Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Automatically generated suggestions

to slate a suggestion for refinement.

to mark a suggestion as irrelevant and log the reason.

View:
Compact
Detailed
created 2 months ago Activity log
  • Created suggestion
The CSS parser (khtml/css/cssparser.cpp) in Konqueror in KDE 4.7.3 allows …

The CSS parser (khtml/css/cssparser.cpp) in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via a crafted font face source, related to "type confusion."

Affected products

Konqueror
  • ==4.7.3

Matching in nixpkgs

created 2 months ago Activity log
  • Created suggestion
qpid-cpp 1.0 crashes when a large message is sent and …

qpid-cpp 1.0 crashes when a large message is sent and the Digest-MD5 mechanism with a security layer is in use .

Affected products

qpid-cpp
  • ==1.0

Matching in nixpkgs

created 2 months ago Activity log
  • Created suggestion
libuser has information disclosure when moving user's home directory

libuser has information disclosure when moving user's home directory

References

Affected products

libuser
  • ==Fixed in 1:0.60

Matching in nixpkgs

Package maintainers

created 2 months ago Activity log
  • Created suggestion
nginx http proxy module does not verify peer identity of …

nginx http proxy module does not verify peer identity of https origin server which could facilitate man-in-the-middle attack (MITM)

Affected products

nginx
  • ==through 1.6.2

Matching in nixpkgs

pkgs.coc-nginx

nginx-language-server extension for coc.nvim

pkgs.nginxQuic

Reverse proxy and lightweight webserver

created 2 months ago Activity log
  • Created suggestion
The encrypt/decrypt functions in Ruby on Rails 2.3 are vulnerable …

The encrypt/decrypt functions in Ruby on Rails 2.3 are vulnerable to padding oracle attacks.

Affected products

rails
  • ==2.3

Matching in nixpkgs

pkgs.rails-new

Generate new Rails applications without having to install Ruby

Package maintainers

created 2 months ago Activity log
  • Created suggestion
Moodle before 2.2.2 has a permission issue in Forum Subscriptions …

Moodle before 2.2.2 has a permission issue in Forum Subscriptions where unenrolled users can subscribe/unsubscribe via mod/forum/index.php

Affected products

Moodle
  • ==2.1 to 2.1.4+
  • ==2.2 to 2.2.1+

Matching in nixpkgs

pkgs.moodle

Free and open-source learning management system (LMS) written in PHP

pkgs.moodle-dl

Moodle downloader that downloads course content fast from Moodle

Package maintainers

created 2 months ago Activity log
  • Created suggestion
insecure permissions on files containing confidential data

The install-chef-suse.sh script shipped with crowbar before 2012-10-02 is creating files containing confidential data with insecure permissions, allowing local users to read confidential data.

References

Affected products

crowbar
  • <2012-10-02

Matching in nixpkgs

Package maintainers

created 2 months ago Activity log
  • Created suggestion
offlineimap before 6.3.4 added support for SSL server certificate validation …

offlineimap before 6.3.4 added support for SSL server certificate validation but it is still possible to use SSL v2 protocol, which is a flawed protocol with multiple security deficiencies.

Affected products

offlineimap
  • ==before 6.3.4

Matching in nixpkgs

pkgs.offlineimap

Synchronize emails between two repositories, so that you can read the same mailbox from multiple computers

created 2 months ago Activity log
  • Created suggestion
gdk-pixbuf through 2.31.1 has GIF loader buffer overflow when initializing …

gdk-pixbuf through 2.31.1 has GIF loader buffer overflow when initializing decompression tables due to an input validation flaw

Affected products

gdk-pixbuf
  • ==through 2.31.1

Matching in nixpkgs

Package maintainers

created 2 months ago Activity log
  • Created suggestion
Mercurial before 1.6.4 fails to verify the Common Name field …

Mercurial before 1.6.4 fails to verify the Common Name field of SSL certificates which allows remote attackers who acquire a certificate signed by a Certificate Authority to perform a man-in-the-middle attack.

Affected products

mercurial
  • ==1.6.4

Matching in nixpkgs

pkgs.mercurial

Fast, lightweight SCM system for very large distributed projects

  • nixos-unstable 7.1
    • nixpkgs-unstable 7.1
    • nixos-unstable-small 7.1
  • nixos-25.11 7.1
    • nixos-25.11-small 7.1
    • nixpkgs-25.11-darwin 7.1

pkgs.mercurialFull

Fast, lightweight SCM system for very large distributed projects

  • nixos-unstable 7.1
    • nixpkgs-unstable 7.1
    • nixos-unstable-small 7.1
  • nixos-25.11 7.1
    • nixos-25.11-small 7.1
    • nixpkgs-25.11-darwin 7.1

pkgs.python313Packages.mercurial

Fast, lightweight SCM system for very large distributed projects

  • nixos-unstable 7.1
    • nixpkgs-unstable 7.1
    • nixos-unstable-small 7.1
  • nixos-25.11 7.1
    • nixos-25.11-small 7.1
    • nixpkgs-25.11-darwin 7.1

Package maintainers