Nixpkgs security tracker

Try the new UI
Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Dismissed suggestions

These automatic suggestions were dismissed after initial triaging.

to select a suggestion for revision.

View:
Compact
Detailed
Dismissed
(max. allowed matches exceeded)
created 2 months, 1 week ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
incomplete mTLS config matching in conn reuse

libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse. libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. However, some TLS settings related to client certificates were left out from the configuration match checks, making them match too easily. In particular options related to the private key.

References

Affected products

curl
  • =<7.17.1
  • =<7.59.0
  • =<7.42.0
  • =<7.10.2
  • =<7.56.1
  • =<7.7.1
  • =<7.29.0
  • =<7.16.0
  • =<7.86.0
  • =<7.15.4
  • =<7.69.1
  • =<7.24.0
  • =<7.11.1
  • =<7.52.0
  • =<7.10.6
  • =<8.2.1
  • =<7.81.0
  • =<7.76.0
  • =<7.85.0
  • =<7.76.1
  • =<7.19.7
  • =<7.21.6
  • =<7.88.0
  • =<8.14.1
  • =<7.16.3
  • =<8.17.0
  • =<8.8.0
  • =<7.55.0
  • =<7.49.0
  • =<7.56.0
  • =<7.65.2
  • =<7.34.0
  • =<7.33.0
  • =<7.10
  • =<7.19.2
  • =<7.70.0
  • =<7.50.0
  • =<7.42.1
  • =<7.19.3
  • =<7.50.2
  • =<8.2.0
  • =<7.16.1
  • =<7.13.0
  • =<7.13.1
  • =<8.20.0
  • =<7.45.0
  • =<7.7.3
  • =<7.83.1
  • =<7.21.0
  • =<8.12.1
  • =<7.53.0
  • =<7.41.0
  • =<7.63.0
  • =<8.1.0
  • =<7.78.0
  • =<7.67.0
  • =<7.7
  • =<7.22.0
  • =<7.69.0
  • =<7.12.0
  • =<7.77.0
  • =<7.40.0
  • =<7.12.1
  • =<7.18.2
  • =<7.10.7
  • =<7.18.0
  • =<7.19.4
  • =<7.46.0
  • =<7.36.0
  • =<7.49.1
  • =<7.47.1
  • =<7.15.0
  • =<7.39.0
  • =<7.48.0
  • =<8.7.0
  • =<7.72.0
  • =<8.0.1
  • =<7.20.1
  • =<7.23.1
  • =<7.15.2
  • =<7.43.0
  • =<7.10.8
  • =<7.13.2
  • =<7.9
  • =<7.80.0
  • =<7.9.2
  • =<7.65.1
  • =<7.7.2
  • =<7.64.1
  • =<7.16.4
  • =<7.50.3
  • =<7.21.3
  • =<7.16.2
  • =<7.73.0
  • =<7.17.0
  • =<7.57.0
  • =<7.21.5
  • =<8.14.0
  • =<7.30.0
  • =<7.9.4
  • =<7.26.0
  • =<7.62.0
  • =<7.18.1
  • =<7.74.0
  • =<7.54.0
  • =<8.11.1
  • =<7.88.1
  • =<7.61.1
  • =<7.10.3
  • =<8.16.0
  • =<7.79.1
  • =<7.19.6
  • =<7.9.5
  • =<8.1.1
  • =<7.65.0
  • =<7.8
  • =<7.15.5
  • =<7.19.0
  • =<7.71.1
  • =<8.18.0
  • =<8.10.1
  • =<8.15.0
  • =<7.37.1
  • =<8.13.0
  • =<7.87.0
  • =<7.28.0
  • =<7.61.0
  • =<8.3.0
  • =<7.54.1
  • =<7.15.1
  • =<7.31.0
  • =<7.9.8
  • =<7.79.0
  • =<7.32.0
  • =<7.53.1
  • =<7.19.1
  • =<7.28.1
  • =<8.1.2
  • =<7.51.0
  • =<7.82.0
  • =<8.0.0
  • =<7.66.0
  • =<7.8.1
  • =<7.9.7
  • =<7.83.0
  • =<7.11.2
  • =<7.68.0
  • =<7.37.0
  • =<8.6.0
  • =<7.12.2
  • =<7.58.0
  • =<7.35.0
  • =<7.21.1
  • =<7.14.1
  • =<8.10.0
  • =<7.27.0
  • =<7.9.6
  • =<7.25.0
  • =<7.9.3
  • =<7.9.1
  • =<7.52.1
  • =<8.12.0
  • =<7.60.0
  • =<7.55.1
  • =<7.21.2
  • =<7.38.0
  • =<8.5.0
  • =<7.84.0
  • =<7.71.0
  • =<8.9.1
  • =<8.11.0
  • =<7.14.0
  • =<7.11.0
  • =<7.50.1
  • =<7.23.0
  • =<7.20.0
  • =<7.21.4
  • =<8.9.0
  • =<7.12.3
  • =<8.4.0
  • =<7.44.0
  • =<8.19.0
  • =<8.7.1
  • =<7.10.5
  • =<7.47.0
  • =<7.21.7
  • =<7.10.1
  • =<7.65.3
  • =<7.15.3
  • =<7.10.4
  • =<7.19.5
  • =<7.64.0
  • =<7.75.0
Dismissed
(max. allowed matches exceeded)
created 2 months, 1 week ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
exposing HTTP/3 early data

In this scenario, libcurl first uses a proper HTTP/3 server for the initial transfers, and when it makes a second transfer to the same site it has been replaced by the attacker's impostor machine - without a valid certificate. When libcurl returns to the hostname the second time with a cached SSL session (`CURLOPT_SSL_SESSIONID_CACHE` is not disabled) and early data enabled (the `CURLSSLOPT_EARLYDATA` bit is set in `CURLOPT_SSL_OPTIONS`), libcurl might send off the second request's bytes on that new connection *before* enforcing the certificate verification failure. Potentially leaking sensitive information.

