Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Dismissed suggestions

These automatic suggestions were dismissed after initial triaging.

to select a suggestion for revision.

View:
Compact
Detailed
Dismissed
(no matching packages found)
Permalink CVE-2026-47922
4.7 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Changed (C)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
created 4 weeks ago Activity log
  • Created & dismissed (no matching packages found) suggestion
CAI Content Credentials | Server-Side Request Forgery (SSRF) (CWE-918)

CAI Content Credentials is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.

Affected products

Content Credentials JS SDK
  • ==@contentauth/c2pa-web@0.12.1
  • =<@contentauth/c2pa-web@0.12.0
Content Credentials Rust SDK
  • ==c2pa-v0.90.6
  • =<c2pa-v0.90.5
Content Credentials Command-Line Tool
  • =<c2patool-v0.27.5
  • ==c2patool-v0.27.6
Dismissed
(no matching packages found)
Permalink CVE-2026-20752
6.7 MEDIUM
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): High (H)
  • Vulnerable System Impact Integrity (VI): None (N)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): High (H)
  • Modified Vulnerable System Impact Integrity (MVI): None (N)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 4 weeks ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Improper authentication for some Intel(R) PROSet/Wireless WiFi Software within Ring …

Improper authentication for some Intel(R) PROSet/Wireless WiFi Software within Ring 0: Kernel may allow an information disclosure. System software adversary with a privileged user combined with a low complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

Affected products

Intel(R) PROSet/Wireless WiFi Software
  • ==See references
Dismissed
(no matching packages found)
Permalink CVE-2026-18708
5.3 MEDIUM
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): None (N)
  • Vulnerable System Impact Integrity (VI): Low (L)
  • Vulnerable System Impact Availability (VA): Low (L)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): None (N)
  • Modified Vulnerable System Impact Integrity (MVI): Low (L)
  • Modified Vulnerable System Impact Availability (MVA): Low (L)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 4 weeks ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Improper Neutralization of Input in MongoDB Server's JavaScript Scripting Engine Leads to Unauthorized Code Execution Within Query Scopes

An issue in MongoDB Server's JavaScript scripting engine could allow an authenticated user with write privileges to cause code they control to be executed within the query scope of other users, through a specially crafted stored value processed during an internal maintenance cycle. This could result in corruption of query results affecting other users and denial of service targeted at their operations on the same database. Impact is limited to the scripting engine's execution sandbox, which does not provide access to database, filesystem, or network resources.

Affected products

MongoDB Server
  • <8.0.29
  • <8.3.8
  • <7.0.40
Dismissed
(no matching packages found)
Permalink CVE-2026-61347
5.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Exploit Code Maturity (E): Unproven (U)
  • Remediation Level (RL): Official Fix (O)
  • Report Confidence (RC): Confirmed (C)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
created 4 weeks ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Windows Event Logging Service Information Disclosure Vulnerability

Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locally.

Affected products

Windows Server 2012
  • <6.2.9200.26280
Windows Server 2016
  • <10.0.14393.9418
Windows Server 2019
  • <10.0.17763.9115
Windows Server 2022
  • <10.0.20348.5499
Windows Server 2025
  • <10.0.26100.33296
Windows Server 2012 R2
  • <6.3.9600.23338
Windows 10 Version 1607
  • <10.0.14393.9418
Windows 10 Version 1809
  • <10.0.17763.9115
Windows 10 Version 21H2
  • <10.0.19044.7663
Windows 10 Version 22H2
  • <10.0.19045.7663
Windows 11 Version 23H2
  • <10.0.22631.7517
Windows 11 Version 24H2
  • <10.0.26100.9168
Windows 11 Version 25H2
  • <10.0.26200.9168
Windows 11 version 23H2
  • <10.0.22631.7517
Windows 11 version 26H1
  • <10.0.28000.2704
Windows Server 2012 (Server Core installation)
  • <6.2.9200.26280
Windows Server 2016 (Server Core installation)
  • <10.0.14393.9418
Windows Server 2019 (Server Core installation)
  • <10.0.17763.9115
Windows Server 2025 (Server Core installation)
  • <10.0.26100.33296
Windows Server 2012 R2 (Server Core installation)
  • <6.3.9600.23338
Dismissed
(no matching packages found)
Permalink CVE-2026-20349
8.6 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): High (H)
created 4 weeks ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability

A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.&nbsp; This vulnerability is due to insufficient error checking when processing HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.

