Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Automatically generated suggestions

to slate a suggestion for refinement.

to mark a suggestion as irrelevant and log the reason.

View:
Compact
Detailed
created 2 months ago Activity log
  • Created suggestion
It was found that foreman, versions 1.x.x before 1.15.6, in …

It was found that foreman, versions 1.x.x before 1.15.6, in Satellite 6 did not properly enforce access controls on certain resources. An attacker with access to the API and knowledge of the resource name can access resources in other organizations.

References

Affected products

foreman
  • ==1.x.x before 1.15.6

Matching in nixpkgs

pkgs.foreman

Process manager for applications with multiple components

Package maintainers

created 2 months ago Activity log
  • Created suggestion
XnView 2.03 has an integer overflow vulnerability

XnView 2.03 has an integer overflow vulnerability

References

Affected products

XnView
  • ==2.03

Matching in nixpkgs

pkgs.xnviewmp

Efficient multimedia viewer, browser and converter

Package maintainers

created 2 months ago Activity log
  • Created suggestion
OpenShift: Install script has temporary file creation vulnerability which can …

OpenShift: Install script has temporary file creation vulnerability which can result in arbitrary code execution

References

Affected products

OpenShift
  • ==through 2014-01-21

Matching in nixpkgs

Package maintainers

created 2 months ago Activity log
  • Created suggestion
eDeploy has RCE via cPickle deserialization of untrusted data

eDeploy has RCE via cPickle deserialization of untrusted data

References

Affected products

eDeploy
  • ==through 2014-10-14

Matching in nixpkgs

Package maintainers

created 2 months ago Activity log
  • Created suggestion
Off-by-one error in the OBJ_obj2txt function in LibreSSL before 2.3.1 …

Off-by-one error in the OBJ_obj2txt function in LibreSSL before 2.3.1 allows remote attackers to cause a denial of service (program crash) or possible execute arbitrary code via a crafted X.509 certificate, which triggers a stack-based buffer overflow. Note: this vulnerability exists because of an incorrect fix for CVE-2014-3508.

Affected products

LibreSSL
  • ==before 2.3.1

Matching in nixpkgs

pkgs.netcat

Utility which reads and writes data across network connections — LibreSSL implementation

Package maintainers

created 2 months ago Activity log
  • Created suggestion
Mozilla Firefox before 25 allows modification of anonymous content of …

Mozilla Firefox before 25 allows modification of anonymous content of pluginProblem.xml binding

Affected products

Firefox
  • ==before 2013

Matching in nixpkgs

pkgs.firefoxpwa

Tool to install, manage and use Progressive Web Apps (PWAs) in Mozilla Firefox (native component)

pkgs.faust2firefox

The faust2firefox script, part of faust functional programming language for realtime audio signal processing

pkgs.firefox_decrypt

Tool to extract passwords from profiles of Mozilla Firefox and derivates

pkgs.firefox-sync-client

Commandline-utility to list/view/edit/delete entries in a firefox-sync account.

pkgs.gnomeExtensions.firefox-profiles

Easily launch Firefox with your favorite profile right from the indicator menu!

  • nixos-unstable 5
    • nixpkgs-unstable 5
    • nixos-unstable-small 5
  • nixos-25.11 5
    • nixos-25.11-small 5
    • nixpkgs-25.11-darwin 5

Package maintainers

created 2 months ago Activity log
  • Created suggestion
The CentralAuth extension for MediaWiki before 1.19.10, 1.2x before 1.21.4, …

The CentralAuth extension for MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to obtain usernames via vectors related to writing the names to the DOM of a page.

Affected products

MediaWiki
  • ==1.2x before 1.21.4
  • ==before 1.19.10
  • ==1.22.x before 1.22.1

Matching in nixpkgs

Package maintainers

created 2 months ago Activity log
  • Created suggestion
Openshift has shell command injection flaws due to unsanitized data …

Openshift has shell command injection flaws due to unsanitized data being passed into shell commands.

References

Affected products

Openshift
  • ==through 2014-04-03

Matching in nixpkgs

Package maintainers

created 2 months ago Activity log
  • Created suggestion
Orthanc versions before 1.12.10 are affected by an authorisation logic …

Orthanc versions before 1.12.10 are affected by an authorisation logic flaw in the application's HTTP Basic Authentication implementation. Successful exploitation could result in Privilege Escalation, potentially allowing full administrative access.

Affected products

orthanc
  • =<1.12.9

Matching in nixpkgs

pkgs.orthanc

Orthanc is a lightweight, RESTful DICOM server for healthcare and medical research

Package maintainers

Permalink CVE-2026-27100
4.3 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): NONE
  • Availability impact (A): NONE
created 2 months ago Activity log
  • Created suggestion
Jenkins 2.550 and earlier, LTS 2.541.1 and earlier accepts Run …

Jenkins 2.550 and earlier, LTS 2.541.1 and earlier accepts Run Parameter values that refer to builds the user submitting the build does not have access to, allowing attackers with Item/Build and Item/Configure permission to obtain information about the existence of jobs, the existence of builds, and if a specified build exists, its display name.

References

Affected products

Jenkins
  • <2.541.*
  • *

Matching in nixpkgs

pkgs.jenkins-job-builder

Jenkins Job Builder is a system for configuring Jenkins jobs using simple YAML files stored in Git