Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Automatically generated suggestions

to slate a suggestion for refinement.

to mark a suggestion as irrelevant and log the reason.

View:
Compact
Detailed
Permalink CVE-2026-2524
5.3 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV):
  • Attack complexity (AC):
  • Privileges required (PR):
  • User interaction (UI):
  • Scope (S):
  • Confidentiality impact (C):
  • Integrity impact (I):
  • Availability impact (A):
created 2 months ago Activity log
  • Created suggestion
Open5GS MME mme_s11_handle_create_session_response denial of service

A flaw has been found in Open5GS 2.7.6. The impacted element is the function mme_s11_handle_create_session_response of the component MME. This manipulation causes denial of service. The attack can be initiated remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Affected products

Open5GS
  • ==2.7.6

Matching in nixpkgs

Package maintainers

created 2 months ago Activity log
  • Created suggestion
Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS …

Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML in the CI game plugin.

Affected products

jenkins
  • ==1.482

Matching in nixpkgs

pkgs.jenkins-job-builder

Jenkins Job Builder is a system for configuring Jenkins jobs using simple YAML files stored in Git

created 2 months ago Activity log
  • Created suggestion
lightdm before 0.9.6 writes in .dmrc and Xauthority files using …

lightdm before 0.9.6 writes in .dmrc and Xauthority files using root permissions while the files are in user controlled folders. A local user can overwrite root-owned files via a symlink, which can allow possible privilege escalation.

Affected products

lightdm
  • ==before 0.9.6

Matching in nixpkgs

pkgs.lightdm-enso-os-greeter

A fork of pantheon greeter that positions elements in a central and vertigal manner and adds a blur effect to the background

Package maintainers

created 2 months ago Activity log
  • Created suggestion
Input validation issues were found in Calibre at devices/linux_mount_helper.c which …

Input validation issues were found in Calibre at devices/linux_mount_helper.c which can lead to argument injection and elevation of privileges.

References

Affected products

Calibre
  • ==unknown

Matching in nixpkgs

pkgs.calibre-web

Web app for browsing, reading and downloading eBooks stored in a Calibre database

Package maintainers

created 2 months ago Activity log
  • Created suggestion
Insufficient policy enforcement in V8 in Google Chrome prior to …

Insufficient policy enforcement in V8 in Google Chrome prior to 14.0.0.0 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

References

Affected products

Chrome
  • <14.0.0.0

Matching in nixpkgs

pkgs.netflix

Open Netflix in Google Chrome app mode

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small
  • nixos-25.11 -
    • nixos-25.11-small
    • nixpkgs-25.11-darwin

pkgs.chrome-export

Scripts to save Google Chrome's bookmarks and history as HTML bookmarks files

pkgs.go-chromecast

CLI for Google Chromecast, Home devices and Cast Groups

created 2 months ago Activity log
  • Created suggestion
Multiple race conditions in the (1) mount.cifs and (2) umount.cifs …

Multiple race conditions in the (1) mount.cifs and (2) umount.cifs programs in Samba 3.6 allow local users to cause a denial of service (mounting outage) via a SIGKILL signal during a time window when the /etc/mtab~ file exists.

Affected products

Samba
  • ==3.6

Matching in nixpkgs

pkgs.samba

Standard Windows interoperability suite of programs for Linux and Unix

pkgs.samba4

Standard Windows interoperability suite of programs for Linux and Unix

pkgs.sambaFull

Standard Windows interoperability suite of programs for Linux and Unix

pkgs.samba4Full

Standard Windows interoperability suite of programs for Linux and Unix

Package maintainers

created 2 months ago Activity log
  • Created suggestion
plow has local buffer overflow vulnerability

plow has local buffer overflow vulnerability

Affected products

plow
  • ==0.0.1
  • ==0.0.2

Matching in nixpkgs

pkgs.plow

High-performance HTTP benchmarking tool that includes a real-time web UI and terminal display

pkgs.plowshare

A command-line download/upload tool for popular file sharing websites

Package maintainers

created 2 months ago Activity log
  • Created suggestion
Zend_XmlRpc Class in Magento before 1.7.0.2 contains an information disclosure …

Zend_XmlRpc Class in Magento before 1.7.0.2 contains an information disclosure vulnerability.

References

Affected products

Magento
  • ==1.7.0.1
  • ==fixed in 1.7.0.2

Matching in nixpkgs

Package maintainers

created 2 months ago Activity log
  • Created suggestion
The $smarty.template variable in Smarty3 allows attackers to possibly execute …

The $smarty.template variable in Smarty3 allows attackers to possibly execute arbitrary PHP code via the sysplugins/smarty_internal_compile_private_special_variable.php file.

References

Affected products

smarty3
  • ==3

Matching in nixpkgs

Package maintainers

created 2 months ago Activity log
  • Created suggestion
A cross-site request forgery (CSRF) vulnerability in the Activity module …

A cross-site request forgery (CSRF) vulnerability in the Activity module 6.x-1.x for Drupal.

References

Affected products

Activity
  • ==6.x-1.x

Matching in nixpkgs

pkgs.pg_activity

Top like application for PostgreSQL server activity monitoring

pkgs.gnomeExtensions.activitywatch-status

Shows the total time spent on the computer, fork of [activitywatch-status-gnome-shell](https://codeberg.org/cweiske/activitywatch-status-gnome-shell/)

  • nixos-unstable 2
    • nixpkgs-unstable 2
    • nixos-unstable-small 2
  • nixos-25.11 2
    • nixos-25.11-small 2
    • nixpkgs-25.11-darwin 2

pkgs.gnomeExtensions.activity-app-launcher

Integrates a category-based application launcher in the activities window. IMPORTANT: it needs the 'gnome-menus' and 'libgnome-menu-3-dev'; they must be installed in the system before installing this extension.

  • nixos-unstable 47
    • nixpkgs-unstable 47
    • nixos-unstable-small 47
  • nixos-25.11 45
    • nixos-25.11-small 45
    • nixpkgs-25.11-darwin 45

pkgs.gnomeExtensions.drive-activity-indicator

Visualize the activity of storage drives (disk activity LED simulator).

  • nixos-unstable 8
    • nixpkgs-unstable 8
    • nixos-unstable-small 8
  • nixos-25.11 8
    • nixos-25.11-small 8
    • nixpkgs-25.11-darwin 8