Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Automatically generated suggestions

to slate a suggestion for refinement.

to mark a suggestion as irrelevant and log the reason.

View:
Compact
Detailed
created 2 months ago Activity log
  • Created suggestion
Multiple cross-site scripting (XSS) vulnerabilities in Ariadne 2.7.6 allow remote …

Multiple cross-site scripting (XSS) vulnerabilities in Ariadne 2.7.6 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO parameter to (1) index.php and (2) loader.php.

References

Affected products

Ariadne
  • ==2.7.6

Matching in nixpkgs

Package maintainers

created 2 months ago Activity log
  • Created suggestion
mom creates world-writable pid files in /var/run

mom creates world-writable pid files in /var/run

Affected products

mom
  • ==through 2012-10-05

Matching in nixpkgs

pkgs.mommy

mommy's here to support you, in any shell, on any system~ ❤️

pkgs.cargo-mommy

Cargo wrapper that encourages you after running commands

pkgs.trimmomatic

Flexible read trimming tool for Illumina NGS data

  • nixos-unstable 0.40
    • nixpkgs-unstable 0.40
    • nixos-unstable-small 0.40
  • nixos-25.11 0.40
    • nixos-25.11-small 0.40
    • nixpkgs-25.11-darwin 0.40

Package maintainers

created 2 months ago Activity log
  • Created suggestion
atop: symlink attack possible due to insecure tempfile handling

atop: symlink attack possible due to insecure tempfile handling

References

Affected products

atop
  • ==through 1.26

Matching in nixpkgs

pkgs.numatop

Tool for runtime memory locality characterization and analysis of processes and threads on a NUMA system

Package maintainers

created 2 months ago Activity log
  • Created suggestion
An issue exists in third_party/WebKit/Source/WebCore/svg/animation/SVGSMILElement.h in WebKit in Google Chrome …

An issue exists in third_party/WebKit/Source/WebCore/svg/animation/SVGSMILElement.h in WebKit in Google Chrome before Blink M11 and M12 when trying to access a removed smil element.

References

Affected products

Chrome
  • ==before Blink M11 and M12

Matching in nixpkgs

pkgs.netflix

Open Netflix in Google Chrome app mode

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small
  • nixos-25.11 -
    • nixos-25.11-small
    • nixpkgs-25.11-darwin

pkgs.chrome-export

Scripts to save Google Chrome's bookmarks and history as HTML bookmarks files

pkgs.go-chromecast

CLI for Google Chromecast, Home devices and Cast Groups

created 2 months ago Activity log
  • Created suggestion
mpack 1.6 has information disclosure via eavesdropping on mails sent …

mpack 1.6 has information disclosure via eavesdropping on mails sent by other users

Affected products

mpack
  • ==1.6

Matching in nixpkgs

pkgs.mpack

Utilities for encoding and decoding binary files in MIME

  • nixos-unstable 1.6
    • nixpkgs-unstable 1.6
    • nixos-unstable-small 1.6
  • nixos-25.11 1.6
    • nixos-25.11-small 1.6
    • nixpkgs-25.11-darwin 1.6

pkgs.libmpack

Simple implementation of msgpack in C

Package maintainers

created 2 months ago Activity log
  • Created suggestion
lilo-uuid-diskid causes lilo.conf to be world-readable in lilo 23.1.

lilo-uuid-diskid causes lilo.conf to be world-readable in lilo 23.1.

Affected products

lilo
  • ==23.1

Matching in nixpkgs

pkgs.lilo

Linux bootloader

  • nixos-unstable 24.2
    • nixpkgs-unstable 24.2
    • nixos-unstable-small 24.2
  • nixos-25.11 24.2
    • nixos-25.11-small 24.2
    • nixpkgs-25.11-darwin 24.2

Package maintainers

Permalink CVE-2010-0047
8.8 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): REQUIRED
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): HIGH
created 2 months ago Activity log
  • Created suggestion
Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows …

Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to "HTML object element fallback content."

References

Affected products

n/a
  • ==n/a
safari
  • ==4.0.3
  • ==4.0.0b
  • ==4.0
  • ==4.0.2
  • ==4.0.1
  • =<4.0.4

Matching in nixpkgs

Package maintainers

created 2 months ago Activity log
  • Created suggestion
gnome-keyring does not discard stored secrets when using gnome_keyring_lock_all_sync function

gnome-keyring does not discard stored secrets when using gnome_keyring_lock_all_sync function

References

Affected products

gnome-keyring
  • ==Fixed 3.14.0

Matching in nixpkgs

pkgs.gnome-keyring

Collection of components in GNOME that store secrets, passwords, keys, certificates and make them available to applications

  • nixos-unstable 48.0
    • nixpkgs-unstable 48.0
    • nixos-unstable-small 48.0
  • nixos-25.11 48.0
    • nixos-25.11-small 48.0
    • nixpkgs-25.11-darwin 48.0

Package maintainers

created 2 months ago Activity log
  • Created suggestion
simplesamlphp before 1.6.3 (squeeze) and before 1.8.2 (sid) incorrectly handles …

simplesamlphp before 1.6.3 (squeeze) and before 1.8.2 (sid) incorrectly handles XML encryption which could allow remote attackers to decrypt or forge messages.

References

Affected products

simplesamlphp
  • ==1.13.1-2

Matching in nixpkgs

pkgs.simplesamlphp

SimpleSAMLphp is an application written in native PHP that deals with authentication (SQL, .htpasswd, YubiKey, LDAP, PAPI, Radius)

Package maintainers

created 2 months ago Activity log
  • Created suggestion
tuned 2.10.0 creates its PID file with insecure permissions which …

tuned 2.10.0 creates its PID file with insecure permissions which allows local users to kill arbitrary processes.

References

Affected products

tuned
  • ==2.10.0-1

Matching in nixpkgs

Package maintainers