Nixpkgs Security Tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Automatically generated suggestions

to remove a suggestion from the queue.

created 5 hours ago
Integer Overflow or Wraparound in Automotive

Memory corruption while calculating offset from partition start point.

Affected products

Snapdragon
  • ==QCA8695AU
  • ==QCA6688AQ
  • ==QAM8255P
  • ==QAM8295P
  • ==SA8195P
  • ==QCA6574AU
  • ==SA8540P
  • ==SA8155P
  • ==SA6150P
  • ==QCA6595AU
  • ==SA8775P
  • ==QAMSRV1M
  • ==QCA6696
  • ==SRV1L
  • ==SA9000P
  • ==SA6145P
  • ==SA8145P
  • ==SA8620P
  • ==SA8770P
  • ==QAM8650P
  • ==QAM8620P
  • ==SA6155P
  • ==QAMSRV1H
  • ==QAM8775P
  • ==SA8650P
  • ==SA8255P
  • ==SA7775P
  • ==SRV1M
  • ==SA8150P
  • ==SA7255P
  • ==SA8295P
  • ==QCA6797AQ
  • ==QCA6595
  • ==QCA6698AQ
  • ==SRV1H

Matching in nixpkgs

pkgs.snapdragon-profiler

Profiler for Android devices running Snapdragon chips

created 5 hours ago
Libsoup: stack-based buffer overflow in libsoup multipart response parsingmultipart http response

A flaw was found in libsoup. This stack-based buffer overflow vulnerability occurs during the parsing of multipart HTTP responses due to an incorrect length calculation. A remote attacker can exploit this by sending a specially crafted multipart HTTP response, which can lead to memory corruption. This issue may result in application crashes or arbitrary code execution in applications that process untrusted server responses, and it does not require authentication or user interaction.

Affected products

libsoup
libsoup3

Matching in nixpkgs

pkgs.tests.pkg-config.defaultPkgConfigPackages."libsoup-gnome-2.4"

Test whether libsoup-2.74.3 exposes pkg-config modules libsoup-gnome-2.4

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small
  • nixos-25.11 -
    • nixpkgs-25.11-darwin
  • nixos-25.05 -
    • nixos-25.05-small

Package maintainers

created 5 hours ago
Use After Free in Secure Processor

Memory Corruption when multiple threads simultaneously access a memory free API.

Affected products

Snapdragon
  • ==X2000086
  • ==X2000090
  • ==X2000094
  • ==Snapdragon 8c Compute Platform (SC8180X-AD) "Poipu Lite"
  • ==FastConnect 7800
  • ==AQT1000
  • ==Snapdragon 8cx Compute Platform (SC8180X-AA, AB)
  • ==WCD9378C
  • ==X2000092
  • ==X2000077
  • ==WCD9380
  • ==QCA6420
  • ==Snapdragon 8cx Gen 3 Compute Platform (SC8280XP-AB, BB)
  • ==WCD9341
  • ==Snapdragon 8cx Gen 2 5G Compute Platform (SC8180XP-AA, AB)
  • ==WSA8840
  • ==WSA8835
  • ==WCD9385
  • ==FastConnect 6800
  • ==WSA8810
  • ==Snapdragon 8cx Compute Platform (SC8180XP-AC, AF) "Poipu Pro"
  • ==Snapdragon 8cx Gen 2 5G Compute Platform (SC8180X-AC, AF) "Poipu Pro"
  • ==WSA8830
  • ==QCA6430
  • ==WSA8845H
  • ==QCC2072
  • ==SC8380XP
  • ==FastConnect 6200
  • ==WSA8815
  • ==WSA8845
  • ==QCA6391
  • ==XG101032
  • ==WCD9340
  • ==FastConnect 6900
  • ==Snapdragon 8c Compute Platform (SC8180XP-AD) "Poipu Lite"
  • ==XG101002
  • ==XG101039

Matching in nixpkgs

pkgs.snapdragon-profiler

Profiler for Android devices running Snapdragon chips

created 5 hours ago
EventStreams publishes suppressed recent change entries that are suppressed from their creation

Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/recentchanges/RecentChangeRCFeedNotifier.Php. This issue affects MediaWiki: from * before 1.39.14, 1.43.4, 1.44.1.

Affected products

MediaWiki
  • <1.39.14, 1.43.4, 1.44.1

Matching in nixpkgs

Package maintainers

created 5 hours ago
Complete content leak of private wikis due to PasswordReset Wikitext injection in error message

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/htmlform/fields/HTMLUserTextField.Php. This issue affects MediaWiki: from * through 1.39.12, 1.42.76 1.43.1, 1.44.0.

