Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Dismissed suggestions

These automatic suggestions were dismissed after initial triaging.

to select a suggestion for revision.

View:
Compact
Detailed
Dismissed
(no matching packages found)
created 2 months ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Gitea LFS mirror synchronization bypasses migration HTTP transport restrictions

Gitea versions before 1.25.5 do not use the migration HTTP transport for LFS push and sync mirror operations, bypassing the configured migration transport protections for those LFS requests.

Affected products

Gitea Open Source Git Server
  • <1.25.5
Dismissed
(no matching packages found)
created 2 months ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Gitea repository creation accepts invalid field values

Gitea versions before 1.25.5 lack validation constraints for repository creation fields, including length-limited template fields and trust model or object format values.

Affected products

Gitea Open Source Git Server
  • <1.25.5
Dismissed
(max. allowed matches exceeded)
created 2 months ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
sending old referer

A vulnerability in libcurl caused the HTTP `Referer:` header to persist even when explicitly cleared. While the documentation states that passing NULL to `CURLOPT_REFERER` suppresses the header, the option failed to clear the internal state. As a result the previous referrer string was erroneously reused and sent in subsequent requests, potentially leaking sensitive information to unintended servers.

References

Affected products

curl
  • =<8.20.0
  • =<8.18.0
  • =<8.19.0
Dismissed
(no matching packages found)
Permalink CVE-2026-27783
4.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
created 2 months ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Gitea issue-template APIs bypass repository unit authorization

Gitea versions up to and including 1.26.1 do not enforce repository-unit authorization on issue-template API endpoints.

Affected products

Gitea Open Source Git Server
  • =<1.26.1
Dismissed
(no matching packages found)
Permalink CVE-2026-44269
4.4 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
created 2 months ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release …

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper link resolution before file access ('link following') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized access.

Affected products

PowerProtect Data Domain
  • <8.3.1.40 or later
  • <7.13.1.80 or later
  • <8.6.1.20 or later
  • <8.7.0.0 or later
Dismissed
(no matching packages found)
Permalink CVE-2026-55945
4.2 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Exploit Code Maturity (E): Unproven (U)
  • Remediation Level (RL): Official Fix (O)
  • Report Confidence (RC): Confirmed (C)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
created 2 months ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to disclose information locally.

Affected products

Microsoft Edge (Chromium-based)
  • <150.0.4078.48
Dismissed
(max. allowed matches exceeded)
Permalink CVE-2026-14612
4.2 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): Low (L)
created 2 months ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
Freeipa: ipa: idm: freeipa: off-by-one buffer overflows in ipa-otpd oauth2.c during oauth2 device authorization

Two off-by-one errors in the FreeIPA ipa-otpd daemon's OAuth2 device authorization handler can cause out-of-bounds memory access when processing an oversized response from a configured external OAuth2/OIDC Identity Provider. An attacker who controls or can man-in-the-middle the IdP endpoint may be able to trigger ipa-otpd to write or read one byte past the end of a fixed-size buffer. Exploitation requires FreeIPA to be configured with an external IdP, attacker control or MITM of that IdP, and a user to initiate the OAuth2 device authorization flow. The most likely impact is limited denial of service affecting the ipa-otpd daemon.

References

Affected products

ipa
idm:DL1/ipa
idm:client/ipa
Dismissed
(max. allowed matches exceeded)
created 2 months ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
incomplete mTLS config matching in conn reuse

libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse. libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. However, some TLS settings related to client certificates were left out from the configuration match checks, making them match too easily. In particular options related to the private key.