References

Affected products

curl
  • =<8.13.0
  • =<8.12.0
  • =<8.14.1
  • =<8.18.0
  • =<8.15.0
  • =<8.11.0
  • =<8.14.0
  • =<8.16.0
  • =<8.19.0
  • =<8.17.0
  • =<8.11.1
  • =<8.20.0
  • =<8.12.1
Dismissed
(no matching packages found)
Permalink CVE-2026-28737
8.7 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): Required (R)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): None (N)
created 2 months, 1 week ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Gitea 3D file viewer allows stored XSS through glTF extensionsRequired

Gitea versions from 1.25.0 before 1.26.0 allow stored cross-site scripting through the extensionsRequired field in glTF files rendered by the 3D file viewer.

Affected products

Gitea Open Source Git Server
  • <1.26.0
Dismissed
(no matching packages found)
Permalink CVE-2026-47897
8.9 HIGH
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Attack Requirement (AT): Present (P)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): High (H)
  • Vulnerable System Impact Integrity (VI): None (N)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): High (H)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Automatable (AU): Yes (Y)
  • Vulnerability Response Effort (RE): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Attack Requirement (MAT): Present (P)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): High (H)
  • Modified Vulnerable System Impact Integrity (MVI): None (N)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): High (H)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 2 months, 1 week ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Apache Lucene.Net: Arbitrary file write from malicious server to Lucene.Net.Replicator client

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucene.Net.Replicator library). This issue affects Apache Lucene.Net.Replicator: from 4.8.0-beta00005 before 4.8.0-beta00018. Users are recommended to upgrade to version 4.8.0-beta00018, which fixes the issue.

Affected products

Lucene.Net.Replicator
  • <4.8.0-beta00018
Dismissed
(no matching packages found)
created 2 months, 1 week ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Gitea organization permission APIs expose private visibility information

Gitea versions before 1.25.5 have insufficient visibility checks in organization permission APIs for hidden members and private organizations.

Affected products

Gitea Open Source Git Server
  • <1.25.5
Dismissed
(no matching packages found)
Permalink CVE-2026-58291
6.1 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Exploit Code Maturity (E): Unproven (U)
  • Remediation Level (RL): Official Fix (O)
  • Report Confidence (RC): Confirmed (C)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
created 2 months, 1 week ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

Operation on a resource after expiration or release in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

Affected products

Microsoft Edge (Chromium-based)
  • <150.0.4078.48
Dismissed
(no matching packages found)
Permalink CVE-2026-57977
7.1 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): High (H)
  • Availability (A): None (N)
  • Exploit Code Maturity (E): Unproven (U)
  • Remediation Level (RL): Official Fix (O)
  • Report Confidence (RC): Confirmed (C)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): None (N)
created 2 months, 1 week ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Microsoft Edge (Chromium-based) Spoofing Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Affected products

Microsoft Edge (Chromium-based)
  • <150.0.4078.48
Dismissed
(max. allowed matches exceeded)
created 2 months, 1 week ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
HTTP/2 stream-dependency tree UAF

A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`. During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation.

References

Affected products

curl
  • =<8.13.0
  • =<8.14.1
  • =<8.0.0
  • =<8.6.0
  • =<8.0.1
  • =<8.18.0
  • =<8.10.1
  • =<8.15.0
  • =<8.9.1
  • =<8.11.0
  • =<8.14.0
  • =<8.4.0
  • =<8.5.0
  • =<8.2.0
  • =<8.1.1
  • =<8.7.0
  • =<7.88.1
  • =<8.1.0
  • =<8.2.1
  • =<8.9.0
  • =<8.16.0
  • =<7.88.0
  • =<8.7.1
  • =<8.12.0
  • =<8.10.0
  • =<8.8.0
  • =<8.1.2
  • =<8.3.0
  • =<8.19.0
  • =<8.17.0
  • =<8.11.1
  • =<8.20.0
  • =<8.12.1
Dismissed
(no matching packages found)
Permalink CVE-2026-14460
8.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 2 months, 1 week ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Missing Authorization in TUBITAK BILGEM's pardus-software

Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-software allows Argument Injection. This issue affects pardus-software: from <= 1.0.4 before 1.0.5.

Affected products

pardus-software
  • <1.0.5
Dismissed
(no matching packages found)
created 2 months, 1 week ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Gitea private organization labels are visible to unauthorized users

Gitea 1.26.2 allows unauthorized users to access labels of private organizations.

Affected products

Gitea Open Source Git Server
  • ==1.26.2