Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Dismissed suggestions

These automatic suggestions were dismissed after initial triaging.

to select a suggestion for revision.

View:
Compact
Detailed
Dismissed
(no matching packages found)
Permalink CVE-2026-16100
6.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): High (H)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Keycloak-services: keycloak-services: unbounded metric cardinality in user event metrics via request-controlled error text

A flaw was found in the user-event metrics recording of Keycloak. When metrics are enabled, the system records raw error messages from failed account operations as Prometheus metric labels. Because these error messages can include user-supplied input like nonexistent client IDs, an authenticated user can create a massive number of unique metric entries, eventually exhausting system memory and causing the service to crash or become unavailable.

References

Affected products

keycloak-services
rhbk/keycloak-rhel9
  • *
rhbk/keycloak-rhel9-operator
  • *
rhbk/keycloak-operator-bundle
  • *
rhbk-keycloak-rhel9/rhbk-keycloak-rhel9
rhbk-openshift-rhel9/rhbk-openshift-rhel9
Dismissed
(no matching packages found)
Permalink CVE-2026-10090
9.9 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Multicluster-operators-subscription: multicluster-operators-subscription: namespace edit user can deploy cluster-scoped clusterrolebinding and become cluster-admin via application subscription

A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernetes (ACM). A user with namespace-scoped "edit" privileges in an ACM hub namespace can create a Channel resource pointing to a Helm repository they control and a Subscription resource referencing it. The app-subscription controller fetches and applies the Helm chart contents with its own elevated authority, without verifying whether the subscription creator holds the "open-cluster-management:subscription-admin" role and without restricting applied resources to the subscription namespace. This allows the attacker to include cluster-scoped resources in the Helm chart, such as a ClusterRoleBinding granting the attacker's ServiceAccount the "cluster-admin" ClusterRole. Successful exploitation results in full cluster-admin privilege escalation. This contradicts the ACM documentation which states that non-subscription-admin users should have resources deployed into the subscription namespace only.

References

Affected products

rhacm2/multicluster-operators-subscription-rhel9
Dismissed
(no matching packages found)
Permalink CVE-2026-16613
4.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): Low (L)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
GDPR Cookie Compliance < 5.1.0 - Cookie Deletion and Forced Logout via CSRF

The GDPR Cookie Compliance WordPress plugin before 5.1.0 expires the visitor's cookies from an action that is reachable without authentication and performs no request-origin check, allowing an attacker to log any user out and delete the site's cookies by luring them to a crafted link.

References

Affected products

GDPR Cookie Compliance
  • <5.1.0
Dismissed
(no matching packages found)
Permalink CVE-2026-6020
7.2 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
ShopLentor <= 3.3.7 - Authenticated (Administrator+) Arbitrary Function Execution via 'callback' Parameter via REST API

The ShopLentor plugin for WordPress is vulnerable to arbitrary function execution via the woolentoropt/v1/custom-action REST API endpoint in all versions up to, and including, 3.3.7. This is due to the handle_action() method passing user-supplied input directly to call_user_func() without an allowlist of permitted callbacks. This makes it possible for authenticated attackers, with Administrator-level access and above, to execute arbitrary PHP callable functions via the 'callback' parameter.

Affected products

ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin
  • =<3.3.7
Dismissed
(max. allowed matches exceeded)
created 1 month ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
ipv4: fib: free fib_alias with kfree_rcu() on insert error path

In the Linux kernel, the following vulnerability has been resolved: ipv4: fib: free fib_alias with kfree_rcu() on insert error path fib_table_insert() publishes new_fa into the leaf's fa_list with fib_insert_alias() before calling the fib entry notifiers. When a notifier fails, the error path removes new_fa with fib_remove_alias() (hlist_del_rcu) and frees it right away with kmem_cache_free(). fib_table_lookup() walks that list under rcu_read_lock() only, so a concurrent lookup that already reached new_fa keeps reading it after the free: BUG: KASAN: slab-use-after-free in fib_table_lookup (net/ipv4/fib_trie.c:1601) Read of size 1 at addr ffff88810676d4eb by task exploit/297 Call Trace: fib_table_lookup (net/ipv4/fib_trie.c:1601) ip_route_output_key_hash_rcu (net/ipv4/route.c:2814) ip_route_output_key_hash (net/ipv4/route.c:2705) __ip4_datagram_connect (net/ipv4/datagram.c:49) udp_connect (net/ipv4/udp.c:2144) __sys_connect (net/socket.c:2167) __x64_sys_connect (net/socket.c:2173) do_syscall_64 entry_SYSCALL_64_after_hwframe which belongs to the cache ip_fib_alias of size 56 Triggering the error path needs CAP_NET_ADMIN and a registered fib notifier that can reject a route; a netdevsim device whose IPv4 FIB resource is exhausted is enough. Free new_fa with alias_free_mem_rcu(), as fib_table_delete() already does for a fib_alias removed from the trie.

