Nixpkgs security tracker

Try the new UI
Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Dismissed suggestions

These automatic suggestions were dismissed after initial triaging.

to select a suggestion for revision.

View:
Compact
Detailed
Dismissed
(no matching packages found)
Permalink CVE-2026-84993
6.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
created 1 week, 2 days ago Activity log
  • Created & dismissed (no matching packages found) suggestion
MikroORM: SQL injection via unvalidated order direction in orderBy

MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to 6.6.16 and 7.1.7, the shared SQL layer validates the field key of an orderBy clause but does not validate its direction value before AbstractSqlPlatform.getOrderByExpression concatenates it into an ORDER BY clause. Applications that bind attacker-controlled request data to the direction in em.find(), em.findOne(), em.findAndCount(), QueryBuilder.orderBy(), or QueryBuilderHelper.getQueryOrderFromObject() can permit a raw SQL fragment that performs blind or boolean extraction of data available to the database account. The BaseMySqlPlatform and MsSqlPlatform fallthrough paths have the same behavior, affecting SQLite, PostgreSQL, MySQL, MariaDB, MSSQL, libSQL, and Oracle drivers, while MongoDB is not affected. This issue is fixed in versions 6.6.16 and 7.1.7.

Affected products

mikro-orm
  • ==>= 7.0.0, < 7.1.7
  • ==< 6.6.16
Dismissed
(max. allowed matches exceeded)
created 1 week, 2 days ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
ASoC: hdac_hda: Fix hlink refcount leak on component registration failure

In the Linux kernel, the following vulnerability has been resolved: ASoC: hdac_hda: Fix hlink refcount leak on component registration failure hdac_hda_dev_probe() gets the HDA link with snd_hdac_ext_bus_link_get() before registering the ASoC component. If component registration fails, the function returns without dropping the link reference. Always call snd_hdac_ext_bus_link_put() after the registration attempt so the reference taken during probe is balanced on both success and failure.

Affected products

Linux
  • =<7.2.*
  • <6ad4892c4f5cb437a928a02f5b7d37d496aa9268
  • <4.20
  • ==4.20
  • <e8ea01a0457080b0cc7c69c430c0ab65d84dc377
  • =<6.12.*
  • <7eef9ae3b4ef782557526dd8ba0c206f028d8c2f
  • =<6.18.*
  • =<*
  • <cb6b0b1a9d5a61ef841739d42c6211094e9c8e2c
Dismissed
(no matching packages found)
Permalink CVE-2026-75513
9.1 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): Low (L)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): Low (L)
created 1 week, 2 days ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Marten: SQL injection in Marten's LINQ provider via unescaped string literals

Marten is a .NET Transactional Document DB and Event Store on PostgreSQL. From version 7.0.0 until 9.13.0, several Marten LINQ and tenant-management paths interpolate runtime, potentially attacker-controlled strings into single-quoted SQL literals without escaping or parameterization. The primary confirmed vector is a dictionary indexer key used by Where filters in src/Marten/Linq/Members/Dictionaries/DictionaryItemMember.cs. Additional affected sinks include SelectParser.cs, DatabaseScopedTenantPartitions.cs, and DeleteAllForTenant.cs reached through IEventStore.DeleteProjectionProgressAsync, while DictionaryContainsKeyFilter.cs (Newtonsoft serializer only; System.Text.Json is not affected) handles ContainsKey calls. Events/Daemon/Internals/EventLoader.cs contains a related per-tenant partition-pruning literal that the advisory identifies as a defense-in-depth sink. A crafted single quote can escape the generated literal, enabling filter or multi-tenant authorization bypass and blind data exfiltration, and deployments that permit semicolon-batched Npgsql statements may also allow data modification. This issue is fixed in version 9.13.0.

Affected products

marten
  • ==>= 7.0.0, < 9.13.0
Dismissed
(no matching packages found)
Permalink CVE-2026-76460
10.0 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 1 week, 2 days ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Cisco Identity Services Engine Authentication Bypass Vulnerability

A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.

