Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Dismissed suggestions

These automatic suggestions were dismissed after initial triaging.

to select a suggestion for revision.

View:
Compact
Detailed
Dismissed
(exclusively hosted service)
Permalink CVE-2026-32169
10.0 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Exploit Code Maturity (E): Unproven (U)
  • Remediation Level (RL): Official Fix (O)
  • Report Confidence (RC): Confirmed (C)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 4 months ago Activity log
  • Created suggestion
Azure Cloud Shell Elevation of Privilege Vulnerability

Server-side request forgery (ssrf) in Azure Cloud Shell allows an unauthorized attacker to elevate privileges over a network.

Affected products

Azure Cloud Shell
  • ==-
Dismissed
(exclusively hosted service)
Permalink CVE-2026-23651
6.7 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Exploit Code Maturity (E): Proof-of-Concept (P)
  • Remediation Level (RL): Official Fix (O)
  • Report Confidence (RC): Confirmed (C)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 4 months, 2 weeks ago Activity log
  • Created suggestion
Microsoft ACI Confidential Containers Elevation of Privilege Vulnerability

Permissive regular expression in Azure Compute Gallery allows an authorized attacker to elevate privileges locally.

Affected products

Microsoft ACI Confidential Containers
  • ==-
Dismissed
(exclusively hosted service)
Permalink CVE-2026-26124
6.7 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Exploit Code Maturity (E): Proof-of-Concept (P)
  • Remediation Level (RL): Official Fix (O)
  • Report Confidence (RC): Confirmed (C)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 4 months, 2 weeks ago Activity log
  • Created suggestion
Microsoft ACI Confidential Containers Elevation of Privilege Vulnerability

Microsoft ACI Confidential Containers Elevation of Privilege Vulnerability

Affected products

Microsoft ACI Confidential Containers
  • ==-
Dismissed
(exclusively hosted service)
Permalink CVE-2026-26125
8.6 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Exploit Code Maturity (E): Proof-of-Concept (P)
  • Remediation Level (RL): Official Fix (O)
  • Report Confidence (RC): Confirmed (C)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
created 4 months, 2 weeks ago Activity log
  • Created suggestion
Payment Orchestrator Service Elevation of Privilege Vulnerability

Payment Orchestrator Service Elevation of Privilege Vulnerability

Affected products

Payment Orchestrator Service
  • ==-
Dismissed
(exclusively hosted service)
Permalink CVE-2026-21536
9.8 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Exploit Code Maturity (E): Unproven (U)
  • Remediation Level (RL): Official Fix (O)
  • Report Confidence (RC): Confirmed (C)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 4 months, 2 weeks ago Activity log
  • Created suggestion
Microsoft Devices Pricing Program Remote Code Execution Vulnerability

Microsoft Devices Pricing Program Remote Code Execution Vulnerability

Affected products

Microsoft Devices Pricing Program
  • ==-
Dismissed
(exclusively hosted service)
Permalink CVE-2026-26122
6.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Exploit Code Maturity (E): Unproven (U)
  • Remediation Level (RL): Official Fix (O)
  • Report Confidence (RC): Confirmed (C)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
created 4 months, 2 weeks ago Activity log
  • Created suggestion
Microsoft ACI Confidential Containers Information Disclosure Vulnerability

Microsoft ACI Confidential Containers Information Disclosure Vulnerability

Affected products

Microsoft ACI Confidential Containers
  • ==-
Permalink CVE-2025-47379
7.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 4 months, 2 weeks ago by @Erethon Activity log
  • Created suggestion
  • @Erethon dismissed
  • @Erethon accepted
  • @Erethon dismissed
Use After Free in Automotive Audio

Memory Corruption when concurrent access to shared buffer occurs due to improper synchronization between assignment and deallocation of buffer resources.

