Nixpkgs security tracker

Try the new UI
Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Dismissed suggestions

These automatic suggestions were dismissed after initial triaging.

to select a suggestion for revision.

View:
Compact
Detailed
Dismissed
(no matching packages found)
Permalink CVE-2026-92466
8.7 HIGH
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): High (H)
  • Vulnerable System Impact Integrity (VI): High (H)
  • Vulnerable System Impact Availability (VA): High (H)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): High (H)
  • Modified Vulnerable System Impact Integrity (MVI): High (H)
  • Modified Vulnerable System Impact Availability (MVA): High (H)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 1 week, 4 days ago Activity log
  • Created & dismissed (no matching packages found) suggestion
microservices-platform through 6.0.0 Missing Authorization via Disabled URL Permission Checking

zlt2000 microservices-platform through 6.0.0 contains a missing authorization vulnerability where the zlt.security.auth.urlPermission.enable flag defaults to false, disabling all permission checks after authentication. Authenticated users with no roles can access administrative APIs including user management, role assignment, and Elasticsearch index operations by bypassing the disabled authorization enforcement.

Affected products

microservices-platform
  • =<6.0.0
Dismissed
(no matching packages found)
Permalink CVE-2026-77408
9.1 CRITICAL
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): Present (P)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): Low (L)
  • Vulnerable System Impact Integrity (VI): High (H)
  • Vulnerable System Impact Availability (VA): High (H)
  • Subsequent System Impact Confidentiality (SC): Low (L)
  • Subsequent System Impact Integrity (SI): High (H)
  • Subsequent System Impact Availability (SA): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): Present (P)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
  • Modified Vulnerable System Impact Integrity (MVI): High (H)
  • Modified Vulnerable System Impact Availability (MVA): High (H)
  • Modified Subsequent System Impact Confidentiality (MSC): Low (L)
  • Modified Subsequent System Impact Integrity (MSI): High (H)
  • Modified Subsequent System Impact Availability (MSA): Low (L)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 1 week, 4 days ago Activity log
  • Created & dismissed (no matching packages found) suggestion
RabbitMQ amqp091-go: Silent Data Truncation and State Corruption via Shortstr Integer Overflow

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, the writeShortstr function in write.go casts the byte length of AMQP shortstr property values to uint8 without first rejecting values longer than 255 bytes. An application that accepts an oversized CorrelationId, ReplyTo, MessageId, Expiration, UserId, AppId, ContentType, ContentEncoding, or Type value can therefore serialize a wrapped length and only a truncated prefix, while reporting no error. The resulting silent metadata corruption can break request and reply correlation, routing, tracing, and downstream message processing. This issue is fixed in version 1.13.0.

Affected products

amqp091-go
  • ==< 1.13.0
Dismissed
(no matching packages found)
Permalink CVE-2026-20330
9.9 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 1 week, 4 days ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Improper Neutralization Vulnerabilities

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. &nbsp; The vulnerabilities tracked by CVE-2026-20330 are related to improper neutralization issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-707.

