Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Automatically generated suggestions

to slate a suggestion for refinement.

to mark a suggestion as irrelevant and log the reason.

View:
Compact
Detailed
Permalink CVE-2026-16219
2.1 LOW
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): Low (L)
  • Vulnerable System Impact Integrity (VI): Low (L)
  • Vulnerable System Impact Availability (VA): Low (L)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Exploit Maturity (E): POC (P)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
  • Modified Vulnerable System Impact Integrity (MVI): Low (L)
  • Modified Vulnerable System Impact Availability (MVA): Low (L)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
created 1 month, 1 week ago Activity log
  • Created suggestion
Croogo CMS Admin File Manager FileManager.php isEditable path traversal

A flaw has been found in Croogo CMS up to 4.0.7. This affects the function FileManager::isEditable of the file FileManager/src/Utility/FileManager.php of the component Admin File Manager. This manipulation causes path traversal. The attack can be initiated remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Affected products

CMS
  • ==4.0.2
  • ==4.0.5
  • ==4.0.4
  • ==4.0.0
  • ==4.0.3
  • ==4.0.1
  • ==4.0.6
  • ==4.0.7

Matching in nixpkgs

pkgs.lcms

Color management engine

  • nixos-unstable 2.18
    • nixpkgs-unstable 2.18
    • nixos-unstable-small 2.19.1
  • nixos-26.05 2.18
    • nixos-26.05-small 2.18
    • nixpkgs-26.05-darwin 2.18

pkgs.lcms1

Color management engine

  • nixos-unstable 1.19
    • nixpkgs-unstable 1.19
    • nixos-unstable-small 1.19
  • nixos-26.05 1.19
    • nixos-26.05-small 1.19
    • nixpkgs-26.05-darwin 1.19

pkgs.lcms2

Color management engine

  • nixos-unstable 2.18
    • nixpkgs-unstable 2.18
    • nixos-unstable-small 2.19.1
  • nixos-26.05 2.18
    • nixos-26.05-small 2.18
    • nixpkgs-26.05-darwin 2.18

pkgs.xcmsdb

Device Color Characterization utility for X Color Management System

pkgs.argyllcms

Color management system (compatible with ICC)

pkgs.pcmsolver

API for the Polarizable Continuum Model

Package maintainers

Permalink CVE-2026-26081
4.8 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): Low (L)
created 1 month, 1 week ago Activity log
  • Created suggestion
HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a …

HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected.

Affected products

HAProxy
  • <3.1.14
  • <3.2.12
  • <3.3.3
  • <3.0.12

Matching in nixpkgs

pkgs.haproxy

Reliable, high performance TCP/HTTP load balancer

Package maintainers

Permalink CVE-2026-16277
6.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): High (H)
created 1 month, 1 week ago Activity log
  • Created suggestion
Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbaddrlist()

A stack-based buffer overflow was found in rpcbind's rpcinfo utility. When querying a remote rpcbind service with `rpcinfo -l`, address information returned by the server is copied into a fixed-size buffer without sufficient bounds checking. A malicious or compromised rpcbind server could use this flaw to crash the rpcinfo client, resulting in a denial of service. The highest threat from this vulnerability is to system availability.

Affected products

rpcbind

Matching in nixpkgs

pkgs.rpcbind

ONC RPC portmapper

  • nixos-unstable -
    • nixos-unstable-small 1.2.9
  • nixos-26.05 -
    • nixos-26.05-small 1.2.6

Package maintainers

Permalink CVE-2026-64621
9.3 CRITICAL
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): High (H)
  • Vulnerable System Impact Integrity (VI): High (H)
  • Vulnerable System Impact Availability (VA): High (H)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): High (H)
  • Modified Vulnerable System Impact Integrity (MVI): High (H)
  • Modified Vulnerable System Impact Availability (MVA): High (H)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 1 month, 1 week ago Activity log
  • Created suggestion
FreeRDP before 3.28.0 Double-Free via selectedmonitors

FreeRDP before 3.28.0 (affected 3.x through 3.27.1) contains a double-free vulnerability in freerdp_client_rdp_file_apply_to_settings() (client/common/file.c) when parsing the selectedmonitors field of a .rdp connection file. The MonitorIds array is allocated through the settings object, and a raw non-owning pointer to it is freed on the strtoul error path without clearing settings->MonitorIds, leaving it dangling; at teardown freerdp_settings_free() frees the same buffer again. An attacker who convinces a victim to open a crafted .rdp file with oversized monitor tokens can trigger a size-controlled double-free in any FreeRDP CLI client (xfreerdp/sdl-freerdp/wlfreerdp) in the default configuration.