Affected products

Snapdragon
  • ==SM7550P
  • ==Snapdragon W5+ Gen 1 Wearable Platform
  • ==WSA8845H
  • ==SA4150P
  • ==SA4155P
  • ==QCA6696
  • ==FastConnect 7800
  • ==QCS8550
  • ==Robotics RB2 Platform
  • ==Qualcomm 215 Mobile Platform
  • ==QCA6574AU
  • ==QCN6274
  • ==MDM9628
  • ==WSA8840
  • ==QCA6174A
  • ==SA8145P
  • ==QCS2290
  • ==WCD9380
  • ==QCA6574A
  • ==Milos
  • ==SA6150P
  • ==SM6650P
  • ==SM7675P
  • ==WCN3988
  • ==WCN6650
  • ==QRB5165N
  • ==SA6155P
  • ==SnapdragonAuto 4GModem
  • ==SA6155
  • ==QCA8695AU
  • ==Snapdragon XR2 5G Platform
  • ==WCD9360
  • ==SM7635P
  • ==Snapdragon 4 Gen 1 Mobile Platform
  • ==Snapdragon Auto 5G Modem-RF Gen 2
  • ==MDM9250
  • ==Qualcomm Video Collaboration VC1 Platform
  • ==Snapdragon X53 5G Modem-RF System
  • ==SRV1M
  • ==AR8031
  • ==Snapdragon 6 Gen 4 Mobile Platform
  • ==WCD9390
  • ==Snapdragon 870 5G Mobile Platform
  • ==WSA8832
  • ==QCA6688AQ
  • ==QCA6698AQ
  • ==SA7255P
  • ==QCA6595
  • ==QCA6678AQ
  • ==QCM6125
  • ==Snapdragon 8 Gen 2 Mobile Platform
  • ==QAM8295P
  • ==QFW7114
  • ==FastConnect 6700
  • ==Snapdragon 888 5G Mobile Platform
  • ==Snapdragon 8 Gen 3 Mobile Platform
  • ==G1 Gen 1
  • ==WCD9326
  • ==WCD9375
  • ==WCD9370
  • ==QCA9367
  • ==Snapdragon 680 4G Mobile Platform
  • ==WCN6450
  • ==QCA6584AU
  • ==Qualcomm Video Collaboration VC3 Platform
  • ==QRB5165M
  • ==SM8635
  • ==Snapdragon 7s Gen 3 Mobile Platform
  • ==Snapdragon 865 5G Mobile Platform
  • ==FastConnect 6800
  • ==SA7775P
  • ==SA8155
  • ==QCA6797AQ
  • ==WCD9385
  • ==QCA6698AU
  • ==QCC710
  • ==SW5100P
  • ==WSA8810
  • ==Snapdragon X35 5G Modem-RF System
  • ==SA8770P
  • ==SA8620P
  • ==Snapdragon X75 5G Modem-RF System
  • ==SA8155P
  • ==Snapdragon 660 Mobile Platform
  • ==Snapdragon X55 5G Modem-RF System
  • ==AR8035
  • ==WCD9340
  • ==SA2150P
  • ==QCM4325
  • ==WCD9335
  • ==WSA8845
  • ==SM7550
  • ==WCN3980
  • ==Snapdragon 782G Mobile Platform
  • ==SM7675
  • ==SRV1H
  • ==WCN3990
  • ==QCA6595AU
  • ==Snapdragon 662 Mobile Platform
  • ==WCN3680B
  • ==WCD9378
  • ==SA8150P
  • ==QCA6564
  • ==QCA8337
  • ==5G Fixed Wireless Access Platform
  • ==SA6145P
  • ==Snapdragon X32 5G Modem-RF System
  • ==Snapdragon 778G 5G Mobile Platform
  • ==SA8255P
  • ==QAMSRV1H
  • ==LeMans_AU_LGIT
  • ==FastConnect 6200
  • ==QCS4290
  • ==WSA8815
  • ==SM7325P
  • ==QCA6574
  • ==FastConnect 6900
  • ==Snapdragon 460 Mobile Platform
  • ==SM8550P
  • ==SDA660
  • ==Snapdragon 8+ Gen 2 Mobile Platform
  • ==WCN3660B
  • ==FWA Gen 3 Ultra Platform
  • ==QAMSRV1M
  • ==QCN9011
  • ==CSRA6620
  • ==SM6225P
  • ==WSA8835
  • ==Snapdragon 778G+ 5G Mobile Platform
  • ==QEP8111
  • ==Flight RB5 5G Platform
  • ==QCA6391
  • ==QCM2290
  • ==SD865 5G
  • ==Snapdragon X12 LTE Modem
  • ==Snapdragon 480 5G Mobile Platform
  • ==Qualcomm Video Collaboration VC5 Platform
  • ==QCA9377
  • ==Snapdragon 695 5G Mobile Platform
  • ==C-V2X 9150
  • ==Snapdragon X72 5G Modem-RF System
  • ==Snapdragon XR2+ Gen 1 Platform
  • ==QCA2066
  • ==QCA8081
  • ==WCD9371
  • ==WSA8830
  • ==LeMansAU
  • ==SA8295P
  • ==WCN3950
  • ==QCA6564A
  • ==SA9000P
  • ==WCD9395
  • ==SM8635P
  • ==Robotics RB5 Platform
  • ==QAM8255P
  • ==Snapdragon Auto 5G Modem-RF
  • ==WCN6755
  • ==CSRA6640
  • ==QFW7124
  • ==SA8195P
  • ==Snapdragon 690 5G Mobile Platform
  • ==QCN6224
  • ==WCN3910
  • ==Snapdragon 865+ 5G Mobile Platform
  • ==Snapdragon 888+ 5G Mobile Platform
  • ==QCM6490
  • ==Smart Audio 400 Platform
  • ==Snapdragon 685 4G Mobile Platform
  • ==SW5100
  • ==SD662
  • ==WCD9341
  • ==WCN3615
  • ==QCN9012
  • ==QCA6564AU
  • ==Snapdragon 7c+ Gen 3 Compute
  • ==QCM5430
  • ==Snapdragon 480+ 5G Mobile Platform
  • ==SM8650Q

