Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Dismissed suggestions

These automatic suggestions were dismissed after initial triaging.

to select a suggestion for revision.

View:
Compact
Detailed
Dismissed
(no matching packages found)
Permalink CVE-2026-44269
4.4 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
created 1 month, 3 weeks ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release …

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper link resolution before file access ('link following') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized access.

Affected products

PowerProtect Data Domain
  • <8.3.1.40 or later
  • <7.13.1.80 or later
  • <8.6.1.20 or later
  • <8.7.0.0 or later
Dismissed
(no matching packages found)
Permalink CVE-2026-55945
4.2 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Exploit Code Maturity (E): Unproven (U)
  • Remediation Level (RL): Official Fix (O)
  • Report Confidence (RC): Confirmed (C)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
created 1 month, 3 weeks ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to disclose information locally.

Affected products

Microsoft Edge (Chromium-based)
  • <150.0.4078.48
Dismissed
(max. allowed matches exceeded)
Permalink CVE-2026-14612
4.2 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): Low (L)
created 1 month, 3 weeks ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
Freeipa: ipa: idm: freeipa: off-by-one buffer overflows in ipa-otpd oauth2.c during oauth2 device authorization

Two off-by-one errors in the FreeIPA ipa-otpd daemon's OAuth2 device authorization handler can cause out-of-bounds memory access when processing an oversized response from a configured external OAuth2/OIDC Identity Provider. An attacker who controls or can man-in-the-middle the IdP endpoint may be able to trigger ipa-otpd to write or read one byte past the end of a fixed-size buffer. Exploitation requires FreeIPA to be configured with an external IdP, attacker control or MITM of that IdP, and a user to initiate the OAuth2 device authorization flow. The most likely impact is limited denial of service affecting the ipa-otpd daemon.

References

Affected products

ipa
idm:DL1/ipa
idm:client/ipa
Dismissed
(max. allowed matches exceeded)
created 1 month, 3 weeks ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
incomplete mTLS config matching in conn reuse

libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse. libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. However, some TLS settings related to client certificates were left out from the configuration match checks, making them match too easily. In particular options related to the private key.

References

Affected products

curl
  • =<7.17.1
  • =<7.59.0
  • =<7.42.0
  • =<7.10.2
  • =<7.56.1
  • =<7.7.1
  • =<7.29.0
  • =<7.16.0
  • =<7.86.0
  • =<7.15.4
  • =<7.69.1
  • =<7.24.0
  • =<7.11.1
  • =<7.52.0
  • =<7.10.6
  • =<8.2.1
  • =<7.81.0
  • =<7.76.0
  • =<7.85.0
  • =<7.76.1
  • =<7.19.7
  • =<7.21.6
  • =<7.88.0
  • =<8.14.1
  • =<7.16.3
  • =<8.17.0
  • =<8.8.0
  • =<7.55.0
  • =<7.49.0
  • =<7.56.0
  • =<7.65.2
  • =<7.34.0
  • =<7.33.0
  • =<7.10
  • =<7.19.2
  • =<7.70.0
  • =<7.50.0
  • =<7.42.1
  • =<7.19.3
  • =<7.50.2
  • =<8.2.0
  • =<7.16.1
  • =<7.13.0
  • =<7.13.1
  • =<8.20.0
  • =<7.45.0
  • =<7.7.3
  • =<7.83.1
  • =<7.21.0
  • =<8.12.1
  • =<7.53.0
  • =<7.41.0
  • =<7.63.0
  • =<8.1.0
  • =<7.78.0
  • =<7.67.0
  • =<7.7
  • =<7.22.0
  • =<7.69.0
  • =<7.12.0
  • =<7.77.0
  • =<7.40.0
  • =<7.12.1
  • =<7.18.2
  • =<7.10.7
  • =<7.18.0
  • =<7.19.4
  • =<7.46.0
  • =<7.36.0
  • =<7.49.1
  • =<7.47.1
  • =<7.15.0
  • =<7.39.0
  • =<7.48.0
  • =<8.7.0
  • =<7.72.0
  • =<8.0.1
  • =<7.20.1
  • =<7.23.1
  • =<7.15.2
  • =<7.43.0
  • =<7.10.8
  • =<7.13.2
  • =<7.9
  • =<7.80.0
  • =<7.9.2
  • =<7.65.1
  • =<7.7.2
  • =<7.64.1
  • =<7.16.4
  • =<7.50.3
  • =<7.21.3
  • =<7.16.2
  • =<7.73.0
  • =<7.17.0
  • =<7.57.0
  • =<7.21.5
  • =<8.14.0
  • =<7.30.0
  • =<7.9.4
  • =<7.26.0
  • =<7.62.0
  • =<7.18.1
  • =<7.74.0
  • =<7.54.0
  • =<8.11.1
  • =<7.88.1
  • =<7.61.1
  • =<7.10.3
  • =<8.16.0
  • =<7.79.1
  • =<7.19.6
  • =<7.9.5
  • =<8.1.1
  • =<7.65.0
  • =<7.8
  • =<7.15.5
  • =<7.19.0
  • =<7.71.1
  • =<8.18.0
  • =<8.10.1
  • =<8.15.0
  • =<7.37.1
  • =<8.13.0
  • =<7.87.0
  • =<7.28.0
  • =<7.61.0
  • =<8.3.0
  • =<7.54.1
  • =<7.15.1
  • =<7.31.0
  • =<7.9.8
  • =<7.79.0
  • =<7.32.0
  • =<7.53.1
  • =<7.19.1
  • =<7.28.1
  • =<8.1.2
  • =<7.51.0
  • =<7.82.0
  • =<8.0.0
  • =<7.66.0
  • =<7.8.1
  • =<7.9.7
  • =<7.83.0
  • =<7.11.2
  • =<7.68.0
  • =<7.37.0
  • =<8.6.0
  • =<7.12.2
  • =<7.58.0
  • =<7.35.0
  • =<7.21.1
  • =<7.14.1
  • =<8.10.0
  • =<7.27.0
  • =<7.9.6
  • =<7.25.0
  • =<7.9.3
  • =<7.9.1
  • =<7.52.1
  • =<8.12.0
  • =<7.60.0
  • =<7.55.1
  • =<7.21.2
  • =<7.38.0
  • =<8.5.0
  • =<7.84.0
  • =<7.71.0
  • =<8.9.1
  • =<8.11.0
  • =<7.14.0
  • =<7.11.0
  • =<7.50.1
  • =<7.23.0
  • =<7.20.0
  • =<7.21.4
  • =<8.9.0
  • =<7.12.3
  • =<8.4.0
  • =<7.44.0
  • =<8.19.0
  • =<8.7.1
  • =<7.10.5
  • =<7.47.0
  • =<7.21.7
  • =<7.10.1
  • =<7.65.3
  • =<7.15.3
  • =<7.10.4
  • =<7.19.5
  • =<7.64.0
  • =<7.75.0
Dismissed
(max. allowed matches exceeded)
created 1 month, 3 weeks ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
exposing HTTP/3 early data