Affected products

FreeRDP
  • <3.28.0
  • ==3.28.0

Matching in nixpkgs

Package maintainers

Permalink CVE-2026-63738
5.3 MEDIUM
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): Low (L)
  • Vulnerable System Impact Integrity (VI): None (N)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
  • Modified Vulnerable System Impact Integrity (MVI): None (N)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 1 month, 1 week ago Activity log
  • Created suggestion
SurrealDB 3.1.0 before 3.1.5 Field Permission Bypass via Traversal

SurrealDB versions 3.1.0 before 3.1.5 fail to enforce field-level SELECT permissions when records are accessed through graph-edge or back-reference traversals. Attackers with table-level SELECT access can read field values hidden by field-level permissions by materializing records through graph traversals instead of direct table scans.

Affected products

surrealdb
  • ==3.1.5
  • <3.1.5

Matching in nixpkgs

pkgs.surrealdb

Scalable, distributed, collaborative, document-graph database, for the realtime web

  • nixos-unstable -
    • nixos-unstable-small 2.6.1
  • nixos-26.05 -
    • nixos-26.05-small 2.6.1

pkgs.surrealdb-surrealkv

SurrealDB with the SurrealKV storage backend

  • nixos-unstable -
    • nixos-unstable-small 2.6.1
  • nixos-26.05 -
    • nixos-26.05-small 2.6.1

pkgs.surrealdb-migrations

Awesome SurrealDB migration tool, with a user-friendly CLI and a versatile Rust library that enables seamless integration into any project

  • nixos-unstable -
    • nixos-unstable-small 2.4.0
  • nixos-26.05 -
    • nixos-26.05-small 2.4.0

Package maintainers

Permalink CVE-2026-63760
8.7 HIGH
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): None (N)
  • Vulnerable System Impact Integrity (VI): None (N)
  • Vulnerable System Impact Availability (VA): High (H)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): None (N)
  • Modified Vulnerable System Impact Integrity (MVI): None (N)
  • Modified Vulnerable System Impact Availability (MVA): High (H)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 1 month, 1 week ago Activity log
  • Created suggestion
SurrealDB before 3.1.0 Denial of Service via JSON Parser

SurrealDB before 3.1.0 fails to enforce the configured recursion depth limit in the value and JSON parser when processing nested braces, brackets, or parentheses. Unauthenticated attackers can send deeply nested JSON payloads to the WebSocket /rpc endpoint to exhaust server memory and crash the process.

Affected products

surrealdb
  • ==3.1.0
  • <3.1.0

Matching in nixpkgs

pkgs.surrealdb

Scalable, distributed, collaborative, document-graph database, for the realtime web

  • nixos-unstable -
    • nixos-unstable-small 2.6.1
  • nixos-26.05 -
    • nixos-26.05-small 2.6.1

pkgs.surrealdb-surrealkv

SurrealDB with the SurrealKV storage backend

  • nixos-unstable -
    • nixos-unstable-small 2.6.1
  • nixos-26.05 -
    • nixos-26.05-small 2.6.1

pkgs.surrealdb-migrations

Awesome SurrealDB migration tool, with a user-friendly CLI and a versatile Rust library that enables seamless integration into any project

  • nixos-unstable -
    • nixos-unstable-small 2.4.0
  • nixos-26.05 -
    • nixos-26.05-small 2.4.0

Package maintainers

Permalink CVE-2026-63090
8.7 HIGH
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): High (H)
  • Vulnerable System Impact Integrity (VI): High (H)
  • Vulnerable System Impact Availability (VA): High (H)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): High (H)
  • Modified Vulnerable System Impact Integrity (MVI): High (H)
  • Modified Vulnerable System Impact Availability (MVA): High (H)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 1 month, 1 week ago Activity log
  • Created suggestion
ProFTPD mod_sftp Heap Buffer Overflow via SFTP Packet Reassembly

ProFTPD before 1.3.9c and 1.3.10rc3 contains a heap-based buffer overflow vulnerability in the mod_sftp module that allows authenticated low-privilege attackers to achieve arbitrary code execution by sending crafted SFTP packet fragments exceeding the 16 KB reassembly buffer in the fxp.c component. Attackers can supply oversized fragments to trigger an incorrectly conditioned reallocation, corrupt pool freelist metadata, overwrite the root_fs BSS global pointer to reference a fake filesystem struct, and redirect pr_fsio_stat() to system() via a crafted RENAME request.

Affected products

proftpd
  • <1.3.10rc3
  • <1.3.9c

Matching in nixpkgs

pkgs.proftpd

Highly configurable GPL-licensed FTP server software

  • nixos-unstable -
  • nixos-26.05 -

Package maintainers

Permalink CVE-2026-63747
8.7 HIGH
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): None (N)
  • Vulnerable System Impact Integrity (VI): None (N)
  • Vulnerable System Impact Availability (VA): High (H)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): None (N)
  • Modified Vulnerable System Impact Integrity (MVI): None (N)
  • Modified Vulnerable System Impact Availability (MVA): High (H)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 1 month, 1 week ago Activity log
  • Created suggestion
SurrealDB before 3.1.0 Denial of Service via malformed RPC use

SurrealDB versions before 3.1.0 contain a denial of service vulnerability in the RPC use handler that panics when db is set without a namespace. Unauthenticated attackers can send a malformed WebSocket message to the /rpc endpoint to crash the server process.