Affected products

Cisco Secure Firewall Management Center (FMC)
  • ==7.6.2.1
  • ==7.4.2.1
  • ==7.7.12
  • ==7.2.8.1
  • ==7.0.9
  • ==7.0.4
  • ==7.3.1
  • ==7.6.0
  • ==7.4.2.3
  • ==7.2.10.1
  • ==7.0.3
  • ==7.0.5
  • ==7.7.0
  • ==7.0.6.1
  • ==7.6.3
  • ==10.0.1
  • ==7.2.2
  • ==7.2.4
  • ==7.2.0.1
  • ==7.2.9
  • ==7.2.1
  • ==7.4.4
  • ==7.7.10.1
  • ==7.0.8
  • ==7.2.6
  • ==7.0.6.3
  • ==7.6.1
  • ==7.4.2.4
  • ==7.4.0
  • ==7.4.5
  • ==7.4.2.2
  • ==7.2.3.1
  • ==7.2.5.2
  • ==7.2.3
  • ==7.7.10
  • ==7.0.1
  • ==7.0.2
  • ==7.3.1.1
  • ==7.0.0
  • ==7.6.4
  • ==7.2.10
  • ==10.0.0
  • ==7.0.6.2
  • ==7.4.6
  • ==7.2.11
  • ==7.6.2
  • ==7.2.0
  • ==7.0.1.1
  • ==7.0.8.1
  • ==7.0.2.1
  • ==7.2.5
  • ==7.0.6
  • ==7.2.8
  • ==7.0.7
  • ==7.4.3
  • ==7.7.11
  • ==7.2.7
  • ==7.3.1.2
  • ==7.6.5
  • ==7.2.10.2
  • ==7.2.5.1
  • ==7.4.1
  • ==7.4.1.1
  • ==7.2.4.1
  • ==7.4.2
  • ==7.3.0
  • ==7.4.7
  • ==7.0.0.1
Cisco Secure Firewall Threat Defense (FTD) Software
  • ==7.6.2.1
  • ==7.4.2.1
  • ==7.0.9
  • ==7.0.4
  • ==7.3.1
  • ==7.6.0
  • ==7.4.2.3
  • ==7.0.3
  • ==7.0.5
  • ==7.7.0
  • ==7.0.6.1
  • ==7.4.4
  • ==7.7.10.1
  • ==7.0.8
  • ==7.0.6.3
  • ==7.6.1
  • ==7.4.2.4
  • ==7.4.0
  • ==7.4.2.2
  • ==7.7.10
  • ==7.0.1
  • ==7.0.2
  • ==7.3.1.1
  • ==7.6.4
  • ==10.0.0
  • ==7.0.6.2
  • ==7.6.2
  • ==7.0.1.1
  • ==7.0.8.1
  • ==7.0.2.1
  • ==7.0.6
  • ==7.4.3
  • ==7.0.7
  • ==7.7.11
  • ==7.3.1.2
  • ==7.4.1
  • ==7.4.1.1
  • ==7.4.2
  • ==7.3.0
  • ==7.4.7
  • ==7.0.0.1
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
  • ==9.22.2
  • ==9.18.4.47
  • ==9.16.3.14
  • ==9.16.4.55
  • ==9.20.4.19
  • ==9.22.2.14
  • ==9.23.1.22
  • ==9.18.4.68
  • ==9.23.1.32
  • ==9.16.4.71
  • ==9.19.1.42
  • ==9.23.1.19
  • ==9.18.4.5
  • ==9.18.1.3
  • ==9.22.1.6
  • ==9.20.4.22
  • ==9.20.3
  • ==9.18.4.67
  • ==9.18.4.24
  • ==9.18.4.53
  • ==9.22.2.13
  • ==9.24.1.221
  • ==9.20.4.30
  • ==9.23.1.211
  • ==9.18.2.7
  • ==9.18.4
  • ==9.16.4.18
  • ==9.22.1.2
  • ==9.20.1.5
  • ==9.23.1.26
  • ==9.16.4.92
  • ==9.16.4.61
  • ==9.18.4.29
  • ==9.22.2.9
  • ==9.24.1.9
  • ==9.18.4.57
  • ==9.18.3.55
  • ==9.18.2.5
  • ==9.23.1.13
  • ==9.16.2.13
  • ==9.20.3.4
  • ==9.16.3
  • ==9.22.2.20
  • ==9.23.1.195
  • ==9.16.4.82
  • ==9.20.2.21
  • ==9.22.2.32
  • ==9.20.4.34
  • ==9.16.4.85
  • ==9.18.4.40
  • ==9.22.1.3
  • ==9.20.3.20
  • ==9.18.4.82
  • ==9.22.3.191
  • ==9.16.3.19
  • ==9.16.2
  • ==9.18.4.50
  • ==9.23.1.7
  • ==9.20.4.7
  • ==9.16.4.89
  • ==9.20.3.7
  • ==9.16.4.67
  • ==9.20.4.28
  • ==9.16.3.15
  • ==9.18.4.76
  • ==9.16.3.23
  • ==9.20.4.10
  • ==9.18.4.71
  • ==9.24.1.5
  • ==9.16.4.70
  • ==9.16.4.62
  • ==9.22.2.4
  • ==9.20.3.16
  • ==9.16.4.19
  • ==9.16.4.39
  • ==9.20.1
  • ==9.22.3
  • ==9.24.1
  • ==9.18.4.66
  • ==9.24.1.155
  • ==9.16.4.9
  • ==9.16.2.7
  • ==9.16.4.48
  • ==9.20.2.22
  • ==9.24.1.11
  • ==9.16.4.38
  • ==9.16.4.27
  • ==9.23.1
  • ==9.20.3.10
  • ==9.16.4
  • ==9.16.4.76
  • ==9.18.3.39
  • ==9.16.4.84
  • ==9.18.3.46
  • ==9.18.4.52
  • ==9.16.2.14
  • ==9.23.1.3
  • ==9.18.2.8
  • ==9.16.1.28
  • ==9.16.2.3
  • ==9.18.2
  • ==9.16.2.11
  • ==9.18.4.8
  • ==9.22.3.5
  • ==9.22.1.1
  • ==9.16.4.14
  • ==9.20.4
  • ==9.20.3.13
  • ==9.18.4.22
  • ==9.18.4.34
  • ==9.20.4.14
  • ==9.20.2.10
  • ==9.18.3
  • ==9.16.4.57
  • ==9.16.3.3
  • ==9.20.3.9
  • ==9.18.3.56
  • ==9.16.1
  • ==9.18.4.135
  • ==9.20.4.235
  • ==9.20.2
  • ==9.24.10
  • ==9.16.4.42
  • ==9.18.3.53
Dismissed
(no matching packages found)
Permalink CVE-2026-76448
4.9 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): High (H)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): None (N)
created 1 week, 4 days ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Cisco Identity Services Engine SQL Injection Vulnerability

