Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Automatically generated suggestions

to slate a suggestion for refinement.

to mark a suggestion as irrelevant and log the reason.

View:
Compact
Detailed
created 2 months ago Activity log
  • Created suggestion
DeleGate 9.9.13 allows local users to gain privileges as demonstrated …

DeleGate 9.9.13 allows local users to gain privileges as demonstrated by the dgcpnod setuid program.

References

Affected products

DeleGate
  • ==9.9.13

Matching in nixpkgs

created 2 months ago Activity log
  • Created suggestion
Cross-site request forgery (CSRF) vulnerability in the web application on …

Cross-site request forgery (CSRF) vulnerability in the web application on Omron NS5, NS8, NS10, NS12, and NS15 HMI terminals 8.1xx through 8.68x allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors.

Affected products

NS5
  • <8.68x
NS8
  • <8.68x
n/a
  • ==n/a
NS10
  • <8.68x
NS12
  • <8.68x
NS15
  • <8.68x

Matching in nixpkgs

created 2 months ago Activity log
  • Created suggestion
File Disclosure in SMF (SimpleMachines Forum) <= 2.0.3: Forum admin …

File Disclosure in SMF (SimpleMachines Forum) <= 2.0.3: Forum admin can read files such as the database config.

Affected products

SMF
  • ==<= 2.0.3

Matching in nixpkgs

pkgs.smfh

Sleek Manifest File Handler

  • nixos-unstable 1.3
    • nixpkgs-unstable 1.3
    • nixos-unstable-small 1.3
  • nixos-25.11 1.3
    • nixos-25.11-small 1.4
    • nixpkgs-25.11-darwin 1.3

pkgs.libsmf

C library for reading and writing Standard MIDI Files

  • nixos-unstable 1.3
    • nixpkgs-unstable 1.3
    • nixos-unstable-small 1.3
  • nixos-25.11 1.3
    • nixos-25.11-small 1.3
    • nixpkgs-25.11-darwin 1.3

Package maintainers

created 2 months ago Activity log
  • Created suggestion
Qemu 1.1.2+dfsg to 2.1+dfsg suffers from a buffer overrun which …

Qemu 1.1.2+dfsg to 2.1+dfsg suffers from a buffer overrun which could potentially result in arbitrary code execution on the host with the privileges of the QEMU process.

Affected products

qemu
  • ==1.1.2+dfsg to 2.1+dfsg

Matching in nixpkgs

pkgs.qemu

Generic and open source machine emulator and virtualizer

pkgs.qemu-user

QEMU User space emulator - launch executables compiled for one CPU on another CPU

Package maintainers

created 2 months ago Activity log
  • Created suggestion
Integer overflow in the Drive Execution Environment (DXE) phase in …

Integer overflow in the Drive Execution Environment (DXE) phase in the Capsule Update feature in the UEFI implementation in EDK2 allows physically proximate attackers to bypass intended access restrictions via crafted data.

References

Affected products

BIOS
  • ==unknown
SCT3
  • ==before 5/23/2014

Matching in nixpkgs

pkgs.gnomeExtensions.one-click-bios

Restart into firmware settings directly from OS

  • nixos-unstable 8
    • nixpkgs-unstable 8
    • nixos-unstable-small 8
  • nixos-25.11 8
    • nixos-25.11-small 8
    • nixpkgs-25.11-darwin 8

Package maintainers

created 2 months ago Activity log
  • Created suggestion
packet.py in pyrad before 2.1 uses weak random numbers to …

packet.py in pyrad before 2.1 uses weak random numbers to generate RADIUS authenticators and hash passwords, which makes it easier for remote attackers to obtain sensitive information via a brute force attack.

Affected products

pyrad
  • ==before 2.1

Matching in nixpkgs

Package maintainers

created 2 months ago Activity log
  • Created suggestion
Monkey HTTP Daemon: broken user name authentication

Monkey HTTP Daemon: broken user name authentication

Affected products

monkey
  • ==< 1.2.2

Matching in nixpkgs

pkgs.monkeysphere

Leverage the OpenPGP web of trust for SSH and TLS authentication

  • nixos-unstable 0.44
    • nixpkgs-unstable 0.44
    • nixos-unstable-small 0.44
  • nixos-25.11 0.44
    • nixos-25.11-small 0.44
    • nixpkgs-25.11-darwin 0.44

pkgs.gnomeExtensions.monkeybar

See your weekly Monkeytype typing activity in top bar

  • nixos-unstable 9
    • nixpkgs-unstable 9
    • nixos-unstable-small 9
  • nixos-25.11 4
    • nixos-25.11-small 4
    • nixpkgs-25.11-darwin 4

pkgs.python312Packages.monkeyhex

Small library to assist users of the python shell who work in contexts where printed numbers are more usefully viewed in hexadecimal

Package maintainers

created 2 months ago Activity log
  • Created suggestion
Mozilla Firefox 20.0a1 and earlier allows remote attackers to cause …

Mozilla Firefox 20.0a1 and earlier allows remote attackers to cause a denial of service (crash), related to event handling with frames.

References

Affected products

Firefox
  • ==20.0a1

Matching in nixpkgs

pkgs.firefoxpwa

Tool to install, manage and use Progressive Web Apps (PWAs) in Mozilla Firefox (native component)

pkgs.faust2firefox

The faust2firefox script, part of faust functional programming language for realtime audio signal processing

pkgs.firefox_decrypt

Tool to extract passwords from profiles of Mozilla Firefox and derivates

pkgs.firefox-sync-client

Commandline-utility to list/view/edit/delete entries in a firefox-sync account.

pkgs.gnomeExtensions.firefox-profiles

Easily launch Firefox with your favorite profile right from the indicator menu!

  • nixos-unstable 5
    • nixpkgs-unstable 5
    • nixos-unstable-small 5
  • nixos-25.11 5
    • nixos-25.11-small 5
    • nixpkgs-25.11-darwin 5

Package maintainers

created 2 months ago Activity log
  • Created suggestion
Apport privilege escalation through Python module imports

Any Python module in sys.path can be imported if the command line of the process triggering the coredump is Python and the first argument is -m in Apport before 2.19.2 function _python_module_path.

References

Affected products

Apport
  • <2.19.1-0ubuntu4
  • <2.0.1-0ubuntu17.13
  • <2.14.1-0ubuntu3.18
  • <2.19.2
  • <2.17.2-0ubuntu1.7

Matching in nixpkgs

Package maintainers

created 2 months ago Activity log
  • Created suggestion
JBoss KeyCloak is vulnerable to soft token deletion via CSRF

JBoss KeyCloak is vulnerable to soft token deletion via CSRF

References

Affected products

KeyCloak
  • ==Fixed in version 1.1.0-Alpha1

Matching in nixpkgs

pkgs.keycloak

Identity and access management for modern applications and services

Package maintainers