Nixpkgs security tracker

Try the new UI
Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Dismissed suggestions

These automatic suggestions were dismissed after initial triaging.

to select a suggestion for revision.

View:
Compact
Detailed
Dismissed
(no matching packages found)
Permalink CVE-2026-71343
7.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Exploit Code Maturity (E): Unproven (U)
  • Remediation Level (RL): Official Fix (O)
  • Report Confidence (RC): Confirmed (C)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 1 week, 3 days ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Windows Remote Access Connection Manager Remote Code Execution Vulnerability

Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to execute code locally.

Affected products

Windows Server 2012
  • <6.2.9200.26349
Windows Server 2016
  • <10.0.14393.9512
Windows Server 2019
  • <10.0.17763.9245
Windows Server 2022
  • <10.0.20348.5622
Windows Server 2025
  • <10.0.26100.33438
Windows Server 2012 R2
  • <6.3.9600.23397
Windows 10 Version 1607
  • <10.0.14393.9512
Windows 10 Version 1809
  • <10.0.17763.9245
Windows 10 Version 21H2
  • <10.0.19044.7725
Windows 10 Version 22H2
  • <10.0.19045.7725
Windows 11 Version 23H2
  • <10.0.22631.7582
Windows 11 Version 24H2
  • <10.0.26100.9445
Windows 11 Version 25H2
  • <10.0.26200.9445
Windows 11 version 23H2
  • <10.0.22631.7582
Windows 11 version 26H1
  • <10.0.28000.2954
Windows Server 2012 (Server Core installation)
  • <6.2.9200.26349
Windows Server 2016 (Server Core installation)
  • <10.0.14393.9512
Windows Server 2019 (Server Core installation)
  • <10.0.17763.9245
Windows Server 2025 (Server Core installation)
  • <10.0.26100.33438
Windows Server 2012 R2 (Server Core installation)
  • <6.3.9600.23397
Dismissed
(no matching packages found)
Permalink CVE-2026-75657
5.4 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): Required (R)
  • Scope (S): Changed (C)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
created 1 week, 3 days ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.

Affected products

Adobe Experience Manager 6.5
  • ==6.5.25
  • =<6.5.24
Adobe Experience Manager 6.5 LTS
  • =<SP2
  • ==SP3
Adobe Experience Manager as a Cloud Service
  • =<2026.7.0
  • ==2026.8.0
Dismissed
(no matching packages found)
Permalink CVE-2026-69579
9.8 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Exploit Code Maturity (E): Unproven (U)
  • Remediation Level (RL): Official Fix (O)
  • Report Confidence (RC): Confirmed (C)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 1 week, 3 days ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Windows Message Queuing Remote Code Execution Vulnerability

Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.

Affected products

Windows Server 2012
  • <6.2.9200.26349
Windows Server 2016
  • <10.0.14393.9512
Windows Server 2019
  • <10.0.17763.9245
Windows Server 2022
  • <10.0.20348.5622
Windows Server 2025
  • <10.0.26100.33438
Windows Server 2012 R2
  • <6.3.9600.23397
Windows 10 Version 1607
  • <10.0.14393.9512
Windows 10 Version 1809
  • <10.0.17763.9245
Windows 10 Version 21H2
  • <10.0.19044.7725
Windows 10 Version 22H2
  • <10.0.19045.7725
Windows 11 Version 23H2
  • <10.0.22631.7582
Windows 11 Version 24H2
  • <10.0.26100.9445
Windows 11 Version 25H2
  • <10.0.26200.9445
Windows 11 version 23H2
  • <10.0.22631.7582
Windows 11 version 26H1
  • <10.0.28000.2954
Windows Server 2012 (Server Core installation)
  • <6.2.9200.26349
Windows Server 2016 (Server Core installation)
  • <10.0.14393.9512
Windows Server 2019 (Server Core installation)
  • <10.0.17763.9245
Windows Server 2025 (Server Core installation)
  • <10.0.26100.33438
Windows Server 2012 R2 (Server Core installation)
  • <6.3.9600.23397
Dismissed
(no matching packages found)
Permalink CVE-2026-69817
7.0 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Exploit Code Maturity (E): Unproven (U)
  • Remediation Level (RL): Official Fix (O)
  • Report Confidence (RC): Confirmed (C)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 1 week, 3 days ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Windows Bluetooth Port Driver Elevation of Privilege Vulnerability

Use after free in Windows Bluetooth Port Driver allows an authorized attacker to elevate privileges locally.