References

Affected products

curl
  • =<7.17.1
  • =<7.59.0
  • =<7.42.0
  • =<7.10.2
  • =<7.56.1
  • =<7.7.1
  • =<7.29.0
  • =<7.16.0
  • =<7.86.0
  • =<7.15.4
  • =<7.69.1
  • =<7.24.0
  • =<7.11.1
  • =<7.52.0
  • =<7.10.6
  • =<8.2.1
  • =<7.81.0
  • =<7.76.0
  • =<7.85.0
  • =<7.76.1
  • =<7.19.7
  • =<7.21.6
  • =<7.88.0
  • =<8.14.1
  • =<7.16.3
  • =<8.17.0
  • =<8.8.0
  • =<7.55.0
  • =<7.49.0
  • =<7.56.0
  • =<7.65.2
  • =<7.34.0
  • =<7.33.0
  • =<7.10
  • =<7.19.2
  • =<7.70.0
  • =<7.50.0
  • =<7.42.1
  • =<7.19.3
  • =<7.50.2
  • =<8.2.0
  • =<7.16.1
  • =<7.13.0
  • =<7.13.1
  • =<8.20.0
  • =<7.45.0
  • =<7.7.3
  • =<7.83.1
  • =<7.21.0
  • =<8.12.1
  • =<7.53.0
  • =<7.41.0
  • =<7.63.0
  • =<8.1.0
  • =<7.78.0
  • =<7.67.0
  • =<7.7
  • =<7.22.0
  • =<7.69.0
  • =<7.12.0
  • =<7.77.0
  • =<7.40.0
  • =<7.12.1
  • =<7.18.2
  • =<7.10.7
  • =<7.18.0
  • =<7.19.4
  • =<7.46.0
  • =<7.36.0
  • =<7.49.1
  • =<7.47.1
  • =<7.15.0
  • =<7.39.0
  • =<7.48.0
  • =<8.7.0
  • =<7.72.0
  • =<8.0.1
  • =<7.20.1
  • =<7.23.1
  • =<7.15.2
  • =<7.43.0
  • =<7.10.8
  • =<7.13.2
  • =<7.9
  • =<7.80.0
  • =<7.9.2
  • =<7.65.1
  • =<7.7.2
  • =<7.64.1
  • =<7.16.4
  • =<7.50.3
  • =<7.21.3
  • =<7.16.2
  • =<7.73.0
  • =<7.17.0
  • =<7.57.0
  • =<7.21.5
  • =<8.14.0
  • =<7.30.0
  • =<7.9.4
  • =<7.26.0
  • =<7.62.0
  • =<7.18.1
  • =<7.74.0
  • =<7.54.0
  • =<8.11.1
  • =<7.88.1
  • =<7.61.1
  • =<7.10.3
  • =<8.16.0
  • =<7.79.1
  • =<7.19.6
  • =<7.9.5
  • =<8.1.1
  • =<7.65.0
  • =<7.8
  • =<7.15.5
  • =<7.19.0
  • =<7.71.1
  • =<8.18.0
  • =<8.10.1
  • =<8.15.0
  • =<7.37.1
  • =<8.13.0
  • =<7.87.0
  • =<7.28.0
  • =<7.61.0
  • =<8.3.0
  • =<7.54.1
  • =<7.15.1
  • =<7.31.0
  • =<7.9.8
  • =<7.79.0
  • =<7.32.0
  • =<7.53.1
  • =<7.19.1
  • =<7.28.1
  • =<8.1.2
  • =<7.51.0
  • =<7.82.0
  • =<8.0.0
  • =<7.66.0
  • =<7.8.1
  • =<7.9.7
  • =<7.83.0
  • =<7.11.2
  • =<7.68.0
  • =<7.37.0
  • =<8.6.0
  • =<7.12.2
  • =<7.58.0
  • =<7.35.0
  • =<7.21.1
  • =<7.14.1
  • =<8.10.0
  • =<7.27.0
  • =<7.9.6
  • =<7.25.0
  • =<7.9.3
  • =<7.9.1
  • =<7.52.1
  • =<8.12.0
  • =<7.60.0
  • =<7.55.1
  • =<7.21.2
  • =<7.38.0
  • =<8.5.0
  • =<7.84.0
  • =<7.71.0
  • =<8.9.1
  • =<8.11.0
  • =<7.14.0
  • =<7.11.0
  • =<7.50.1
  • =<7.23.0
  • =<7.20.0
  • =<7.21.4
  • =<8.9.0
  • =<7.12.3
  • =<8.4.0
  • =<7.44.0
  • =<8.19.0
  • =<8.7.1
  • =<7.10.5
  • =<7.47.0
  • =<7.21.7
  • =<7.10.1
  • =<7.65.3
  • =<7.15.3
  • =<7.10.4
  • =<7.19.5
  • =<7.64.0
  • =<7.75.0
Dismissed
(max. allowed matches exceeded)
created 2 months ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
exposing HTTP/3 early data

In this scenario, libcurl first uses a proper HTTP/3 server for the initial transfers, and when it makes a second transfer to the same site it has been replaced by the attacker's impostor machine - without a valid certificate. When libcurl returns to the hostname the second time with a cached SSL session (`CURLOPT_SSL_SESSIONID_CACHE` is not disabled) and early data enabled (the `CURLSSLOPT_EARLYDATA` bit is set in `CURLOPT_SSL_OPTIONS`), libcurl might send off the second request's bytes on that new connection *before* enforcing the certificate verification failure. Potentially leaking sensitive information.

References

Affected products

curl
  • =<8.13.0
  • =<8.12.0
  • =<8.14.1
  • =<8.18.0
  • =<8.15.0
  • =<8.11.0
  • =<8.14.0
  • =<8.16.0
  • =<8.19.0
  • =<8.17.0
  • =<8.11.1
  • =<8.20.0
  • =<8.12.1
Dismissed
(no matching packages found)
Permalink CVE-2026-28737
8.7 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): Required (R)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): None (N)
created 2 months ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Gitea 3D file viewer allows stored XSS through glTF extensionsRequired

Gitea versions from 1.25.0 before 1.26.0 allow stored cross-site scripting through the extensionsRequired field in glTF files rendered by the 3D file viewer.

Affected products

Gitea Open Source Git Server
  • <1.26.0