40ff15415a57a116e
  • <18506d7263768d76ac8e057ba55a4d9da50aad66
  • =<6.18.*
Dismissed
(no matching packages found)
Permalink CVE-2026-20198
4.8 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): Required (R)
  • Scope (S): Changed (C)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Cisco Integrated Management Controller Cross-Site Scripting Vulnerability

A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the browser of the targeted user or access sensitive, browser-based information.

Affected products

Cisco Unified Computing System (Standalone)
  • ==4.0(4c)
  • ==4.0(2c)
  • ==3.1(2c)
  • ==4.2(3j)
  • ==4.0(2k)
  • ==4.0(4e)
  • ==4.2(3i)
  • ==4.3(2.240053)
  • ==3.1(3a)
  • ==4.3(6.260033)
  • ==4.3(2.250022)
  • ==4.2(3h)
  • ==3.1(3h)
  • ==4.1(1f)
  • ==4.3(6.250117)
  • ==4.2(3e)
  • ==6.0(2.260069)
  • ==4.2(3m)
  • ==4.0(2r)
  • ==4.0(4j)
  • ==4.0(4b)
  • ==4.1(2h)
  • ==4.0(2o)
  • ==4.2(1c)
  • ==4.2(3l)
  • ==3.1(2i)
  • ==4.3(5.240021)
  • ==4.1(2l)
  • ==4.3(6.260003)
  • ==4.0(1e)
  • ==6.0(1.250130)
  • ==4.3(2.250045)
  • ==4.0(2i)
  • ==4.1(1d)
  • ==4.0(2l)
  • ==3.1(3g)
  • ==4.0(2h)
  • ==4.3(6.250040)
  • ==6.0(1.250192)
  • ==4.1(3m)
  • ==4.3(2.240037)
  • ==4.3(2.240107)
  • ==4.1(2d)
  • ==4.0(2m)
  • ==3.1(3i)
  • ==4.1(3l)
  • ==4.0(4d)
  • ==4.2(1g)
  • ==4.2(1i)
  • ==3.1(3b)
  • ==3.1(3d)
  • ==4.3(6.260017)
  • ==4.1(2g)
  • ==4.0(2d)
  • ==4.0(2p)
  • ==4.3(6.250060)
  • ==3.1(2d)
  • ==4.2(1a)
  • ==4.3(2.240090)
  • ==4.1(3g)
  • ==4.1(2e)
  • ==4.2(2a)
  • ==4.3(1.230138)
  • ==4.3(6.250101)
  • ==4.0(1h)
  • ==4.1(1g)
  • ==4.0(1d)
  • ==4.2(1b)
  • ==4.3(5.250033)
  • ==4.3(4.242066)
  • ==4.3(4.240142)
  • ==4.1(3i)
  • ==4.1(2j)
  • ==4.3(2.230270)
  • ==4.3(2.240077)
  • ==4.0(4f)
  • ==4.0(2q)
  • ==4.2(2f)
  • ==4.0(4i)
  • ==4.0(4k)
  • ==4.3(5.250030)
  • ==4.1(3d)
  • ==4.3(6.250053)
  • ==4.1(2f)
  • ==4.3(5.250001)
  • ==3.1(2b)
  • ==4.0(2g)
  • ==6.0(1.250174)
  • ==4.3(5.250045)
  • ==4.1(1h)
  • ==4.3(2.260007)
  • ==4.2(1e)
  • ==4.3(5.250043)
  • ==4.3(2.240002)
  • ==4.3(4.241014)
  • ==4.2(3b)
  • ==4.0(1c)
  • ==4.1(3n)
  • ==4.1(3c)
  • ==4.2(3k)
  • ==4.3(3.240043)
  • ==4.1(2b)
  • ==4.0(4l)
  • ==4.2(3g)
  • ==4.2(3q)
  • ==4.3(3.240022)
  • ==4.3(2.250016)
  • ==4.3(4.242028)
  • ==4.2(1j)
  • ==3.1(1d)
  • ==4.0(1b)
  • ==4.3(4.240152)