Matching in nixpkgs

Testing suggestion edit
Testing round #2
Test round #3
Dismissed
(exclusively hosted service)
Permalink CVE-2026-26365
4.0 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
updated 4 months, 2 weeks ago by @ADMIN Activity log
  • Created suggestion
  • @ADMIN dismissed
Akamai Ghost on Akamai CDN edge servers before 2026-02-06 mishandles …

Akamai Ghost on Akamai CDN edge servers before 2026-02-06 mishandles processing of custom hop-by-hop HTTP headers, where an incoming request containing the header "Connection: Transfer-Encoding" could result in a forward request with invalid message framing, depending on the Akamai processing path. This could result in the origin server parsing the request body incorrectly, leading to HTTP request smuggling.

Affected products

Ghost
  • <2026-02-06

Matching in nixpkgs

pkgs.ghostie

Github notifications in your terminal

pkgs.ghostty

Fast, native, feature-rich terminal emulator pushing modern features

pkgs.ghostunnel

TLS proxy with mutual authentication support for securing non-TLS backend applications

pkgs.ghostty-bin

Fast, native, feature-rich terminal emulator pushing modern features

Package maintainers

Dismissed
(exclusively hosted service)
Permalink CVE-2025-54914
10.0 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Exploit Code Maturity (E): Unproven (U)
  • Remediation Level (RL): Official Fix (O)
  • Report Confidence (RC): Confirmed (C)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 4 months, 2 weeks ago by @ADMIN Activity log
  • Created suggestion
  • @ADMIN dismissed
Azure Networking Elevation of Privilege Vulnerability

Azure Networking Elevation of Privilege Vulnerability

Affected products

Networking
  • ==-
  • ==N/A

Matching in nixpkgs

Package maintainers

Permalink CVE-2026-2968
3.7 LOW
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Exploit Code Maturity (E): Proof-of-Concept (P)
  • Remediation Level (RL): Not Defined (X)
  • Report Confidence (RC): Reasonable (R)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
updated 4 months, 3 weeks ago by @fricklerhandwerk Activity log
  • Created suggestion
  • @fricklerhandwerk ignored package mongoose
  • @fricklerhandwerk dismissed
Cesanta Mongoose Poly1305 Authentication Tag tls_chacha20.c mg_chacha20_poly1305_decrypt signature verification

A vulnerability was detected in Cesanta Mongoose up to 7.20. This impacts the function mg_chacha20_poly1305_decrypt of the file /src/tls_chacha20.c of the component Poly1305 Authentication Tag Handler. The manipulation results in improper verification of cryptographic signature. The attack may be launched remotely. This attack is characterized by high complexity. The exploitability is said to be difficult. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Affected products

Mongoose
  • ==7.19
  • ==7.4
  • ==7.3
  • ==7.18
  • ==7.16
  • ==7.14
  • ==7.15
  • ==7.2
  • ==7.6
  • ==7.8
  • ==7.17
  • ==7.5
  • ==7.13
  • ==7.12
  • ==7.9
  • ==7.0
  • ==7.1
  • ==7.7
  • ==7.11
  • ==7.20
  • ==7.10
Ignored packages (1)

pkgs.mongoose

Graph Coarsening and Partitioning Library

Not in Nixpkgs (the one in Nixpkgs is a different one)