Affected products

Windows Server 2012
  • <6.2.9200.26349
Windows Server 2016
  • <10.0.14393.9512
Windows Server 2019
  • <10.0.17763.9245
Windows Server 2022
  • <10.0.20348.5622
Windows Server 2025
  • <10.0.26100.33438
Windows Server 2012 R2
  • <6.3.9600.23397
Windows 10 Version 1607
  • <10.0.14393.9512
Windows 10 Version 1809
  • <10.0.17763.9245
Windows 10 Version 21H2
  • <10.0.19044.7725
Windows 10 Version 22H2
  • <10.0.19045.7725
Windows 11 Version 23H2
  • <10.0.22631.7582
Windows 11 Version 24H2
  • <10.0.26100.9445
Windows 11 Version 25H2
  • <10.0.26200.9445
Windows 11 version 23H2
  • <10.0.22631.7582
Windows 11 version 26H1
  • <10.0.28000.2954
Windows Server 2012 (Server Core installation)
  • <6.2.9200.26349
Windows Server 2016 (Server Core installation)
  • <10.0.14393.9512
Windows Server 2019 (Server Core installation)
  • <10.0.17763.9245
Windows Server 2025 (Server Core installation)
  • <10.0.26100.33438
Windows Server 2012 R2 (Server Core installation)
  • <6.3.9600.23397
Dismissed
(no matching packages found)
Permalink CVE-2026-78620
5.9 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): None (N)
created 1 week, 3 days ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Improper Path Validation in Okta Access Gateway Kerberos Configuration Handling

The Okta Access Gateway Kerberos configuration handler does not validate file paths specified in event payloads before writing file contents. The path from the event payload is used directly as the write destination, resulting in files being written to unintended locations on the appliance filesystem.

Affected products

Okta Access Gateway
  • <2026.9.1
Dismissed
(no matching packages found)
Permalink CVE-2026-71341
5.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Exploit Code Maturity (E): Unproven (U)
  • Remediation Level (RL): Official Fix (O)
  • Report Confidence (RC): Confirmed (C)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
created 1 week, 3 days ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Windows Partition Management Driver Information Disclosure Vulnerability

Out-of-bounds read in Windows Partition Management Driver allows an authorized attacker to disclose information locally.

Affected products

Windows Server 2012
  • <6.2.9200.26349
Windows Server 2016
  • <10.0.14393.9512
Windows Server 2019
  • <10.0.17763.9245
Windows Server 2022
  • <10.0.20348.5622
Windows Server 2025
  • <10.0.26100.33438
Windows Server 2012 R2
  • <6.3.9600.23397
Windows 10 Version 1607
  • <10.0.14393.9512
Windows 10 Version 1809
  • <10.0.17763.9245
Windows 10 Version 21H2
  • <10.0.19044.7725
Windows 10 Version 22H2
  • <10.0.19045.7725
Windows 11 Version 23H2
  • <10.0.22631.7582
Windows 11 Version 24H2
  • <10.0.26100.9445
Windows 11 Version 25H2
  • <10.0.26200.9445
Windows 11 version 23H2
  • <10.0.22631.7582
Windows 11 version 26H1
  • <10.0.28000.2954
Windows Server 2012 (Server Core installation)
  • <6.2.9200.26349
Windows Server 2016 (Server Core installation)
  • <10.0.14393.9512
Windows Server 2019 (Server Core installation)
  • <10.0.17763.9245
Windows Server 2025 (Server Core installation)
  • <10.0.26100.33438
Windows Server 2012 R2 (Server Core installation)
  • <6.3.9600.23397
Dismissed
(no matching packages found)
Permalink CVE-2026-78574
7.5 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): None (N)
created 1 week, 3 days ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Improper Assembly Resolution in Okta Hyperdrive Integration Plugin Registry Handling

The Okta Hyperdrive Integration plugin resolves a required assembly using a registry path within the current user's hive without integrity verification. The referenced path is loaded via Assembly.LoadFrom without signature validation, resulting in an unverified assembly executing within the context of the host process or elevated installer.