  • ==4.0(1a)
  • ==4.0(2f)
  • ==4.3(1.230124)
  • ==4.3(4.241063)
  • ==4.3(2.250037)
  • ==4.2(3p)
  • ==4.3(4.252002)
  • ==4.0(2n)
  • ==4.3(6.250044)
  • ==4.1(2k)
  • ==4.0(1g)
  • ==4.1(3f)
  • ==4.3(4.242038)
  • ==4.3(2.250063)
  • ==4.1(1c)
  • ==4.1(2m)
  • ==3.1(2e)
  • ==4.0(4h)
  • ==4.2(1f)
  • ==6.0(1.250127)
  • ==6.0(1.250194)
  • ==4.3(4.252001)
  • ==3.1(3c)
  • ==6.0(1.250131)
  • ==4.3(1.230097)
  • ==3.1(3k)
  • ==4.2(2g)
  • ==4.1(2a)
  • ==4.1(3h)
  • ==4.2(3n)
  • ==4.2(3d)
  • ==4.3(2.240009)
  • ==4.2(3o)
  • ==4.0(4n)
  • ==4.3(2.230207)
  • ==4.3(2.250021)
  • ==4.3(6.250039)
  • ==3.1(3j)
  • ==4.3(3.240041)
  • ==4.0(4m)
  • ==6.0(2.260044)
  • ==4.1(3b)
  • ==3.1(2g)
  • ==4.0(1.240)
Cisco Enterprise NFV Infrastructure Software
  • ==4.9.4-ES8
  • ==4.8.1
  • ==4.14.1
  • ==4.4.3
  • ==4.12.3
  • ==3.12.3
  • ==3.8.1
  • ==3.6.3
  • ==3.12.1b
  • ==4.1.1
  • ==4.15.3
  • ==4.4.1
  • ==4.18.2a
  • ==4.12.7
  • ==3.9.1
  • ==4.9.6
  • ==4.7.1
  • ==4.10.1
  • ==4.9.4
  • ==4.1.2
  • ==4.2.1
  • ==4.6.3-FC4
  • ==3.5.1
  • ==4.15.1
  • ==4.15.4
  • ==4.12.1
  • ==3.11.2
  • ==4.4.2
  • ==3.3.1
  • ==4.8.2
  • ==4.9.1
  • ==4.18.1
  • ==4.16.1
  • ==4.13.1
  • ==4.9.4-ES9
  • ==4.12.5
  • ==4.5.1
  • ==3.12.1
  • ==3.11.3
  • ==3.9.2
  • ==3.4.1
  • ==3.6.1
  • ==4.6.3
  • ==3.12.1a
  • ==3.6.2
  • ==4.6.2
  • ==4.9.2
  • ==4.11.1
  • ==4.15.2
  • ==4.2.2
  • ==3.5.2
  • ==4.6.2-FC3
  • ==4.9.3
  • ==4.12.2
  • ==4.9.5
  • ==4.6.5-ES1
  • ==3.11.1
  • ==3.10.2
  • ==4.18.2
  • ==4.6.2-FC2
  • ==4.6.1
  • ==4.12.8
  • ==4.12.6
  • ==4.9.2-FC5
  • ==3.7.1
  • ==4.9.4-FC3
  • ==4.12.4
  • ==3.12.2
  • ==4.6.4
  • ==3.10.3
  • ==4.15.5
  • ==3.10.1
Cisco Unified Computing System E-Series Software (UCSE)
  • ==4.00
  • ==3.1.5
  • ==4.02
  • ==3.2.1
  • ==4.15.3
  • ==3.2.13.6
  • ==3.2.2
  • ==3.1.4
  • ==3.2.3
  • ==3.2.7
  • ==3.2.15.3
  • ==3.2.4
  • ==4.12.1
  • ==3.2.15
  • ==3.2.8
  • ==3.1.0
  • ==3.2.11.3
  • ==3.2.17.1
  • ==3.1.3
  • ==3.2.6
  • ==3.2.12.2
  • ==4.11.1
  • ==4.15.2
  • ==4.12.2
  • ==3.1.1
  • ==3.2.11.5
  • ==3.2.16.1
  • ==3.2.10
  • ==3.2.11.1
  • ==3.2.14
  • ==3.1.2
Dismissed
(no matching packages found)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Apache Answer: Missing authorization in revision audit reject allows authenticated users to reject pending revisions