Affected products

Linux
  • =<6.6.*
  • =<6.12.*
  • <d007056868723de9c0cc3f5ffaad47a8d468b9a4
  • =<7.1.*
  • <b8d2ea75c76abcd0d72679c2f488271f573e32fb
  • <5.6
  • ==5.6
  • =<*
  • <cb8be318b4432abd88d3172ec157330f27a5f7a7
  • <f2f152e94a67bc746afaf05a1b2702c195553112
  • <8150b5365f026e72250cacc527ea00be30f40105
  • =<6.18.*
Dismissed
(no matching packages found)
Permalink CVE-2026-20308
4.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): Low (L)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Cisco IOS XE Software Web-Based Management Interface Vulnerability

A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to perform a denial of service (DoS) attack against an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web-based management interface of an affected device. A successful exploit could allow the attacker to cause the web-based management interface to become unresponsive.

Affected products

Cisco IOS XE Software
  • ==17.15.1y
  • ==17.3.1x
  • ==16.12.1z1
  • ==16.12.9
  • ==16.12.1s
  • ==17.18.1
  • ==16.9.2s
  • ==17.15.4
  • ==17.12.1z2
  • ==17.12.1x
  • ==16.9.3h
  • ==16.9.7
  • ==17.1.2
  • ==17.12.5
  • ==17.12.4b
  • ==17.7.1a
  • ==17.2.1
  • ==16.10.1a
  • ==16.12.4
  • ==17.3.1w
  • ==17.3.3
  • ==17.6.8
  • ==16.12.13
  • ==16.10.1d
  • ==16.9.1b
  • ==17.10.1b
  • ==16.9.8
  • ==17.9.6a
  • ==17.11.1a
  • ==17.9.1
  • ==17.12.1z5
  • ==16.12.7
  • ==17.9.4a
  • ==16.12.5
  • ==17.6.1x
  • ==17.15.4a
  • ==16.10.3
  • ==17.12.3a
  • ==16.10.1s
  • ==16.12.4a
  • ==17.2.1r
  • ==17.7.1b
  • ==17.12.7
  • ==16.12.2a
  • ==17.3.6
  • ==16.12.2
  • ==17.4.2
  • ==17.9.5b
  • ==16.9.1d
  • ==17.9.1y1
  • ==17.1.1a
  • ==17.1.3
  • ==17.3.5a
  • ==16.11.1s
  • ==17.15.4b
  • ==16.12.1c
  • ==16.9.5
  • ==17.18.3a
  • ==17.15.1b
  • ==17.12.4a
  • ==17.3.5
  • ==16.12.1t
  • ==17.6.4
  • ==17.9.5d
  • ==17.12.1y
  • ==17.11.1
  • ==17.17.1
  • ==16.12.8
  • ==17.18.1y
  • ==16.9.8b
  • ==16.9.1a
  • ==17.9.5c
  • ==17.9.1w
  • ==17.9.7b
  • ==17.12.1
  • ==17.7.1
  • ==17.13.1a
  • ==17.9.2a
  • ==17.6.7
  • ==17.15.3a
  • ==17.15.5
  • ==17.3.8
  • ==17.4.1
  • ==17.9.3a
  • ==17.5.1a
  • ==17.9.5a
  • ==17.15.2c
  • ==17.3.2
  • ==17.12.1z4
  • ==17.4.1c
  • ==17.14.1a
  • ==16.10.1c
  • ==16.12.10a
  • ==16.9.3
  • ==17.1.1s
  • ==17.6.6a
  • ==17.3.4c
  • ==17.8.1
  • ==16.12.1z2
  • ==17.6.2
  • ==17.9.4
  • ==16.12.15
  • ==17.12.6a
  • ==17.3.1
  • ==17.4.1b
  • ==17.4.1a
  • ==17.12.3
  • ==17.18.3
  • ==17.15.4c
  • ==16.12.1
  • ==16.12.6a
  • ==16.12.1w
  • ==17.6.1z
  • ==17.12.1z
  • ==17.15.3b
  • ==17.14.1
  • ==16.12.11
  • ==16.12.1x
  • ==17.15.1
  • ==17.18.1a
  • ==16.9.6
  • ==17.6.3
  • ==17.12.5d
  • ==17.9.5e
  • ==17.15.1x
  • ==17.3.1z
  • ==17.9.7
  • ==17.10.1a
  • ==16.10.1
  • ==17.3.8a
  • ==16.9.8a
  • ==16.9.3a
  • ==16.10.2
  • ==17.2.1a
  • ==16.9.5f
  • ==17.18.2
  • ==17.1.1t
  • ==26.2.1ea
  • ==17.15.2b
  • ==17.18.1w
  • ==16.9.2
  • ==17.2.2
  • ==17.9.2
  • ==16.9.1
  • ==17.3.5b
  • ==16.9.4
  • ==16.10.1e
  • ==17.6.1a
  • ==17.12.1z1
  • ==17.12.6b
  • ==17.6.6
  • ==17.15.2
  • ==16.11.1b
  • ==17.18.1z
  • ==16.11.2
  • ==17.9.3
  • ==16.9.2a
  • ==17.6.1
  • ==17.12.1a
  • ==17.10.1
  • ==17.12.1z6
  • ==16.12.1z
  • ==16.10.1f
  • ==17.3.2a
  • ==16.12.6
  • ==17.15.4s1
  • ==16.12.2t
  • ==17.7.2
  • ==16.12.2s
  • ==17.3.7
  • ==17.9.1x1
  • ==16.12.3
  • ==17.3.4b
  • ==16.12.16
  • ==17.15.5a
  • ==17.12.2
  • ==17.6.8a
  • ==17.9.7a
  • ==17.6.5a
  • ==17.3.4
  • ==17.1.1
  • ==17.12.5a
  • ==16.12.1y
  • ==17.12.2a
  • ==16.11.1
  • ==17.6.5
  • ==17.15.3
  • ==17.15.1a
  • ==16.12.12
  • ==17.15.4d
  • ==17.12.7b
  • ==17.3.4a
  • ==16.9.3s
  • ==16.12.3a
  • ==16.11.1c
  • ==17.3.3a
  • ==16.12.1a
  • ==17.9.1x
  • ==17.9.1a
  • ==17.8.1a
  • ==16.10.1b
  • ==17.9.5f
  • ==16.9.1c
  • ==17.6.1z1
  • ==16.12.14
  • ==17.12.1w
  • ==17.12.6
  • ==16.11.1a
  • ==16.12.10
  • ==17.9.8
  • ==17.2.1v
  • ==17.4.2a
  • ==17.15.1w
  • ==17.15.2a
  • ==17.9.1y
  • ==17.12.1z3
  • ==16.10.1g
  • ==17.2.3
  • ==17.16.1a
  • ==16.9.1s
  • ==16.12.5b
  • ==16.9.4c
  • ==17.12.5b
  • ==17.5.1
  • ==17.12.5c
  • ==16.12.3s
  • ==17.9.9
  • ==17.6.3a
  • ==17.12.7a
  • ==26.1.1a
  • ==17.12.4
  • ==26.1.1
  • ==17.9.5
  • ==17.3.1a
  • ==17.16.1
  • ==17.18.1x
  • ==17.9.6
  • ==17.13.1
  • ==16.12.5a
Dismissed
(no matching packages found)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Apache Qpid Proton-J: Type size/count handling can lead to excessive allocation pre-authentication

