Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Dismissed suggestions

These automatic suggestions were dismissed after initial triaging.

to select a suggestion for revision.

View:
Compact
Detailed
Dismissed
(exclusively hosted service)
Permalink CVE-2026-26124
6.7 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Exploit Code Maturity (E): Proof-of-Concept (P)
  • Remediation Level (RL): Official Fix (O)
  • Report Confidence (RC): Confirmed (C)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 5 months, 3 weeks ago Activity log
  • Created suggestion
Microsoft ACI Confidential Containers Elevation of Privilege Vulnerability

Microsoft ACI Confidential Containers Elevation of Privilege Vulnerability

Affected products

Microsoft ACI Confidential Containers
  • ==-
Dismissed
(exclusively hosted service)
Permalink CVE-2026-26125
8.6 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Exploit Code Maturity (E): Proof-of-Concept (P)
  • Remediation Level (RL): Official Fix (O)
  • Report Confidence (RC): Confirmed (C)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
created 5 months, 3 weeks ago Activity log
  • Created suggestion
Payment Orchestrator Service Elevation of Privilege Vulnerability

Payment Orchestrator Service Elevation of Privilege Vulnerability

Affected products

Payment Orchestrator Service
  • ==-
Dismissed
(exclusively hosted service)
Permalink CVE-2026-21536
9.8 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Exploit Code Maturity (E): Unproven (U)
  • Remediation Level (RL): Official Fix (O)
  • Report Confidence (RC): Confirmed (C)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 5 months, 3 weeks ago Activity log
  • Created suggestion
Microsoft Devices Pricing Program Remote Code Execution Vulnerability

Microsoft Devices Pricing Program Remote Code Execution Vulnerability

Affected products

Microsoft Devices Pricing Program
  • ==-
Dismissed
(exclusively hosted service)
Permalink CVE-2026-26122
6.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Exploit Code Maturity (E): Unproven (U)
  • Remediation Level (RL): Official Fix (O)
  • Report Confidence (RC): Confirmed (C)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
created 5 months, 3 weeks ago Activity log
  • Created suggestion
Microsoft ACI Confidential Containers Information Disclosure Vulnerability

Microsoft ACI Confidential Containers Information Disclosure Vulnerability

Affected products

Microsoft ACI Confidential Containers
  • ==-
Permalink CVE-2025-47379
7.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 5 months, 4 weeks ago by @Erethon Activity log
  • Created suggestion
  • @Erethon dismissed
  • @Erethon accepted
  • @Erethon dismissed
Use After Free in Automotive Audio

Memory Corruption when concurrent access to shared buffer occurs due to improper synchronization between assignment and deallocation of buffer resources.