Affected products

Cisco ISE Passive Identity Connector
  • ==3.5.0
  • ==3.4.0
Cisco Identity Services Engine Software
  • ==3.1.0 p8
  • ==3.2 Patch 8
  • ==3.3 Patch 9
  • ==3.4 Patch 3
  • ==3.3 Patch 10
  • ==3.3 Patch 7
  • ==3.3 Patch 8
  • ==3.5 Patch 1
  • ==3.3 Patch 2
  • ==3.3 Patch 6
  • ==3.4 Patch 1
  • ==3.4 Patch 2
  • ==3.4 Patch 6
  • ==3.3 Patch 5
  • ==3.2.0 p7
  • ==3.5 Patch 3
  • ==3.3 Patch 4
  • ==3.4 Patch 5
  • ==3.3 Patch 1
  • ==3.4.0
  • ==3.1.0 p10
  • ==3.4 Patch 4
  • ==3.2 Patch 10
  • ==3.1.0 p9
  • ==3.3 Patch 3
  • ==3.5.0
  • ==3.1.0 p11
  • ==3.5 Patch 2
  • ==3.3 Patch 11
  • ==3.2 Patch 9
Dismissed
(no matching packages found)
Permalink CVE-2026-92216
5.3 MEDIUM
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Passive (P)
  • Vulnerable System Impact Confidentiality (VC): None (N)
  • Vulnerable System Impact Integrity (VI): Low (L)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Exploit Maturity (E): Not Defined (X)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Passive (P)
  • Modified Vulnerable System Impact Confidentiality (MVC): None (N)
  • Modified Vulnerable System Impact Integrity (MVI): Low (L)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
created 1 week, 2 days ago Activity log
  • Created & dismissed (no matching packages found) suggestion
a2ui-project a2ui Binder generic-binder.ts openUrl redirect

A vulnerability was found in a2ui-project a2ui up to 0.10.7. Affected by this issue is the function openUrl of the file renderers/web_core/src/v0_9/rendering/generic-binder.ts of the component Binder. The manipulation results in open redirect. It is possible to launch the attack remotely. The project was informed of the problem early through an issue report but has not responded yet.

Affected products

a2ui
  • ==0.10.5
  • ==0.10.3
  • ==0.10.0
  • ==0.10.6
  • ==0.10.1
  • ==0.10.2
  • ==0.10.7
  • ==0.10.4
Dismissed
(no matching packages found)
Permalink CVE-2026-27549
8.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 1 week, 2 days ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Command Injection in /index.php/attached_devices_tab/do_upload

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/do_upload endpoint using operator credentials allowing execution of commands with root privileges on the device.

Affected products

YL212CEI8M1IO
  • <1.7.4
YL212CPN8M1IO
  • <1.7.4
YN115CEI8RPIO
  • <1.7.4
YN115CPN8RPIO
  • <1.7.4
IOL MA8 PN DI8
  • <1.7.4
IOL MA8 EIP DI8
  • <1.7.4
ICE2-8IOL-G65L-V1D
  • <1.7.4
ICE3-8IOL-G65L-V1D
  • <1.7.4
ICE2-8IOL-K45P-RJ45
  • <1.7.4
ICE2-8IOL-K45S-RJ45
  • <1.7.4
ICE2-8IOL1-G65L-V1D
  • <1.7.4
ICE3-8IOL-K45P-RJ45
  • <1.7.4
ICE3-8IOL-K45S-RJ45
  • <1.7.4
ICE3-8IOL1-G65L-V1D
  • <1.7.4
ICE3-8IOL-G65L-V1D-Y
  • <1.7.4
Dismissed
(max. allowed matches exceeded)
created 1 week, 2 days ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
iio: chemical: atlas-sensor: fix PM reference leak in buffer postenable

In the Linux kernel, the following vulnerability has been resolved: iio: chemical: atlas-sensor: fix PM reference leak in buffer postenable atlas_buffer_postenable() acquires a runtime PM reference with pm_runtime_resume_and_get() but returns the result of atlas_set_interrupt() directly. If atlas_set_interrupt() fails, the runtime PM reference is leaked and the device can never autosuspend. Add pm_runtime_put_autosuspend() on the error path to balance the reference.