Affected products

Cisco Secure Firewall Threat Defense (FTD) Software
  • ==7.6.2
  • ==7.2.9
  • ==7.2.8.1
  • ==10.0.2
  • ==7.0.9
  • ==7.2.0
  • ==7.2.3
  • ==7.7.0
  • ==7.7.11
  • ==7.6.4
  • ==7.0.2.1
  • ==7.2.5.2
  • ==7.6.2.1
  • ==7.0.2
  • ==7.6.0
  • ==7.4.2.4
  • ==7.2.0.1
  • ==7.2.10.2
  • ==7.4.2.1
  • ==7.0.6
  • ==7.4.8
  • ==7.3.1
  • ==7.0.1
  • ==7.2.1
  • ==7.2.4.1
  • ==7.2.10
  • ==7.4.2
  • ==7.2.8
  • ==7.4.3
  • ==7.0.0.1
  • ==7.2.5
  • ==7.4.2.2
  • ==7.0.0
  • ==10.0.0
  • ==7.2.4
  • ==7.2.2
  • ==7.0.6.1
  • ==7.0.6.2
  • ==7.0.7
  • ==7.0.8
  • ==7.3.0
  • ==7.6.1
  • ==7.2.11
  • ==7.4.0
  • ==7.0.3
  • ==7.4.4
  • ==7.7.10.1
  • ==7.4.1
  • ==7.4.2.3
  • ==7.0.5
  • ==7.0.6.3
  • ==7.3.1.2
  • ==7.7.10
  • ==7.0.8.1
  • ==7.2.12
  • ==7.2.5.1
  • ==7.0.1.1
  • ==7.0.4
  • ==7.2.6
  • ==7.4.1.1
  • ==7.7.13
  • ==7.3.1.1
  • ==7.2.7
  • ==7.4.7
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
  • ==9.16.1
  • ==9.22.2.4
  • ==9.23.1.195
  • ==9.22.1.6
  • ==9.22.2.32
  • ==9.16.4.76
  • ==9.16.4.61
  • ==9.22.2.20
  • ==9.20.3
  • ==9.20.4.14
  • ==9.18.3.53
  • ==9.16.3.19
  • ==9.20.4.30
  • ==9.18.4.34
  • ==9.20.3.4
  • ==9.16.4.57
  • ==9.18.4.29
  • ==9.16.4.89
  • ==9.18.4.40
  • ==9.16.4.55
  • ==9.18.2.8
  • ==9.24.1.9
  • ==9.16.4.84
  • ==9.20.3.16
  • ==9.18.4.135
  • ==9.23.1.32
  • ==9.20.1
  • ==9.19.1.24
  • ==9.22.2.14
  • ==9.23.1.19
  • ==9.18.4.90
  • ==9.18.2.5
  • ==9.18.4.76
  • ==9.22.3
  • ==9.20.4.28
  • ==9.23.1.26
  • ==9.16.4.39
  • ==9.18.4.68
  • ==9.22.2
  • ==9.18.2
  • ==9.20.2.22
  • ==9.24.1.5
  • ==9.16.2.14
  • ==9.18.4.5
  • ==9.18.4.47
  • ==9.16.3.14
  • ==9.16.2.13
  • ==9.19.1.22
  • ==9.16.3.23
  • ==9.16.4.14
  • ==9.16.3.3
  • ==9.19.1.38
  • ==9.18.4.57
  • ==9.20.4.10
  • ==9.18.4.24
  • ==9.18.1
  • ==9.20.1.5
  • ==9.19.1.18
  • ==9.18.1.3
  • ==9.20.4.34
  • ==9.18.3.55
  • ==9.16.4
  • ==9.16.3.15
  • ==9.16.4.71
  • ==9.18.4.82
  • ==9.16.4.38
  • ==9.18.4.8
  • ==9.16.4.70
  • ==9.16.4.82
  • ==9.20.2.21
  • ==9.18.2.7
  • ==9.19.1.42
  • ==9.20.2.10
  • ==9.20.3.9
  • ==9.23.1.7
  • ==9.22.2.9
  • ==9.18.4.71
  • ==9.20.4.22
  • ==9.19.1.28
  • ==9.20.4.46
  • ==9.20.4.7
  • ==9.18.4.50
  • ==9.22.2.13
  • ==9.22.1.2
  • ==9.16.4.9
  • ==9.16.2.11
  • ==9.16.4.42
  • ==9.16.2.7
  • ==9.20.3.13
  • ==9.23.1.13
  • ==9.16.4.27
  • ==9.24.1.11
  • ==9.24.1.155
  • ==9.18.3.56
  • ==9.23.1.22
  • ==9.20.3.20
  • ==9.19.1.5
  • ==9.16.4.48
  • ==9.16.2.3
  • ==9.16.4.92
  • ==9.16.1.28
  • ==9.19.1.31
  • ==9.16.4.19
  • ==9.16.4.62
  • ==9.20.2
  • ==9.20.3.10
  • ==9.19.1.9
  • ==9.16.4.67
  • ==9.19.1.37
  • ==9.23.1.3
  • ==9.20.3.7
  • ==9.16.3
  • ==9.19.1.12
  • ==9.18.4.66
  • ==9.19.1
  • ==9.22.3.5
  • ==9.23.1
  • ==9.18.4
  • ==9.20.4
  • ==9.20.4.19
  • ==9.22.1.3
  • ==9.18.4.67
  • ==9.16.2
  • ==9.18.4.22
  • ==9.18.3
  • ==9.16.4.85
  • ==9.18.3.46
  • ==9.18.4.53
  • ==9.24.1
  • ==9.19.1.27
  • ==9.18.4.52
  • ==9.22.1.1
  • ==9.18.3.39
Dismissed
(no matching packages found)
Permalink CVE-2026-59138
6.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): High (H)
  • Exploit Code Maturity (E): Unproven (U)
  • Remediation Level (RL): Official Fix (O)
  • Report Confidence (RC): Confirmed (C)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): High (H)
created 4 weeks ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Microsoft Remote Registry Service Denial of Service Vulnerability

Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.