Affected products

MediaWiki
  • =<1.39.12, 1.42.76 1.43.1, 1.44.0

Matching in nixpkgs

Package maintainers

created 5 hours ago
OpenList Insecure TLS Default Configuration

OpenList Frontend is a UI component for OpenList. Prior to 4.1.10, certificate verification is disabled by default for all storage driver communications. The TlsInsecureSkipVerify setting is default to true in the DefaultConfig() function in internal/conf/config.go. This vulnerability enables Man-in-the-Middle (MitM) attacks by disabling TLS certificate verification, allowing attackers to intercept and manipulate all storage communications. Attackers can exploit this through network-level attacks like ARP spoofing, rogue Wi-Fi access points, or compromised internal network equipment to redirect traffic to malicious endpoints. Since certificate validation is skipped, the system will unknowingly establish encrypted connections with attacker-controlled servers, enabling full decryption, data theft, and manipulation of all storage operations without triggering any security warnings. This vulnerability is fixed in 4.1.10.

Affected products

OpenList
  • ==< 4.1.10

Matching in nixpkgs

Package maintainers

created 5 hours ago
NixOs Odoo database and filestore publicly accessible with default odoo configuration

The NixOs Odoo package is an open source ERP and CRM system. From 21.11 to before 25.11 and 26.05, every NixOS based Odoo setup publicly exposes the database manager without any authentication. This allows unauthorized actors to delete and download the entire database, including Odoos file store. Unauthorized access is evident from http requests. If kept, searching access logs and/or Odoos log for requests to /web/database can give indicators, if this has been actively exploited. The database manager is a featured intended for development and not meant to be publicly reachable. On other setups, a master password acts as 2nd line of defence. However, due to the nature of NixOS, Odoo is not able to modify its own configuration file and thus unable to persist the auto-generated password. This also applies when manually setting a master password in the web-UI. This means, the password is lost when restarting Odoo. When no password is set, the user is prompted to set one directly via the database manager. This requires no authentication or action by any authorized user or the system administrator. Thus, the database is effectively world readable by anyone able to reach Odoo. This vulnerability is fixed in 25.11 and 26.05.

Affected products

nixpkgs
  • ==>= 21.11, < 25.11

Matching in nixpkgs

pkgs.manual

None

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small
  • nixos-25.11 -
    • nixpkgs-25.11-darwin
  • nixos-25.05 -
    • nixos-25.05-small

pkgs.metrics

None

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small
  • nixos-25.11 -
    • nixpkgs-25.11-darwin
  • nixos-25.05 -
    • nixos-25.05-small

pkgs.lib-tests

None

  • nixos-unstable -
  • nixos-25.11 -
    • nixpkgs-25.11-darwin
  • nixos-25.05 -
    • nixos-25.05-small

pkgs.nixpkgs-vet

Tool to vet (check) Nixpkgs, including its pkgs/by-name directory

pkgs.nixpkgs-lint

A utility for Nixpkgs contributors to check Nixpkgs for common errors

  • nixos-unstable 1
    • nixpkgs-unstable 1
    • nixos-unstable-small 1
  • nixos-25.11 1
    • nixpkgs-25.11-darwin 1
  • nixos-25.05 -
    • nixos-25.05-small 1

pkgs.nixpkgs-track

Track where Nixpkgs pull requests have reached

pkgs.nixpkgs-manual

None

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small
  • nixos-25.11 -
    • nixpkgs-25.11-darwin
  • nixos-25.05 -
    • nixos-25.05-small

pkgs.nixpkgs-review

Review pull-requests on https://github.com/NixOS/nixpkgs

pkgs.release-checks

None

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small
  • nixos-25.11 -
    • nixpkgs-25.11-darwin
  • nixos-25.05 -
    • nixos-25.05-small