Affected products

Linux
  • =<7.2.*
  • <aedf8f068d9da774d5cb62e9c9d6e62b2ce64d86
  • ==5.14
  • =<6.12.*
  • <c7e91ae6d7802170f53ece09a4ecc6302265d3e4
  • <72daa7eb7fc6202fece0bb56487d72af5c49ccdf
  • =<5.15.*
  • <bcd3f72e26314edfce7eaf8d7160b3119c7b7fed
  • =<6.18.*
  • <43bce901047e95bbf8fb63eb471460642e497604
  • <777e8ebfe6b3fa733694977f0f4cf849e07e925c
  • =<*
  • =<6.1.*
  • =<6.6.*
  • <5.14
  • <a595f4d3e4ee1c91c62a298730a77b16dc26b426
Dismissed
(no matching packages found)
Permalink CVE-2026-92749
9.2 CRITICAL
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Attack Requirement (AT): Present (P)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): High (H)
  • Vulnerable System Impact Integrity (VI): High (H)
  • Vulnerable System Impact Availability (VA): High (H)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Attack Requirement (MAT): Present (P)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): High (H)
  • Modified Vulnerable System Impact Integrity (MVI): High (H)
  • Modified Vulnerable System Impact Availability (MVA): High (H)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 1 week, 2 days ago Activity log
  • Created & dismissed (no matching packages found) suggestion
SafeLine through 9.4.1 Authentication Bypass via Weak Session Secret

SafeLine through 9.4.1 derives the management console session-signing secret from a time-seeded math/rand generator, allowing attackers to reconstruct the key offline. Unauthenticated remote attackers who can bound the install timestamp can regenerate the secret and forge valid administrator session cookies to gain control of protected sites.

Affected products

SafeLine
  • =<9.4.1
Dismissed
(max. allowed matches exceeded)
created 1 week, 2 days ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
usb: image: mdc800: change kmalloc() to kzalloc()

In the Linux kernel, the following vulnerability has been resolved: usb: image: mdc800: change kmalloc() to kzalloc() Change the kmalloc() calls in usb_mdc800_init() for irq_urb_buffer and download_urb_buffer to kzalloc(), avoiding potential stack leaks if a shorter message is received in mdc800_usb_irq() and mdc800_usb_download_notify()

Affected products

Linux
  • <5.10.270
  • =<6.18.*
  • =<6.1.*
  • <553c375e86a49882e95840565512e17bff31cc3a
  • <6.12.110
  • =<6.12.*
  • <838455cc8bfe1278150d1d776529edea6cd4c1dd
  • =<*
  • <6.1.188
  • <6c601410d1a9ae645f604fe2f61b9f4942c77dfb
  • <8c38049879f2108f57c98f03cc7f3db51a12bdab
  • <2430eb81e44111b30eeb5273bbcf8b24ca517ef9
  • =<5.15.*
  • <6.6.157
  • <6.18.51
  • <7.2.5
  • =<7.2.*
  • <2df8f7720ed91f1aad4f128553b6e90c7c5fac1e
  • <67c6726dd6048a2781aa43a2bf9fcf1e16ee3a7d
  • <5.15.221
  • =<6.6.*
  • <e22428f0c038c23109c0383a235aa607b0cd4c95
  • =<5.10.*
Dismissed
(no matching packages found)
created 1 week, 2 days ago Activity log
  • Created & dismissed (no matching packages found) suggestion
LearnPress < 4.4.7 - Unauthenticated Unpublished Course Disclosure via REST API

The LearnPress WordPress plugin before 4.4.7 does not check the user's capabilities before applying a user supplied post status filter in one of its REST routes, allowing unauthenticated attackers to list courses that are not published, including draft, pending, private, scheduled and trashed ones.

References

Affected products

LearnPress
  • <4.4.7