Affected products

Snapdragon
  • ==QCA6698AQ
  • ==QCA8695AU
  • ==SA8295P
  • ==Snapdragon 7s Gen 3 Mobile Platform
  • ==SRV1M
  • ==WCD9375
  • ==QCA9377
  • ==QCN6224
  • ==Snapdragon 8 Gen 2 Mobile Platform
  • ==SRV1H
  • ==SA8155
  • ==QCA6174A
  • ==QEP8111
  • ==QCN9012
  • ==SA8150P
  • ==SM7325P
  • ==SA8145P
  • ==Snapdragon 8 Gen 3 Mobile Platform
  • ==AR8031
  • ==QCA2066
  • ==Snapdragon 782G Mobile Platform
  • ==Snapdragon X12 LTE Modem
  • ==Snapdragon Auto 5G Modem-RF
  • ==WCN3950
  • ==WCN6755
  • ==Flight RB5 5G Platform
  • ==QAM8255P
  • ==SM8650Q
  • ==WCD9340
  • ==WSA8835
  • ==Milos
  • ==Snapdragon X35 5G Modem-RF System
  • ==Snapdragon 460 Mobile Platform
  • ==QRB5165M
  • ==SM8550P
  • ==Snapdragon 888+ 5G Mobile Platform
  • ==QCN9011
  • ==WCD9335
  • ==QCA6584AU
  • ==Snapdragon 660 Mobile Platform
  • ==SM8635P
  • ==SD865 5G
  • ==QFW7114
  • ==WCN3660B
  • ==QRB5165N
  • ==G1 Gen 1
  • ==QCA6391
  • ==Snapdragon 662 Mobile Platform
  • ==Qualcomm 215 Mobile Platform
  • ==Snapdragon XR2+ Gen 1 Platform
  • ==Snapdragon W5+ Gen 1 Wearable Platform
  • ==QCA8337
  • ==SA6155P
  • ==QCA6698AU
  • ==SM7675P
  • ==5G Fixed Wireless Access Platform
  • ==WCD9370
  • ==WCD9390
  • ==QCA6574A
  • ==SA4150P
  • ==WCN3910
  • ==SA2150P
  • ==QCA6564A
  • ==FastConnect 7800
  • ==SM7675
  • ==FWA Gen 3 Ultra Platform
  • ==SM7550P
  • ==Snapdragon 778G 5G Mobile Platform
  • ==Snapdragon 870 5G Mobile Platform
  • ==WSA8840
  • ==Snapdragon X55 5G Modem-RF System
  • ==QCA6574
  • ==QCM5430
  • ==QCM6490
  • ==AR8035
  • ==FastConnect 6700
  • ==WCD9378
  • ==WCN3988
  • ==LeMans_AU_LGIT
  • ==SA9000P
  • ==QCA6797AQ
  • ==QCC710
  • ==QCN6274
  • ==CSRA6640
  • ==Snapdragon 888 5G Mobile Platform
  • ==QCA8081
  • ==QCA6678AQ
  • ==SA7775P
  • ==SM7550
  • ==WCD9326
  • ==Snapdragon 865 5G Mobile Platform
  • ==WSA8832
  • ==SnapdragonAuto 4GModem
  • ==Robotics RB2 Platform
  • ==Snapdragon 685 4G Mobile Platform
  • ==FastConnect 6900
  • ==Snapdragon 7c+ Gen 3 Compute
  • ==FastConnect 6800
  • ==Robotics RB5 Platform
  • ==SA8155P
  • ==QCA9367
  • ==SM6650P
  • ==QCA6574AU
  • ==WSA8830
  • ==Snapdragon 695 5G Mobile Platform
  • ==QCA6688AQ
  • ==Smart Audio 400 Platform
  • ==Snapdragon X53 5G Modem-RF System
  • ==WCD9371
  • ==WCD9395
  • ==Snapdragon Auto 5G Modem-RF Gen 2
  • ==Qualcomm Video Collaboration VC5 Platform
  • ==Snapdragon X72 5G Modem-RF System
  • ==SD662
  • ==LeMansAU
  • ==WCD9380
  • ==WSA8810
  • ==WCN3990
  • ==SA8770P
  • ==QCS2290
  • ==Snapdragon 6 Gen 4 Mobile Platform
  • ==CSRA6620
  • ==QCS4290
  • ==WCN6650
  • ==SA4155P
  • ==QCA6595
  • ==SW5100P
  • ==Snapdragon X75 5G Modem-RF System
  • ==SA8255P
  • ==QCA6564
  • ==Snapdragon 4 Gen 1 Mobile Platform
  • ==SW5100
  • ==Snapdragon 690 5G Mobile Platform
  • ==WSA8845H
  • ==Snapdragon 8+ Gen 2 Mobile Platform
  • ==QCM4325
  • ==QFW7124
  • ==SM8635
  • ==QCS8550
  • ==QCA6564AU
  • ==SA8195P
  • ==WCD9341
  • ==Snapdragon X32 5G Modem-RF System
  • ==QAMSRV1H
  • ==WSA8845
  • ==C-V2X 9150
  • ==QCM6125
  • ==Qualcomm Video Collaboration VC3 Platform
  • ==Snapdragon 778G+ 5G Mobile Platform
  • ==SA8620P
  • ==WCN3680B
  • ==QCA6696
  • ==WCD9360
  • ==SA6145P
  • ==WSA8815
  • ==QCA6595AU
  • ==QAMSRV1M
  • ==QAM8295P
  • ==SA6155
  • ==WCD9385
  • ==FastConnect 6200
  • ==WCN3980
  • ==Snapdragon 480+ 5G Mobile Platform
  • ==SA6150P
  • ==QCM2290
  • ==MDM9250
  • ==SM6225P
  • ==Snapdragon 865+ 5G Mobile Platform
  • ==MDM9628
  • ==SA7255P
  • ==WCN3615
  • ==Snapdragon 480 5G Mobile Platform
  • ==SM7635P
  • ==WCN6450
  • ==Snapdragon 680 4G Mobile Platform
  • ==Snapdragon XR2 5G Platform
  • ==Qualcomm Video Collaboration VC1 Platform
  • ==SDA660

