Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Automatically generated suggestions

to slate a suggestion for refinement.

to mark a suggestion as irrelevant and log the reason.

View:
Compact
Detailed
created 2 months ago Activity log
  • Created suggestion
Qemu before 1.6.2 block diver for the various disk image …

Qemu before 1.6.2 block diver for the various disk image formats used by Bochs and for the QCOW version 2 format, are vulnerable to a possible crash caused by signed data types or a logic error while creating QCOW2 snapshots, which leads to incorrectly calling update_refcount() routine.

Affected products

Qemu
  • ==before 1.6.2

Matching in nixpkgs

pkgs.qemu

Generic and open source machine emulator and virtualizer

pkgs.qemu-user

QEMU User space emulator - launch executables compiled for one CPU on another CPU

Package maintainers

created 2 months ago Activity log
  • Created suggestion
MediaWiki before 1.19.4 and 1.20.x before 1.20.3 allows remote attackers …

MediaWiki before 1.19.4 and 1.20.x before 1.20.3 allows remote attackers to cause a denial of service (application crash) by sending a specially crafted request.

References

Affected products

mediawiki
  • ==1.19.4
  • ==1.20.3

Matching in nixpkgs

Package maintainers

created 2 months ago Activity log
  • Created suggestion
Heap-based buffer overflow in the CRC32 verification in Info-ZIP UnZip …

Heap-based buffer overflow in the CRC32 verification in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command.

References

Affected products

UnZip
  • ==6.0 and earlier

Matching in nixpkgs

pkgs.unzip

Extraction utility for archives compressed in .zip format

  • nixos-unstable 6.0
    • nixpkgs-unstable 6.0
    • nixos-unstable-small 6.0
  • nixos-25.11 6.0
    • nixos-25.11-small 6.0
    • nixpkgs-25.11-darwin 6.0

pkgs.runzip

Tool to convert filename encoding inside a ZIP archive

  • nixos-unstable 1.4
    • nixpkgs-unstable 1.4
    • nixos-unstable-small 1.4
  • nixos-25.11 1.4
    • nixos-25.11-small 1.4
    • nixpkgs-25.11-darwin 1.4

pkgs.unzipNLS

Extraction utility for archives compressed in .zip format

  • nixos-unstable 6.0
    • nixpkgs-unstable 6.0
    • nixos-unstable-small 6.0
  • nixos-25.11 6.0
    • nixos-25.11-small 6.0
    • nixpkgs-25.11-darwin 6.0

Package maintainers

created 2 months ago Activity log
  • Created suggestion
MediaWiki before 1.19.4 and 1.20.x before 1.20.3 contains an error …

MediaWiki before 1.19.4 and 1.20.x before 1.20.3 contains an error in the api.php script which allows remote attackers to obtain sensitive information.

Affected products

mediawiki
  • ==1.19.4
  • ==1.20.3

Matching in nixpkgs

Package maintainers

created 2 months ago Activity log
  • Created suggestion
Heap-based buffer overflow in xnview.exe in XnView before 2.03 allows …

Heap-based buffer overflow in xnview.exe in XnView before 2.03 allows remote attackers to execute arbitrary code via a crafted RLE compressed layer in an XCF file.

Affected products

XnView
  • ==before 2.03

Matching in nixpkgs

pkgs.xnviewmp

Efficient multimedia viewer, browser and converter

Package maintainers

created 2 months ago Activity log
  • Created suggestion
Juju Joyent provider uploads user's private ssh key by default

Juju Core's Joyent provider before version 1.25.5 uploads the user's private ssh key.

Affected products

Juju
  • <1.25.5

Matching in nixpkgs

pkgs.juju

Open source modelling tool for operating software in the cloud

pkgs.jujuutils

Utilities around FireWire devices connected to a Linux computer

  • nixos-unstable 0.2
    • nixpkgs-unstable 0.2
    • nixos-unstable-small 0.2
  • nixos-25.11 0.2
    • nixos-25.11-small 0.2
    • nixpkgs-25.11-darwin 0.2
created 2 months ago Activity log
  • Created suggestion
Cross-site scripting (XSS) vulnerability in Cogent DataHub before 7.3.5 allows …

Cross-site scripting (XSS) vulnerability in Cogent DataHub before 7.3.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Affected products

n/a
  • ==n/a
DataHub
  • <7.3.5

Matching in nixpkgs

created 2 months ago Activity log
  • Created suggestion
includes/libs/IEUrlExtension.php in the MediaWiki API in MediaWiki 1.19.x before 1.19.8, …

includes/libs/IEUrlExtension.php in the MediaWiki API in MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x before 1.21.2 does not properly detect extensions when there are an even number of "." (period) characters in a string, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the siprop parameter in a query action to wiki/api.php.

Affected products

MediaWiki
  • ==and 1.21.x before 1.21.2
  • ==1.19.x before 1.19.8
  • ==1.20.x before 1.20.7

Matching in nixpkgs

Package maintainers

created 2 months ago Activity log
  • Created suggestion
GnuTLS before 3.3.13 does not validate that the signature algorithms …

GnuTLS before 3.3.13 does not validate that the signature algorithms match when importing a certificate.

Affected products

GnuTLS
  • ==before 3.3.13

Matching in nixpkgs

Package maintainers

created 2 months ago Activity log
  • Created suggestion
Integer overflow in Trihedral Engineering VTScada (formerly VTS) 6.5 through …

Integer overflow in Trihedral Engineering VTScada (formerly VTS) 6.5 through 9.x before 9.1.20, 10.x before 10.2.22, and 11.x before 11.1.07 allows remote attackers to cause a denial of service (server crash) via a crafted request, which triggers a large memory allocation.

Affected products

VTS
  • <9.1.19
  • <10.2.21
n/a
  • ==n/a

Matching in nixpkgs

pkgs.vtsls

LSP wrapper for typescript extension of vscode.

Package maintainers