Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Automatically generated suggestions

to slate a suggestion for refinement.

to mark a suggestion as irrelevant and log the reason.

View:
Compact
Detailed
created 2 months ago Activity log
  • Created suggestion
In JON 2.1.x before 2.1.2 SP1, users can obtain unauthorized …

In JON 2.1.x before 2.1.2 SP1, users can obtain unauthorized security information about private resources managed by JBoss ON.

References

Affected products

JON
  • ==2.1.x before 2.1.2 SP1

Matching in nixpkgs

pkgs.jonquil

JSON parser on top of TOML implementation

created 2 months ago Activity log
  • Created suggestion
Transmission before 1.92 allows an attacker to cause a denial …

Transmission before 1.92 allows an attacker to cause a denial of service (crash) or possibly have other unspecified impact via a large number of tr arguments in a magnet link.

Affected products

transmission
  • ==before 1.92

Matching in nixpkgs

pkgs.transmission_3

Fast, easy and free BitTorrent client (deprecated version 3)

pkgs.libtransmission_3

Fast, easy and free BitTorrent client (deprecated version 3)

pkgs.transmission_3-qt

Fast, easy and free BitTorrent client (deprecated version 3)

Package maintainers

created 2 months ago Activity log
  • Created suggestion
Moodle before 2.2.2 has a course information leak in gradebook …

Moodle before 2.2.2 has a course information leak in gradebook where users are able to see hidden grade items in export

Affected products

Moodle
  • ==2.1 to 2.1.4+
  • ==2.2 to 2.2.1+

Matching in nixpkgs

pkgs.moodle

Free and open-source learning management system (LMS) written in PHP

pkgs.moodle-dl

Moodle downloader that downloads course content fast from Moodle

Package maintainers

created 2 months ago Activity log
  • Created suggestion
Moodle before 2.2.2 has an external enrolment plugin context check …

Moodle before 2.2.2 has an external enrolment plugin context check issue where capability checks are not thorough

Affected products

Moodle
  • ==2.2 to 2.2.1+

Matching in nixpkgs

pkgs.moodle

Free and open-source learning management system (LMS) written in PHP

pkgs.moodle-dl

Moodle downloader that downloads course content fast from Moodle

Package maintainers

created 2 months ago Activity log
  • Created suggestion
Transmission before 1.92 allows attackers to prevent download of a …

Transmission before 1.92 allows attackers to prevent download of a file by corrupted data during the endgame.

Affected products

transmission
  • ==before 1.92

Matching in nixpkgs

pkgs.transmission_3

Fast, easy and free BitTorrent client (deprecated version 3)

pkgs.libtransmission_3

Fast, easy and free BitTorrent client (deprecated version 3)

pkgs.transmission_3-qt

Fast, easy and free BitTorrent client (deprecated version 3)

Package maintainers

Permalink CVE-2026-2523
5.3 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV):
  • Attack complexity (AC):
  • Privileges required (PR):
  • User interaction (UI):
  • Scope (S):
  • Confidentiality impact (C):
  • Integrity impact (I):
  • Availability impact (A):
created 2 months ago Activity log
  • Created suggestion
Open5GS SMF gn-handler.c smf_gn_handle_create_pdp_context_request assertion

A vulnerability was detected in Open5GS up to 2.7.6. The affected element is the function smf_gn_handle_create_pdp_context_request of the file /src/smf/gn-handler.c of the component SMF. The manipulation results in reachable assertion. It is possible to launch the attack remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Affected products

Open5GS
  • ==2.7.4
  • ==2.7.0
  • ==2.7.3
  • ==2.7.6
  • ==2.7.1
  • ==2.7.5
  • ==2.7.2

Matching in nixpkgs

Package maintainers

created 2 months ago Activity log
  • Created suggestion
Moodle before 2.2.2 has users' private files included in course …

Moodle before 2.2.2 has users' private files included in course backups

Affected products

Moodle
  • ==2.1 to 2.1.4+
  • ==2.2 to 2.2.1+
  • ==2.0 to 2.0.7+

Matching in nixpkgs

pkgs.moodle

Free and open-source learning management system (LMS) written in PHP

pkgs.moodle-dl

Moodle downloader that downloads course content fast from Moodle

Package maintainers

created 2 months ago Activity log
  • Created suggestion
Use after free vulnerability in documentloader in WebKit in Google …

Use after free vulnerability in documentloader in WebKit in Google Chrome before Blink M13 in DocumentWriter::replaceDocument function.

References

Affected products

Chrome
  • ==before Blink M13

Matching in nixpkgs

pkgs.netflix

Open Netflix in Google Chrome app mode

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small
  • nixos-25.11 -
    • nixos-25.11-small
    • nixpkgs-25.11-darwin

pkgs.chrome-export

Scripts to save Google Chrome's bookmarks and history as HTML bookmarks files

pkgs.go-chromecast

CLI for Google Chromecast, Home devices and Cast Groups

created 2 months ago Activity log
  • Created suggestion
liboping 1.3.2 allows users reading arbitrary files upon the local …

liboping 1.3.2 allows users reading arbitrary files upon the local system.

References

Affected products

liboping
  • ==1.3.2

Matching in nixpkgs

pkgs.liboping

C library to generate ICMP echo requests (a.k.a. ping packets)

Package maintainers

created 2 months ago Activity log
  • Created suggestion
xpdf allows remote attackers to cause a denial of service …

xpdf allows remote attackers to cause a denial of service (NULL pointer dereference and crash) in the way it processes JBIG2 PDF stream objects.

Affected products

xpdf
  • ==N/A

Matching in nixpkgs

pkgs.xpdf

Viewer for Portable Document Format (PDF) files

  • nixos-unstable 4.06
    • nixpkgs-unstable 4.06
    • nixos-unstable-small 4.06
  • nixos-25.11 4.06
    • nixos-25.11-small 4.06
    • nixpkgs-25.11-darwin 4.06

Package maintainers