In this scenario, libcurl first uses a proper HTTP/3 server for the initial transfers, and when it makes a second transfer to the same site it has been replaced by the attacker's impostor machine - without a valid certificate. When libcurl returns to the hostname the second time with a cached SSL session (`CURLOPT_SSL_SESSIONID_CACHE` is not disabled) and early data enabled (the `CURLSSLOPT_EARLYDATA` bit is set in `CURLOPT_SSL_OPTIONS`), libcurl might send off the second request's bytes on that new connection *before* enforcing the certificate verification failure. Potentially leaking sensitive information.

References

Affected products

curl
  • =<8.13.0
  • =<8.12.0
  • =<8.14.1
  • =<8.18.0
  • =<8.15.0
  • =<8.11.0
  • =<8.14.0
  • =<8.16.0
  • =<8.19.0
  • =<8.17.0
  • =<8.11.1
  • =<8.20.0
  • =<8.12.1
Dismissed
(no matching packages found)
Permalink CVE-2026-28737
8.7 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): Required (R)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): None (N)
created 1 month, 3 weeks ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Gitea 3D file viewer allows stored XSS through glTF extensionsRequired

Gitea versions from 1.25.0 before 1.26.0 allow stored cross-site scripting through the extensionsRequired field in glTF files rendered by the 3D file viewer.

Affected products

Gitea Open Source Git Server
  • <1.26.0
Dismissed
(no matching packages found)
Permalink CVE-2026-47897
8.9 HIGH
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Attack Requirement (AT): Present (P)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): High (H)
  • Vulnerable System Impact Integrity (VI): None (N)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): High (H)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Automatable (AU): Yes (Y)
  • Vulnerability Response Effort (RE): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Attack Requirement (MAT): Present (P)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): High (H)
  • Modified Vulnerable System Impact Integrity (MVI): None (N)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): High (H)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 1 month, 3 weeks ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Apache Lucene.Net: Arbitrary file write from malicious server to Lucene.Net.Replicator client

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucene.Net.Replicator library). This issue affects Apache Lucene.Net.Replicator: from 4.8.0-beta00005 before 4.8.0-beta00018. Users are recommended to upgrade to version 4.8.0-beta00018, which fixes the issue.

Affected products

Lucene.Net.Replicator
  • <4.8.0-beta00018
Dismissed
(no matching packages found)
created 1 month, 3 weeks ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Gitea organization permission APIs expose private visibility information

Gitea versions before 1.25.5 have insufficient visibility checks in organization permission APIs for hidden members and private organizations.

Affected products

Gitea Open Source Git Server
  • <1.25.5
Dismissed
(no matching packages found)
Permalink CVE-2026-58291
6.1 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Exploit Code Maturity (E): Unproven (U)
  • Remediation Level (RL): Official Fix (O)
  • Report Confidence (RC): Confirmed (C)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
created 1 month, 3 weeks ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

Operation on a resource after expiration or release in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

Affected products

Microsoft Edge (Chromium-based)
  • <150.0.4078.48
Dismissed
(no matching packages found)
Permalink CVE-2026-57977
7.1 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): High (H)
  • Availability (A): None (N)
  • Exploit Code Maturity (E): Unproven (U)
  • Remediation Level (RL): Official Fix (O)
  • Report Confidence (RC): Confirmed (C)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): None (N)
created 1 month, 3 weeks ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Microsoft Edge (Chromium-based) Spoofing Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Affected products

Microsoft Edge (Chromium-based)
  • <150.0.4078.48