Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Automatically generated suggestions

to slate a suggestion for refinement.

to mark a suggestion as irrelevant and log the reason.

View:
Compact
Detailed
created 2 months ago Activity log
  • Created suggestion
libuser 0.56 and 0.57 has a TOCTOU (time-of-check time-of-use) race …

libuser 0.56 and 0.57 has a TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees.

References

Affected products

libuser
  • ==0.57
  • ==0.56

Matching in nixpkgs

Package maintainers

created 2 months ago Activity log
  • Created suggestion
A cross-site scripting vulnerability flaw was found in the auto_link …

A cross-site scripting vulnerability flaw was found in the auto_link function in Rails before version 3.0.6.

Affected products

rails
  • ==rails 3.0.6

Matching in nixpkgs

pkgs.rails-new

Generate new Rails applications without having to install Ruby

Package maintainers

created 2 months ago Activity log
  • Created suggestion
Bitlbee does not drop extra group privileges correctly in unix.c

Bitlbee does not drop extra group privileges correctly in unix.c

References

Affected products

Bitlbee
  • ==3.0.4

Matching in nixpkgs

pkgs.bitlbee

IRC instant messaging gateway

  • nixos-unstable 3.6
    • nixpkgs-unstable 3.6
    • nixos-unstable-small 3.6
  • nixos-25.11 3.6
    • nixos-25.11-small 3.6
    • nixpkgs-25.11-darwin 3.6

Package maintainers

created 2 months ago Activity log
  • Created suggestion
Thunar before 1.3.1 could crash when copy and pasting a …

Thunar before 1.3.1 could crash when copy and pasting a file name with % format characters due to a format string error.

Affected products

thunar
  • ==before 1.3.1

Matching in nixpkgs

pkgs.thunar-volman

Thunar extension for automatic management of removable drives and media

Package maintainers

created 2 months ago Activity log
  • Created suggestion
asterisk allows calls on prohibited networks

asterisk allows calls on prohibited networks

Affected products

asterisk
  • ==All 1.6.1 versions

Matching in nixpkgs

pkgs.asterisk

Software implementation of a telephone private branch exchange (PBX)

pkgs.asterisk_18

Software implementation of a telephone private branch exchange (PBX)

Package maintainers

created 2 months ago Activity log
  • Created suggestion
Yubico PAM Module before 2.10 performed user authentication when 'use_first_pass' …

Yubico PAM Module before 2.10 performed user authentication when 'use_first_pass' PAM configuration option was not used and the module was configured as 'sufficient' in the PAM configuration. A remote attacker could use this flaw to circumvent common authentication process and obtain access to the account in question by providing a NULL value (pressing Ctrl-D keyboard sequence) as the password string.

Affected products

yubico-pam
  • ==before 2.10

Matching in nixpkgs

created 2 months ago Activity log
  • Created suggestion
trytond 2.4: ModelView.button fails to validate authorization

trytond 2.4: ModelView.button fails to validate authorization

Affected products

trytond
  • ==≤ 2.4

Matching in nixpkgs

pkgs.trytond

Server of the Tryton application platform

Package maintainers

created 2 months ago Activity log
  • Created suggestion
Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS …

Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL that points to Jenkins.

Affected products

jenkins
  • ==1.447.2

Matching in nixpkgs

pkgs.jenkins-job-builder

Jenkins Job Builder is a system for configuring Jenkins jobs using simple YAML files stored in Git

created 2 months ago Activity log
  • Created suggestion
A Privilege Escalation vulnerability exits in Fedoraproject Sectool due to …

A Privilege Escalation vulnerability exits in Fedoraproject Sectool due to an incorrect DBus file.

Affected products

sectool
  • ==through 2012-04-03

Matching in nixpkgs

Package maintainers

created 2 months ago Activity log
  • Created suggestion
An privilege elevation vulnerability exists in Cloud-init before 0.7.0 when …

An privilege elevation vulnerability exists in Cloud-init before 0.7.0 when requests to an untrusted system are submitted for EC2 instance data.

Affected products

cloud-init
  • ==before 0.7.0

Matching in nixpkgs

pkgs.cloud-init

Provides configuration and customization of cloud instance

  • nixos-unstable 25.2
    • nixpkgs-unstable 25.2
    • nixos-unstable-small 25.2
  • nixos-25.11 25.2
    • nixos-25.11-small 25.2
    • nixpkgs-25.11-darwin 25.2

Package maintainers