A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to conduct an SQL or HQL injection attack on an affected device. This vulnerability is due to insufficient validation of user-supplied input to the affected APIs before it is used to build database queries. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to execute arbitrary SQL or HQL queries against the underlying database, which could allow the attacker to view or modify data that they are not authorized to access. To exploit this vulnerability, the attacker must have valid administrative credentials.

Affected products

Cisco ISE Passive Identity Connector
  • ==3.3.0
  • ==3.5.0
  • ==3.4.0
  • ==3.2.0
  • ==3.1.0
Cisco Identity Services Engine Software
  • ==3.1.0 p8
  • ==3.2 Patch 8
  • ==3.3 Patch 9
  • ==3.3.0
  • ==3.4 Patch 3
  • ==3.3 Patch 7
  • ==3.3 Patch 10
  • ==3.2.0
  • ==3.3 Patch 8
  • ==3.2.0 p4
  • ==3.5 Patch 1
  • ==3.3 Patch 2
  • ==3.3 Patch 6
  • ==3.4 Patch 1
  • ==3.1.0 p3
  • ==3.4 Patch 2
  • ==3.1.0 p2
  • ==3.3 Patch 5
  • ==3.4 Patch 6
  • ==3.2.0 p2
  • ==3.2.0 p6
  • ==3.1.0
  • ==3.2.0 p3
  • ==3.2.0 p7
  • ==3.5 Patch 3
  • ==3.3 Patch 4
  • ==3.4 Patch 5
  • ==3.1.0 p4
  • ==3.1.0 p7
  • ==3.1.0 p72
  • ==3.2.0 p1
  • ==3.1.0 p6
  • ==3.3 Patch 1
  • ==3.4.0
  • ==3.2.0 p5
  • ==3.4 Patch 4
  • ==3.1.0 p10
  • ==3.2 Patch 10
  • ==3.1.0 p9
  • ==3.3 Patch 3
  • ==3.5.0
  • ==3.1.0 p11
  • ==3.5 Patch 2
  • ==3.1.0 p1
  • ==3.2 Patch 9
  • ==3.3 Patch 11
  • ==3.1.0 p5
Dismissed
(max. allowed matches exceeded)
created 1 week, 4 days ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
accel/amdxdna: return early from a zero-length flush

In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: return early from a zero-length flush SYNC_BO does not constrain its size, so a request for zero bytes reaches drm_clflush_virt_range(), which ends with an unconditional clflushopt(end - 1). For an empty range that is the byte before the mapping, and abo->mem.kva comes from vmap(), so the access lands in the guard page below the vmalloc area and faults: BUG: unable to handle page fault for address: ffffd16fbbc70fff #PF: supervisor read access in kernel mode Oops: Oops: 0000 [#1] SMP NOPTI CPU: 7 UID: 1000 Comm: sync_bo_probe RIP: 0010:drm_clflush_virt_range+0x3c/0x70 Call Trace: amdxdna_drm_sync_bo_ioctl+0x124/0x430 [amdxdna] drm_ioctl+0x301/0x4c0 __x64_sys_ioctl+0x115/0x2f0 do_syscall_64+0xa6/0x3d0 Any process that can open the render node can do this. Reproduced 3 of 3 times on a Strix Point NPU (1022:17f0), by calling SYNC_BO with size 0 on an AMDXDNA_BO_SHARE object. The import arm takes the same request but flushes the whole scatterlist, so it survives it. Nothing needs flushing for an empty range, so answer before choosing a path.