Improper Authorization vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Any authenticated user can reject arbitrary pending edit-revisions without review permission due to a missing authorization check on the reject operation. Users are recommended to upgrade to version 2.0.2, which fixes the issue.

Affected products

Apache Answer
  • =<2.0.1
Dismissed
(no matching packages found)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Missing permission checks in Jenkins Sauce OnDemand Plugin 2.2.0 and …

Missing permission checks in Jenkins Sauce OnDemand Plugin 2.2.0 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

References

Affected products

Jenkins Sauce OnDemand Plugin
  • =<2.2.0
Dismissed
(no matching packages found)
Permalink CVE-2026-16443
7.4 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): None (N)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Keycloak-services: keycloak-services: saml broker metadata import disables response signature validation

A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red Hat Build of Keycloak. When importing identity provider metadata that lacks specific usage attributes for keys, the system incorrectly disables signature validation for SAML responses even if a signing certificate is provided. This issue allows an unauthenticated attacker to forge a SAML response and gain unauthorized access to a user account by knowing their external identifier.

References

Affected products

keycloak-services
rhbk/keycloak-rhel9
  • *
rhbk/keycloak-rhel9-operator
  • *
rhbk/keycloak-operator-bundle
  • *
rhbk-keycloak-rhel9/rhbk-keycloak-rhel9
rhbk-openshift-rhel9/rhbk-openshift-rhel9
Dismissed
(no matching packages found)
Permalink CVE-2026-17556
8.8 HIGH
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): None (N)
  • Vulnerable System Impact Integrity (VI): High (H)
  • Vulnerable System Impact Availability (VA): High (H)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): None (N)
  • Modified Vulnerable System Impact Integrity (MVI): High (H)
  • Modified Vulnerable System Impact Availability (MVA): High (H)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Path traversal in GitHub Enterprise Server allowed unauthenticated deletion of instance storage via the X-GitHub-Request-Id header

A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to delete arbitrary files and directories on the instance, including the entire user storage directory containing Git LFS objects, release assets, attachments, and avatars. The X-GitHub-Request-Id request header was used without sanitization as a filesystem path segment for the upload buffer directory, so a traversal value pointed the buffer at an arbitrary path and the deferred cleanup routine recursively removed the traversed target. Exploitation required only network reachability to the instance and no authentication, and it worked even when private mode was enabled. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.22 and was fixed in versions 3.21.4, 3.20.6, 3.19.10, 3.18.13 and 3.17.19. This vulnerability was reported via the GitHub Bug Bounty program.

Affected products

Enterprise Server
  • =<3.19.9
  • =<3.17.18
  • =<3.18.12
  • =<3.21.3
  • =<3.20.5
Dismissed
(no matching packages found)
Permalink CVE-2026-7557
9.1 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): None (N)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
SAML authentication bypass in Progress MarkLogic Server

An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass authentication and impersonate any user, including administrators. This vulnerability affects deployments with SAML single sign-on enabled.

Affected products

MarkLogic Server
  • <12.0.3
  • <11.3.6
Dismissed
(no matching packages found)
Permalink CVE-2026-16993
3.7 LOW
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
DHL for WooCommerce < 4.0.1 - Unauthenticated Shipping Label Disclosure via Unprotected Uploads Directory

The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not protect its shipping-label storage directory with server-independent access control, relying only on an Apache .htaccess file, so on a web server that does not honor .htaccess (such as nginx) an unauthenticated visitor can download stored shipping labels (each containing a customer's name and postal address) by requesting predictable filenames.

References

Affected products

DHL Shipping Germany for WooCommerce
  • <4.0.1
Dismissed
(no matching packages found)
Permalink CVE-2026-60009
8.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
In Eclipse Theia versions up to and including 1.73.1, the …

In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend binds `POST /file-upload` in every filesystem-enabled deployment. The handler takes an attacker-supplied absolute path from the multipart `uri` field and calls `fs.move(tmp, target, { overwrite: true })` with no workspace confinement and no authentication. In browser (non-Electron) deployments the connection token is enforced only on WebSocket upgrades; the HTTP middleware in `@theia/core` re-issues the cookie and calls `next()` without rejecting tokenless HTTP requests. Because `multipart/form-data` is a CORS-safelisted request type, a cross-origin web page can trigger the write with no preflight and no credentials, resulting in an unauthenticated arbitrary file write outside the workspace to any absolute path the backend process can write. This can escalate to remote code execution, for example by overwriting a startup-executed file such as `~/.bashrc`. Electron mode uses a separate `ElectronSecurityToken` and is not affected via this path.

Affected products

Eclipse Theia
  • <1.74.0
Dismissed
(no matching packages found)
Permalink CVE-2026-49331
6.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Openshift/oauth-proxy: openshift/oauth-proxy: unauthenticated identity header injection on whitelisted paths

A flaw was found in openshift/oauth-proxy. On paths configured to bypass authentication (skip-auth-regex), the proxy forwards client-supplied identity headers (X-Forwarded-User, X-Forwarded-Email, X-Forwarded-Access-Token) to the upstream application without stripping them. An unauthenticated attacker can inject forged identity headers on whitelisted paths.

References

Affected products

openshift4/ose-oauth-proxy
openshift4/ose-oauth-proxy-rhel9