Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Automatically generated suggestions

to slate a suggestion for refinement.

to mark a suggestion as irrelevant and log the reason.

View:
Compact
Detailed
created 2 months ago Activity log
  • Created suggestion
The git-changelog utility in git-extras 1.7.0 allows local users to …

The git-changelog utility in git-extras 1.7.0 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/changelog or (2) /tmp/.git-effort.

Affected products

git-extras
  • ==1.7.0

Matching in nixpkgs

pkgs.git-extras

GIT utilities -- repo summary, repl, changelog population, author commit percentages and more

Package maintainers

created 2 months ago Activity log
  • Created suggestion
openvas-scanner before 2011-09-11 creates a temporary file insecurely when generating …

openvas-scanner before 2011-09-11 creates a temporary file insecurely when generating OVAL system characteristics document with the ovaldi integrated tool enabled. A local attacker could use this flaw to conduct symlink attacks to overwrite arbitrary files on the system.

Affected products

openvas-scanner
  • ==through 2011-09-11

Matching in nixpkgs

Package maintainers

created 2 months ago Activity log
  • Created suggestion
LinuxMint as of 2012-03-19 has temporary file creation vulnerabilities in …

LinuxMint as of 2012-03-19 has temporary file creation vulnerabilities in mintNanny.

References

Affected products

Mint
  • ==2012-03-19

Matching in nixpkgs

pkgs.mint

Refreshing language for the front-end web

pkgs.garmintools

Provides the ability to communicate with the Garmin Forerunner 305 via the USB interface

  • nixos-unstable 0.10
    • nixpkgs-unstable 0.10
    • nixos-unstable-small 0.10
  • nixos-25.11 0.10
    • nixos-25.11-small 0.10
    • nixpkgs-25.11-darwin 0.10

pkgs.mint-themes

Mint-X and Mint-Y themes for the cinnamon desktop

pkgs.mint-x-icons

Mint/metal theme based on mintified versions of Clearlooks Revamp, Elementary and Faenza

pkgs.marwaita-mint

Variation for marwaita GTK theme based on linux mint color scheme

  • nixos-unstable 24
    • nixpkgs-unstable 24
    • nixos-unstable-small 24
  • nixos-25.11 24
    • nixos-25.11-small 24
    • nixpkgs-25.11-darwin 24

Package maintainers

created 2 months ago Activity log
  • Created suggestion
Gallery Plugin1.4 for WordPress has a Remote File Include Vulnerability

Gallery Plugin1.4 for WordPress has a Remote File Include Vulnerability

References

Affected products

Gallery
  • ==1.4

Matching in nixpkgs

created 2 months ago Activity log
  • Created suggestion
Mozilla Firefox prior to 3.6 has a DoS vulnerability due …

Mozilla Firefox prior to 3.6 has a DoS vulnerability due to an issue in the validation of certificates.

References

Affected products

Firefox
  • ==prior to 3.6

Matching in nixpkgs

pkgs.firefoxpwa

Tool to install, manage and use Progressive Web Apps (PWAs) in Mozilla Firefox (native component)

pkgs.faust2firefox

The faust2firefox script, part of faust functional programming language for realtime audio signal processing

pkgs.firefox_decrypt

Tool to extract passwords from profiles of Mozilla Firefox and derivates

pkgs.firefox-sync-client

Commandline-utility to list/view/edit/delete entries in a firefox-sync account.

pkgs.gnomeExtensions.firefox-profiles

Easily launch Firefox with your favorite profile right from the indicator menu!

  • nixos-unstable 5
    • nixpkgs-unstable 5
    • nixos-unstable-small 5
  • nixos-25.11 5
    • nixos-25.11-small 5
    • nixpkgs-25.11-darwin 5

Package maintainers

created 2 months ago Activity log
  • Created suggestion
poppler before 0.16.3 has malformed commands that may cause corruption …

poppler before 0.16.3 has malformed commands that may cause corruption of the internal stack.

Affected products

poppler
  • ==before 0.16.3

Matching in nixpkgs

Package maintainers

created 2 months ago Activity log
  • Created suggestion
In NetworkManager 0.9.2.0, when a new wireless network was created …

In NetworkManager 0.9.2.0, when a new wireless network was created with WPA/WPA2 security in AdHoc mode, it created an open/insecure network.

Affected products

network-manager
  • ==0.9.2.0

Matching in nixpkgs

Package maintainers

created 2 months ago Activity log
  • Created suggestion
A missing permission check was found in The CLI in …

A missing permission check was found in The CLI in JBoss Operations Network before 2.3.1 does not properly check permissions, which allows JBoss ON users to perform management tasks and configuration changes with the privileges of the administrator user.

References

Affected products

JBoss
  • ==2.3.1

Matching in nixpkgs

Package maintainers

created 2 months ago Activity log
  • Created suggestion
Bad cast in CSS in Google Chrome prior to 11.0.0.0 …

Bad cast in CSS in Google Chrome prior to 11.0.0.0 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

References

Affected products

Chrome
  • <11.0.0.0

Matching in nixpkgs

pkgs.netflix

Open Netflix in Google Chrome app mode

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small
  • nixos-25.11 -
    • nixos-25.11-small
    • nixpkgs-25.11-darwin

pkgs.chrome-export

Scripts to save Google Chrome's bookmarks and history as HTML bookmarks files

pkgs.go-chromecast

CLI for Google Chromecast, Home devices and Cast Groups

created 2 months ago Activity log
  • Created suggestion
Hash collision attack vulnerability in Jenkins before 1.447, Jenkins LTS …

Hash collision attack vulnerability in Jenkins before 1.447, Jenkins LTS before 1.424.2, and Jenkins Enterprise by CloudBees 1.424.x before 1.424.2.1 and 1.400.x before 1.400.0.11 could allow remote attackers to cause a considerable CPU load, aka "the Hash DoS attack."

References

Affected products

Jenkins
  • ==before 1.447
Jenkins LTS
  • ==before 1.424.2
Jenkins Enterprise by CloudBees
  • ==1.400.x before 1.400.0.11
  • ==1.424.x before 1.424.2.1

Matching in nixpkgs

pkgs.jenkins-job-builder

Jenkins Job Builder is a system for configuring Jenkins jobs using simple YAML files stored in Git