A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue.

Affected products

org.apache.qpid:proton-j
  • =<0.34.1
Dismissed
(no matching packages found)
Permalink CVE-2026-16604
7.5 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Content Protector (Passster) < 4.3.6 - Unauthenticated Protected Content Disclosure via Content-Lock Block data-content Attribute

The Passster WordPress plugin before 4.3.6 outputs password-protected block content in the public page response before verifying the password, allowing unauthenticated users to recover the protected content without knowing the password.

References

Affected products

Passster
  • <4.3.6
Dismissed
(no matching packages found)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Apache Qpid Proton Dotnet: Unbounded type nesting can lead to pre-authentication stackoverflow

A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Proton-Dotnet through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue

Affected products

org.apache.qpid
  • =<1.0.0
Dismissed
(no matching packages found)
Permalink CVE-2026-5651
4.9 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Askeet <= 3.0 - Authenticated (Administrator+) SQL Injection via 'sql_query' Parameter

The Askeet plugin for WordPress is vulnerable to SQL Injection via the 'sql_query' parameter in multiple AJAX actions (askeet_execute_sql_query, askeet_export_all_results) in all versions up to, and including, 3.0. This is due to the askeet_is_safe_query() filter being bypassable using MySQL conditional comments (e.g., /*!UNION*/). The filter strips regular block comments before checking for forbidden SQL keywords, but MySQL interprets conditional comments as executable code. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Affected products

Askeet — Talk to Your WooCommerce Data
  • =<3.0