Matching in nixpkgs

pkgs.snapdragon-profiler

An profiler for Android devices running Snapdragon chips

  • nixos-unstable -
Testing suggestion edit
Testing round #2
Test round #3
Dismissed
(exclusively hosted service)
Permalink CVE-2026-26365
4.0 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
updated 5 months, 4 weeks ago by @ADMIN Activity log
  • Created suggestion
  • @ADMIN dismissed
Akamai Ghost on Akamai CDN edge servers before 2026-02-06 mishandles …

Akamai Ghost on Akamai CDN edge servers before 2026-02-06 mishandles processing of custom hop-by-hop HTTP headers, where an incoming request containing the header "Connection: Transfer-Encoding" could result in a forward request with invalid message framing, depending on the Akamai processing path. This could result in the origin server parsing the request body incorrectly, leading to HTTP request smuggling.

Affected products

Ghost
  • <2026-02-06

Matching in nixpkgs

pkgs.ghostie

Github notifications in your terminal

  • nixos-unstable -
    • nixos-unstable-small 0.3.1

pkgs.ghostty

Fast, native, feature-rich terminal emulator pushing modern features

  • nixos-unstable -
    • nixos-unstable-small 1.2.3

pkgs.ghost-cli

CLI Tool for installing & updating Ghost

  • nixos-unstable -

pkgs.ghostfolio

Open Source Wealth Management Software

  • nixos-unstable -

pkgs.ghostunnel

TLS proxy with mutual authentication support for securing non-TLS backend applications

  • nixos-unstable -
    • nixos-unstable-small 1.8.4

pkgs.ghostscript

PostScript interpreter (mainline version)

  • nixos-unstable -

pkgs.ghosttohugo

Convert Ghost export to Hugo posts

  • nixos-unstable -
    • nixos-unstable-small 0.5.3

pkgs.ghostty-bin

Fast, native, feature-rich terminal emulator pushing modern features

  • nixos-unstable -
    • nixos-unstable-small 1.2.3

pkgs.ghostscriptX

PostScript interpreter (mainline version)

  • nixos-unstable -

Package maintainers

Dismissed
(exclusively hosted service)
Permalink CVE-2025-54914
10.0 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Exploit Code Maturity (E): Unproven (U)
  • Remediation Level (RL): Official Fix (O)
  • Report Confidence (RC): Confirmed (C)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 5 months, 4 weeks ago by @ADMIN Activity log
  • Created suggestion
  • @ADMIN dismissed
Azure Networking Elevation of Privilege Vulnerability

Azure Networking Elevation of Privilege Vulnerability

Affected products

Networking
  • ==N/A
  • ==-

Matching in nixpkgs

Package maintainers

Permalink CVE-2026-2968
3.7 LOW
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Exploit Code Maturity (E): Proof-of-Concept (P)
  • Remediation Level (RL): Not Defined (X)
  • Report Confidence (RC): Reasonable (R)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
updated 6 months ago by @fricklerhandwerk Activity log
  • Created suggestion
  • @fricklerhandwerk ignored package mongoose
  • @fricklerhandwerk dismissed
Cesanta Mongoose Poly1305 Authentication Tag tls_chacha20.c mg_chacha20_poly1305_decrypt signature verification