Affected products

Linux
  • =<7.2.*
  • ==6.17
  • <f00def884a831dc49eb659dac2dd09dbfd21e67f
  • <6.17
  • =<6.18.*
  • =<*
  • <45962da5821d0a691f638ccb13842889156d8969
  • <dc14753664240cedf669623b27ae9922b0618b25
Dismissed
(no matching packages found)
Permalink CVE-2026-92804
7.1 HIGH
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): High (H)
  • Vulnerable System Impact Integrity (VI): Low (L)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): High (H)
  • Modified Vulnerable System Impact Integrity (MVI): Low (L)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 1 week, 4 days ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Nango through 0.70.4 Server-Side Request Forgery via Configuration

Nango through 0.70.4 fails to validate caller-supplied connection configuration values interpolated into provider token and proxy URL templates. Authenticated attackers can supply malicious configuration values to direct server requests at internal addresses or cloud metadata endpoints, potentially exfiltrating provider credentials.

Affected products

Nango
  • =<0.70.4
Dismissed
(no matching packages found)
Permalink CVE-2026-20306
9.1 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 1 week, 4 days ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Cisco Identity Services Engine Command Injection Vulnerability

A vulnerability in the REST API of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted commands to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the device and elevate privileges to root. In single-node deployments, successful exploitation of this vulnerability could cause the affected ISE node to become unavailable, resulting in a DoS condition. In that condition, endpoints that have not already authenticated would be unable to access the network until the node is restored.

Affected products

Cisco ISE Passive Identity Connector
  • ==3.4.0
Cisco Identity Services Engine Software
  • ==3.5 Patch 3
  • ==3.4 Patch 5
  • ==3.4 Patch 6
  • ==3.4 Patch 4
Dismissed
(no matching packages found)
Permalink CVE-2026-92469
7.2 HIGH
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): None (N)
  • Vulnerable System Impact Integrity (VI): High (H)
  • Vulnerable System Impact Availability (VA): High (H)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): None (N)
  • Modified Vulnerable System Impact Integrity (MVI): High (H)
  • Modified Vulnerable System Impact Availability (MVA): High (H)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 1 week, 4 days ago Activity log
  • Created & dismissed (no matching packages found) suggestion
microservices-platform through 6.0.0 Arbitrary File Deletion via Missing Ownership Check

zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the file-center module DELETE /files/{id} endpoint that performs no ownership validation. Authenticated attackers can enumerate file identifiers via GET /files and delete arbitrary users' files and metadata by supplying their identifiers to the delete endpoint.

Affected products

microservices-platform
  • =<6.0.0
Dismissed
(max. allowed matches exceeded)
created 1 week, 4 days ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
media: chips-media: wave5: Add timeout while stop_streaming

In the Linux kernel, the following vulnerability has been resolved: media: chips-media: wave5: Add timeout while stop_streaming When stop_streaming is called, an infinite loop may occur in some cases. Add a bounded poll of the queue status: loop until the queues drain, sleeping briefly between polls, and bail out once VPU_DEC_STOP_TIMEOUT elapses.

Affected products

Linux
  • =<7.2.*
  • <c104f37b9f79d6c179c5f1a170d7f1da497ff527
  • =<*
  • ==6.8
  • <2ae7faed2e60d6d07d9efdd962d20dcb15330ced
  • <6.8
Dismissed
(max. allowed matches exceeded)
Permalink CVE-2026-89844
8.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Adjacent (A)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Adjacent (A)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 1 week, 4 days ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
scsi: qla2xxx: Hold vport_slock for host map update in report ID acquisition

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Hold vport_slock for host map update in report ID acquisition qla24xx_report_id_acquisition() format-1 handling drops vport_slock after taking the vport reference and then calls qla_update_host_map() without the lock. That reaches qla_update_vp_map(), which mutates the ha->host_map btree via btree_insert32()/btree_update32()/btree_remove32() and is documented to require vport_slock to be held by the caller. Running it unlocked can race concurrent host_map updates and corrupt the btree. The format-2 path in the same function already wraps its host_map update (SET_AL_PA) in vport_slock; the format-1 path is the lone outlier. Hold vport_slock across the format-1 qla_update_host_map() call to honor the documented locking contract. The vref_count taken in the loop keeps the vport valid, so this only adds the missing host_map serialization.

Affected products

Linux
  • =<7.2.*
  • <6.3
  • =<6.12.*
  • =<6.18.*
  • <7d0b3f745efb24c0aac5e06b49b3420bc65d23b9
  • =<*
  • <776e4e8cbcf155302f430ce9793d1502e3c113a0
  • <7944039ba9cb5c3a935d17c91004e3b8649ff58e
  • ==6.3
  • <e8f1b0cb9782338c6341ceed816e9c1243743cdd
  • <6ed66e2a67bbd22877008ff9aa64bd574a7fc011
  • =<6.6.*