Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Automatically generated suggestions

to slate a suggestion for refinement.

to mark a suggestion as irrelevant and log the reason.

View:
Compact
Detailed
created 2 months ago Activity log
  • Created suggestion
Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS …

Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML in the Violations plugin.

Affected products

jenkins
  • ==2

Matching in nixpkgs

pkgs.jenkins-job-builder

Jenkins Job Builder is a system for configuring Jenkins jobs using simple YAML files stored in Git

created 2 months ago Activity log
  • Created suggestion
LinuxMint as of 2012-03-19 has temporary file creation vulnerabilities in …

LinuxMint as of 2012-03-19 has temporary file creation vulnerabilities in mintUpdate.

Affected products

Mint
  • ==2012-03-19

Matching in nixpkgs

pkgs.mint

Refreshing language for the front-end web

pkgs.garmintools

Provides the ability to communicate with the Garmin Forerunner 305 via the USB interface

  • nixos-unstable 0.10
    • nixpkgs-unstable 0.10
    • nixos-unstable-small 0.10
  • nixos-25.11 0.10
    • nixos-25.11-small 0.10
    • nixpkgs-25.11-darwin 0.10

pkgs.mint-themes

Mint-X and Mint-Y themes for the cinnamon desktop

pkgs.mint-x-icons

Mint/metal theme based on mintified versions of Clearlooks Revamp, Elementary and Faenza

pkgs.marwaita-mint

Variation for marwaita GTK theme based on linux mint color scheme

  • nixos-unstable 24
    • nixpkgs-unstable 24
    • nixos-unstable-small 24
  • nixos-25.11 24
    • nixos-25.11-small 24
    • nixpkgs-25.11-darwin 24

Package maintainers

created 2 months ago Activity log
  • Created suggestion
OpenStack Keystone: extremely long passwords can crash Keystone by exhausting …

OpenStack Keystone: extremely long passwords can crash Keystone by exhausting stack space

Affected products

Keystone
  • ==2014.1.3

Matching in nixpkgs

pkgs.keystone

Lightweight multi-platform, multi-architecture assembler framework

Package maintainers

created 2 months ago Activity log
  • Created suggestion
thttpd has a local DoS vulnerability via specially-crafted .htpasswd files

thttpd has a local DoS vulnerability via specially-crafted .htpasswd files

References

Affected products

thttpd
  • ==2012-12-15

Matching in nixpkgs

pkgs.thttpd

Tiny/turbo/throttling HTTP server

  • nixos-unstable 2.29
    • nixpkgs-unstable 2.29
    • nixos-unstable-small 2.29
  • nixos-25.11 2.29
    • nixos-25.11-small 2.29
    • nixpkgs-25.11-darwin 2.29

Package maintainers

created 2 months ago Activity log
  • Created suggestion
udisks before 1.0.3 allows a local user to load arbitrary …

udisks before 1.0.3 allows a local user to load arbitrary Linux kernel modules.

Affected products

udisks
  • ==before 1.0.3

Matching in nixpkgs

pkgs.udisks

Daemon, tools and libraries to access and manipulate disks, storage devices and technologies

pkgs.udisks2

Daemon, tools and libraries to access and manipulate disks, storage devices and technologies

Package maintainers

created 2 months ago Activity log
  • Created suggestion
There is a file disclosure vulnerability in SMF (Simple Machines …

There is a file disclosure vulnerability in SMF (Simple Machines Forum) affecting versions through v2.0.3. On some configurations a SMF deployment is shared by several "co-admins" that are not trusted beyond the SMF deployment. This vulnerability allows them to read arbitrary files on the filesystem and therefore gain new privileges by reading the settings.php with the database passwords.

References

Affected products

SMF
  • ==through 2.0.3

Matching in nixpkgs

pkgs.smfh

Sleek Manifest File Handler

  • nixos-unstable 1.3
    • nixpkgs-unstable 1.3
    • nixos-unstable-small 1.3
  • nixos-25.11 1.3
    • nixos-25.11-small 1.4
    • nixpkgs-25.11-darwin 1.3

pkgs.libsmf

C library for reading and writing Standard MIDI Files

  • nixos-unstable 1.3
    • nixpkgs-unstable 1.3
    • nixos-unstable-small 1.3
  • nixos-25.11 1.3
    • nixos-25.11-small 1.3
    • nixpkgs-25.11-darwin 1.3

Package maintainers

created 2 months ago Activity log
  • Created suggestion
The error function in Error.cc in poppler before 0.21.4 allows …

The error function in Error.cc in poppler before 0.21.4 allows remote attackers to execute arbitrary commands via a PDF containing an escape sequence for a terminal emulator.

Affected products

poppler
  • ==before 0.21.4

Matching in nixpkgs

Package maintainers

created 2 months ago Activity log
  • Created suggestion
Yaws 1.91 has a directory traversal vulnerability in the way …

Yaws 1.91 has a directory traversal vulnerability in the way certain URLs are processed. A remote authenticated user could use this flaw to obtain content of arbitrary local files via specially-crafted URL request.

Affected products

yaws
  • ==1.91

Matching in nixpkgs

pkgs.yaws

Webserver for dynamic content written in Erlang

created 2 months ago Activity log
  • Created suggestion
xlockmore before 5.43 'dclock' security bypass vulnerability

xlockmore before 5.43 'dclock' security bypass vulnerability

Affected products

xlockmore
  • ==< 5.43

Matching in nixpkgs

pkgs.xlockmore

Screen locker for the X Window System

  • nixos-unstable 5.87
    • nixpkgs-unstable 5.87
    • nixos-unstable-small 5.87
  • nixos-25.11 5.84
    • nixos-25.11-small 5.84
    • nixpkgs-25.11-darwin 5.84

Package maintainers

created 2 months ago Activity log
  • Created suggestion
mediawiki allows deleted text to be exposed

mediawiki allows deleted text to be exposed

Affected products

mediawiki
  • ==1.16

Matching in nixpkgs

Package maintainers