A vulnerability was detected in Cesanta Mongoose up to 7.20. This impacts the function mg_chacha20_poly1305_decrypt of the file /src/tls_chacha20.c of the component Poly1305 Authentication Tag Handler. The manipulation results in improper verification of cryptographic signature. The attack may be launched remotely. This attack is characterized by high complexity. The exploitability is said to be difficult. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Affected products

Mongoose
  • ==7.7
  • ==7.20
  • ==7.11
  • ==7.19
  • ==7.6
  • ==7.2
  • ==7.8
  • ==7.10
  • ==7.14
  • ==7.4
  • ==7.5
  • ==7.17
  • ==7.15
  • ==7.0
  • ==7.16
  • ==7.12
  • ==7.13
  • ==7.9
  • ==7.3
  • ==7.18
  • ==7.1
Ignored packages (1)

pkgs.mongoose

Graph Coarsening and Partitioning Library

  • nixos-unstable -
    • nixos-unstable-small 3.3.6
Not in Nixpkgs (the one in Nixpkgs is a different one)
updated 7 months ago by @fricklerhandwerk Activity log
  • Created suggestion
  • @fricklerhandwerk ignored
    2 packages
    • terraform-providers.icinga_icinga2
    • terraform-providers.icinga2
  • @fricklerhandwerk dismissed
Icinga has insecure permission of %ProgramData%\icinga2\var on Windows

Icinga 2 is an open source monitoring system. Starting in version 2.3.0 and prior to versions 2.13.14, 2.14.8, and 2.15.2, the Icinga 2 MSI did not set appropriate permissions for the `%ProgramData%\icinga2\var` folder on Windows. This resulted in the its contents - including the private key of the user and synced configuration - being readable by all local users. All installations on Windows are affected. Versions 2.13.14, 2.14.8, and 2.15.2 contains a fix. There are two possibilities to work around the issue without upgrading Icinga 2. Upgrade Icinga for Windows to at least version v1.13.4, v1.12.4, or v1.11.2. These version will automatically fix the ACLs for the Icinga 2 agent as well. Alternatively, manually update the ACL for the given folder `C:\ProgramData\icinga2\var` (and `C:\Program Files\WindowsPowerShell\modules\icinga-powershell-framework\certificate` to fix the issue for the Icinga for Windows as well) including every sub-folder and item to restrict access for general users, only allowing the Icinga service user and administrators access.

Affected products

icinga2
  • ==>= 2.15.0, < 2.15.2
  • ==>= 2.14.0, < 2.14.8
  • ==>= 2.3.0, < 2.13.14

Matching in nixpkgs

pkgs.icinga2

Open source monitoring system

  • nixos-unstable -

pkgs.icinga2-agent

Open source monitoring system

  • nixos-unstable -
Ignored packages (2)

Package maintainers

sdf
updated 7 months, 1 week ago by @fricklerhandwerk Activity log
  • Created suggestion
  • @fricklerhandwerk ignored
    3 packages
    • python313Packages.moonraker-api
    • python312Packages.moonraker-api
    • home-assistant-custom-components.moonraker
  • @fricklerhandwerk dismissed
Moonraker with LDAP Enabled Allows Malicious Search Filter Injection

Moonraker is a Python web server providing API access to Klipper 3D printing firmware. In versions 0.9.3 and below, instances configured with the "ldap" component enabled are vulnerable to LDAP search filter injection techniques via the login endpoint. The 401 error response message can be used to determine whether or not a search was successful, allowing for brute force methods to discover LDAP entries on the server such as user IDs and user attributes. This issue has been fixed in version 0.10.0.

Affected products

moonraker
  • ==< 0.10.0

Matching in nixpkgs

Ignored packages (3)

Package maintainers

asd