pkgs.nixpkgs-pytools

Tools for removing the tedious nature of creating nixpkgs derivations

pkgs.tests.lib-tests

None

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small

pkgs.nixpkgs-reviewFull

Review pull-requests on https://github.com/NixOS/nixpkgs

pkgs.nixpkgs-lint-community

Fast semantic linter for Nix using tree-sitter

pkgs.tests.pkgs-lib.formats

None

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small

pkgs.nixpkgs-openjdk-updater

Updater for Nixpkgs OpenJDK packages

pkgs.python312Packages.nixpkgs

Allows to `from nixpkgs import` stuff in interactive Python sessions

pkgs.python313Packages.nixpkgs

Allows to `from nixpkgs import` stuff in interactive Python sessions

pkgs.lixPackageSets.git.nixpkgs-review

Review pull-requests on https://github.com/NixOS/nixpkgs

pkgs.python312Packages.nixpkgs-pytools

Tools for removing the tedious nature of creating nixpkgs derivations

pkgs.python313Packages.nixpkgs-pytools

Tools for removing the tedious nature of creating nixpkgs derivations

pkgs.python314Packages.nixpkgs-pytools

Tools for removing the tedious nature of creating nixpkgs derivations

pkgs.tests.trivial-builders.references

None

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small
  • nixos-25.11 -
    • nixpkgs-25.11-darwin
  • nixos-25.05 -
    • nixos-25.05-small

pkgs.lixPackageSets.latest.nixpkgs-review

Review pull-requests on https://github.com/NixOS/nixpkgs

  • nixos-25.05 -

pkgs.lixPackageSets.stable.nixpkgs-review

Review pull-requests on https://github.com/NixOS/nixpkgs

pkgs.lixPackageSets.git.nixpkgs-reviewFull

Review pull-requests on https://github.com/NixOS/nixpkgs

pkgs.lixPackageSets.lix_2_90.nixpkgs-review

Review pull-requests on https://github.com/NixOS/nixpkgs

pkgs.lixPackageSets.lix_2_92.nixpkgs-review

Review pull-requests on https://github.com/NixOS/nixpkgs

pkgs.lixPackageSets.lix_2_93.nixpkgs-review

Review pull-requests on https://github.com/NixOS/nixpkgs

pkgs.lixPackageSets.lix_2_94.nixpkgs-review

Review pull-requests on https://github.com/NixOS/nixpkgs

pkgs.python312Packages.nixpkgs-plugin-update

Library for updating plugin collections in Nixpkgs

pkgs.python313Packages.nixpkgs-plugin-update

Library for updating plugin collections in Nixpkgs

pkgs.python314Packages.nixpkgs-plugin-update

Library for updating plugin collections in Nixpkgs

pkgs.lixPackageSets.stable.nixpkgs-reviewFull

Review pull-requests on https://github.com/NixOS/nixpkgs

pkgs.lixPackageSets.lix_2_94.nixpkgs-reviewFull

Review pull-requests on https://github.com/NixOS/nixpkgs

pkgs.python312Packages.nixpkgs-updaters-library

Boilerplate-less updater library for Nixpkgs ecosystems

  • nixos-25.05 -

pkgs.python313Packages.nixpkgs-updaters-library

Boilerplate-less updater library for Nixpkgs ecosystems

pkgs.python314Packages.nixpkgs-updaters-library

Boilerplate-less updater library for Nixpkgs ecosystems

created 5 hours ago
HTML injection in API action=feedcontributions output from i18n message

Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/api/ApiFeedContributions.Php. This issue affects MediaWiki: from * before 1.39.13, 1.42.7 1.43.2, 1.44.0.

Affected products

MediaWiki
  • <1.39.13, 1.42.7 1.43.2, 1.44.0

Matching in nixpkgs

Package maintainers

created 5 hours ago
Stored XSS through system messages provided to CodexHtmlForms

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/htmlform/CodexHTMLForm.Php, includes/htmlform/fields/HTMLButtonField.Php. This issue affects MediaWiki: from * before 1.39.14, 1.43.4, 1.44.1.

Affected products

MediaWiki
  • <1.39.14, 1.43.4, 1.44.1

Matching in nixpkgs

Package maintainers

created 5 hours ago
Exposed Dangerous Method or Function in HLOS

Cryptographic issue when a Trusted Zone with outdated code is triggered by a HLOS providing incorrect input.