Affected products

Okta Hyperdrive Integration Plugin
  • <1.5.2
Dismissed
(no matching packages found)
Permalink CVE-2026-86725
7.1 HIGH
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): None (N)
  • Vulnerable System Impact Integrity (VI): High (H)
  • Vulnerable System Impact Availability (VA): Low (L)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): None (N)
  • Modified Vulnerable System Impact Integrity (MVI): High (H)
  • Modified Vulnerable System Impact Availability (MVA): Low (L)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 1 week, 3 days ago Activity log
  • Created & dismissed (no matching packages found) suggestion
AVideo SocialMediaPublisher Missing Authorization via add.json.php

AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in the SocialMediaPublisher plugin's add.json.php endpoint that allows authenticated users to modify other users' OAuth token records. Attackers can supply arbitrary row IDs to overwrite another user's stored access_token and refresh_token, then delete the compromised record to destroy the victim's provider linkage.

Affected products

AVideo
  • =<c3edcc274c389816d434acadac07ee78eaf330c1
Dismissed
(no matching packages found)
Permalink CVE-2026-69732
8.1 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Exploit Code Maturity (E): Unproven (U)
  • Remediation Level (RL): Official Fix (O)
  • Report Confidence (RC): Confirmed (C)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 1 week, 3 days ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Windows Link Layer Topology Discovery Protocol Remote Code Execution Vulnerability

Heap-based buffer overflow in Windows Link Layer Topology Discovery Protocol allows an unauthorized attacker to execute code over a network.

Affected products

Windows Server 2012
  • <6.2.9200.26349
Windows Server 2016
  • <10.0.14393.9512
Windows Server 2019
  • <10.0.17763.9245
Windows Server 2022
  • <10.0.20348.5622
Windows Server 2025
  • <10.0.26100.33438
Windows Server 2012 R2
  • <6.3.9600.23397
Windows 10 Version 1607
  • <10.0.14393.9512
Windows 10 Version 1809
  • <10.0.17763.9245
Windows 10 Version 21H2
  • <10.0.19044.7725
Windows 10 Version 22H2
  • <10.0.19045.7725
Windows 11 Version 23H2
  • <10.0.22631.7582
Windows 11 Version 24H2
  • <10.0.26100.9445
Windows 11 Version 25H2
  • <10.0.26200.9445
Windows 11 version 23H2
  • <10.0.22631.7582
Windows 11 version 26H1
  • <10.0.28000.2954
Windows Server 2012 (Server Core installation)
  • <6.2.9200.26349
Windows Server 2016 (Server Core installation)
  • <10.0.14393.9512
Windows Server 2019 (Server Core installation)
  • <10.0.17763.9245
Windows Server 2025 (Server Core installation)
  • <10.0.26100.33438
Windows Server 2012 R2 (Server Core installation)
  • <6.3.9600.23397
Dismissed
(no matching packages found)
Permalink CVE-2026-77101
8.7 HIGH
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): None (N)
  • Vulnerable System Impact Integrity (VI): None (N)
  • Vulnerable System Impact Availability (VA): High (H)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): None (N)
  • Modified Vulnerable System Impact Integrity (MVI): None (N)
  • Modified Vulnerable System Impact Availability (MVA): High (H)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 1 week, 3 days ago Activity log
  • Created & dismissed (no matching packages found) suggestion
CommServe Stack-based Buffer Overflow

CommServe contained a stack-based buffer overflow issue affecting service availability. Software customers upgrade to resolved maintenance release. Update CommServe.

Affected products

Commvault Cloud
  • =<11.46.19
  • =<11.36.122
  • =<11.44.19
  • =<11.40.71