Affected products

Windows Server 2012
  • <6.2.9200.26280
Windows Server 2016
  • <10.0.14393.9418
Windows Server 2019
  • <10.0.17763.9115
Windows Server 2022
  • <10.0.20348.5499
Windows Server 2025
  • <10.0.26100.33296
Windows Server 2012 R2
  • <6.3.9600.23338
Windows 10 Version 1607
  • <10.0.14393.9418
Windows 10 Version 1809
  • <10.0.17763.9115
Windows 10 Version 21H2
  • <10.0.19044.7663
Windows 10 Version 22H2
  • <10.0.19045.7663
Windows 11 Version 23H2
  • <10.0.22631.7517
Windows 11 Version 24H2
  • <10.0.26100.9168
Windows 11 Version 25H2
  • <10.0.26200.9168
Windows 11 version 23H2
  • <10.0.22631.7517
Windows 11 version 26H1
  • <10.0.28000.2704
Windows Server 2012 (Server Core installation)
  • <6.2.9200.26280
Windows Server 2016 (Server Core installation)
  • <10.0.14393.9418
Windows Server 2019 (Server Core installation)
  • <10.0.17763.9115
Windows Server 2025 (Server Core installation)
  • <10.0.26100.33296
Windows Server 2012 R2 (Server Core installation)
  • <6.3.9600.23338
Dismissed
(no matching packages found)
Permalink CVE-2026-63528
5.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Exploit Code Maturity (E): Unproven (U)
  • Remediation Level (RL): Official Fix (O)
  • Report Confidence (RC): Confirmed (C)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
created 4 weeks ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Microsoft Office Word Information Disclosure Vulnerability

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

Affected products

Microsoft Word 2016
  • <16.0.5565.1000
Microsoft Office 2019
  • <https://aka.ms/OfficeSecurityReleases
Microsoft Office LTSC 2021
  • <https://aka.ms/OfficeSecurityReleases
Microsoft Office LTSC 2024
  • <https://aka.ms/OfficeSecurityReleases
Microsoft Office 365 for Mac
  • <16.112.26081010
Microsoft 365 Apps for Enterprise
  • <https://aka.ms/OfficeSecurityReleases
Microsoft Office LTSC for Mac 2021
  • <16.112.26081010
Microsoft Office LTSC for Mac 2024
  • <16.112.26081010
Dismissed
(no matching packages found)
Permalink CVE-2026-58243
8.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 4 weeks ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Privilege Escalation vulnerability in SAP ABAP Developer Tools

SAP ABAP Development Tools does not perform necessary authorization checks for certain functionality, allowing an attacker with low privileges to execute unauthorized database operations against SAP NetWeaver AS ABAP. Successful exploitation could allow the attacker to read sensitive data, modify application data, and disrupt access for legitimate users, resulting in high impact on confidentiality, integrity, and availability.

Affected products

SAP ABAP Developer Tools
  • ==SAP_BASIS 920
  • ==SAP_BASIS 758
  • ==SAP_BASIS 755
  • ==SAP_BASIS 750
  • ==SAP_BASIS 918
  • ==SAP_BASIS 757
  • ==SAP_BASIS 753
  • ==SAP_BASIS 751
  • ==SAP_BASIS 816
  • ==SAP_BASIS 754
  • ==SAP_BASIS 752
  • ==SAP_BASIS 756
Dismissed
(no matching packages found)
Permalink CVE-2026-70340
8.1 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Exploit Code Maturity (E): Unproven (U)
  • Remediation Level (RL): Official Fix (O)
  • Report Confidence (RC): Confirmed (C)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 4 weeks ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Azure CycleCloud Elevation of Privilege Vulnerability

Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.

Affected products

Azure CycleCloud 8.9.1
  • <8.9.1
Dismissed
(max. allowed matches exceeded)
Permalink CVE-2026-69119
7.2 HIGH
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): Low (L)
  • Vulnerable System Impact Integrity (VI): High (H)
  • Vulnerable System Impact Availability (VA): High (H)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
  • Modified Vulnerable System Impact Integrity (MVI): High (H)
  • Modified Vulnerable System Impact Availability (MVA): High (H)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 4 weeks ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
Taubyte Tau v1.1.10 Missing Authorization via POST /projects/{id}

Taubyte Tau v1.1.10 contains a missing authorization vulnerability in the services/auth HTTP service that allows any authenticated user to read or permanently delete another tenant's project by supplying an arbitrary project ID to the GET and DELETE /projects/{id} endpoints. The GitHubTokenHTTPAuth middleware only validates that a caller presents a valid GitHub OAuth token without verifying ownership or access rights to the target project, enabling attackers with any valid GitHub token to invoke bare KV-store operations such as projects.Fetch and project.Delete against any project ID to achieve cross-tenant project takeover.

Affected products

tau
  • =<1.1.10