Affected products

Snapdragon
  • ==QCA8081
  • ==QCA6688AQ
  • ==AR8035
  • ==Robotics RB5 Platform
  • ==SD 8 Gen1 5G
  • ==SM8750
  • ==SA8540P
  • ==WCD9380
  • ==QCN6274
  • ==SM6475
  • ==Snapdragon X35 5G Modem-RF System
  • ==Qualcomm Video Collaboration VC3 Platform
  • ==SRV1L
  • ==SSG2115P
  • ==QRB5165M
  • ==SA4150P
  • ==SM8735
  • ==WCN7881
  • ==WCD9378
  • ==Snapdragon X32 5G Modem-RF System
  • ==Snapdragon 480+ 5G Mobile Platform (SM4350-AC)
  • ==WCN3988
  • ==SM8475P
  • ==QAM8775P
  • ==SA8650P
  • ==SM7635
  • ==SM8635P
  • ==SXR2350P
  • ==WSA8845H
  • ==SA7775P
  • ==SRV1M
  • ==WCD9395
  • ==QFW7124
  • ==QDU1010
  • ==Snapdragon X75 5G Modem-RF System
  • ==WCD9370
  • ==SA8295P
  • ==SW5100P
  • ==Snapdragon X72 5G Modem-RF System
  • ==QCA6595
  • ==QCA6698AQ
  • ==Snapdragon 662 Mobile Platform
  • ==QCA6574
  • ==QCA8695AU
  • ==Snapdragon 460 Mobile Platform
  • ==Snapdragon 685 4G Mobile Platform (SM6225-AD)
  • ==Qualcomm Video Collaboration VC5 Platform
  • ==QCN9011
  • ==SM7435
  • ==QRU1052
  • ==SXR2330P
  • ==Snapdragon AR2 Gen 1 Platform
  • ==QAM8295P
  • ==SA8195P
  • ==WCN3950
  • ==WCN6740
  • ==SA8775P
  • ==Snapdragon 680 4G Mobile Platform
  • ==WCN3910
  • ==QCA6174A
  • ==QRU1032
  • ==SA9000P
  • ==WCN7861
  • ==WSA8840
  • ==QCA6574A
  • ==Flight RB5 5G Platform
  • ==SA8620P
  • ==WCD9385
  • ==SSG2125P
  • ==WSA8810
  • ==QEP8111
  • ==Snapdragon 8 Gen 1 Mobile Platform
  • ==SA8770P
  • ==Snapdragon 4 Gen 1 Mobile Platform
  • ==WSA8830
  • ==QAM8620P
  • ==QMP1000
  • ==QAMSRV1H
  • ==SM4635
  • ==QCM5430
  • ==SM8650Q
  • ==SA8255P
  • ==SA8150P
  • ==QCA8337
  • ==QCS5430
  • ==SM8635
  • ==QRU1062
  • ==SM6650
  • ==QCC710
  • ==QFW7114
  • ==Snapdragon AR1 Gen 1 Platform "Luna1"
  • ==QCM6490
  • ==QCM4490
  • ==QDX1010
  • ==SM6650P
  • ==SM7635P
  • ==Snapdragon AR1 Gen 1 Platform
  • ==QDX1011
  • ==QAM8255P
  • ==SM7675
  • ==QCS4490
  • ==Snapdragon 7+ Gen 2 Mobile Platform
  • ==SA4155P
  • ==QCA6595AU
  • ==SXR2230P
  • ==Snapdragon W5+ Gen 1 Wearable Platform
  • ==SXR2250P
  • ==QCA6696
  • ==SA6145P
  • ==SA8145P
  • ==WSA8835
  • ==WCN7880
  • ==WCN6755
  • ==QCS6490
  • ==Snapdragon 8 Gen 3 Mobile Platform
  • ==QAM8650P
  • ==Snapdragon 8+ Gen 1 Mobile Platform
  • ==WCN7860
  • ==SG4150P
  • ==WSA8845
  • ==WSA8832
  • ==QCA6678AQ
  • ==SXR1230P
  • ==WCD9340
  • ==FastConnect 6900
  • ==WCD9375
  • ==WCD9390
  • ==QAMSRV1M
  • ==SRV1H
  • ==QCS9100
  • ==SM6225P
  • ==FastConnect 6700
  • ==Snapdragon 7 Gen 1 Mobile Platform
  • ==FastConnect 7800
  • ==Snapdragon 6 Gen 1 Mobile Platform
  • ==Snapdragon Auto 5G Modem-RF Gen 2
  • ==WCN7750
  • ==SM7675P
  • ==Snapdragon 695 5G Mobile Platform
  • ==QCA6574AU
  • ==SA8155P
  • ==SA6150P
  • ==QCA6584AU
  • ==QRB5165N
  • ==WCN6650
  • ==SM8750P
  • ==SW5100
  • ==SA6155P
  • ==QCN9012
  • ==QCN6224
  • ==SC8380XP
  • ==FastConnect 6200
  • ==WSA8815
  • ==Snapdragon 480 5G Mobile Platform
  • ==QCA6391
  • ==SA7255P
  • ==QCS615
  • ==Snapdragon 4 Gen 2 Mobile Platform
  • ==QCA6797AQ
  • ==QCS7230

Matching in nixpkgs

pkgs.snapdragon-profiler

Profiler for Android devices running Snapdragon chips