Affected products

surrealdb
  • ==3.1.0
  • <3.1.0

Matching in nixpkgs

pkgs.surrealdb

Scalable, distributed, collaborative, document-graph database, for the realtime web

  • nixos-unstable -
    • nixos-unstable-small 2.6.1
  • nixos-26.05 -
    • nixos-26.05-small 2.6.1

pkgs.surrealdb-surrealkv

SurrealDB with the SurrealKV storage backend

  • nixos-unstable -
    • nixos-unstable-small 2.6.1
  • nixos-26.05 -
    • nixos-26.05-small 2.6.1

pkgs.surrealdb-migrations

Awesome SurrealDB migration tool, with a user-friendly CLI and a versatile Rust library that enables seamless integration into any project

  • nixos-unstable -
    • nixos-unstable-small 2.4.0
  • nixos-26.05 -
    • nixos-26.05-small 2.4.0

Package maintainers

Permalink CVE-2026-47128
6.1 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): High (H)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): Low (L)
created 1 month, 1 week ago Activity log
  • Created suggestion
nono: Sandbox escape on Linux via D-Bus: `systemd-run --user`

nono is software that allows users to run AI agents in a zero-latency sandbox. Prior to version 0.55.0, the nono Landlock/seccomp policies allow access to local Unix domain sockets (concrete and abstract). This allows an easy sandbox escape by talking to the per-user systemd dbus socket. Version 0.55.0 patches the issue.

Affected products

nono
  • ==< 0.55.0

Matching in nixpkgs

pkgs.nono

Secure, kernel-enforced sandbox for AI agents, MCP and LLM workloads

  • nixos-unstable -
  • nixos-26.05 -

pkgs.mononoki

Font for programming and code review

  • nixos-unstable -
    • nixos-unstable-small 1.6
  • nixos-26.05 -
    • nixos-26.05-small 1.6

pkgs.gnonograms

Nonograms puzzle game

  • nixos-unstable -
    • nixos-unstable-small 2.1.2
  • nixos-26.05 -
    • nixos-26.05-small 2.1.2

pkgs.nerd-fonts.mononoki

Nerd Fonts: Keeps in mind differentiation of characters and resolution sizes

  • nixos-unstable -
  • nixos-26.05 -

pkgs.maple-mono.Normal-CN

Open source Normal Ligature monospace CN font with round corner and ligatures for IDE and command line

  • nixos-unstable -
    • nixos-unstable-small 7.9
  • nixos-26.05 -
    • nixos-26.05-small 7.9

pkgs.maple-mono.Normal-NF

Open source Normal Ligature Nerd Font font with round corner and ligatures for IDE and command line

  • nixos-unstable -
    • nixos-unstable-small 7.9
  • nixos-26.05 -
    • nixos-26.05-small 7.9

pkgs.maple-mono.Normal-OTF

Open source Normal Ligature OpenType font with round corner and ligatures for IDE and command line

  • nixos-unstable -
    • nixos-unstable-small 7.9
  • nixos-26.05 -
    • nixos-26.05-small 7.9

pkgs.maple-mono.Normal-TTF

Open source Normal Ligature monospace TrueType font with round corner and ligatures for IDE and command line

  • nixos-unstable -
    • nixos-unstable-small 7.9
  • nixos-26.05 -
    • nixos-26.05-small 7.9

pkgs.maple-mono.NormalNL-CN

Open source Normal No Ligature monospace CN font with round corner and ligatures for IDE and command line

  • nixos-unstable -
    • nixos-unstable-small 7.9
  • nixos-26.05 -
    • nixos-26.05-small 7.9

pkgs.maple-mono.NormalNL-NF

Open source Normal No Ligature Nerd Font font with round corner and ligatures for IDE and command line

  • nixos-unstable -
    • nixos-unstable-small 7.9
  • nixos-26.05 -
    • nixos-26.05-small 7.9

pkgs.maple-mono.Normal-NF-CN

Open source Normal Ligature Nerd Font CN font with round corner and ligatures for IDE and command line

  • nixos-unstable -
    • nixos-unstable-small 7.9
  • nixos-26.05 -
    • nixos-26.05-small 7.9

pkgs.maple-mono.Normal-Woff2

Open source Normal Ligature WOFF2.0 font with round corner and ligatures for IDE and command line

  • nixos-unstable -
    • nixos-unstable-small 7.9
  • nixos-26.05 -
    • nixos-26.05-small 7.9

pkgs.maple-mono.NormalNL-OTF

Open source Normal No Ligature OpenType font with round corner and ligatures for IDE and command line

  • nixos-unstable -
    • nixos-unstable-small 7.9
  • nixos-26.05 -
    • nixos-26.05-small 7.9

pkgs.maple-mono.NormalNL-TTF

Open source Normal No Ligature monospace TrueType font with round corner and ligatures for IDE and command line

  • nixos-unstable -
    • nixos-unstable-small 7.9
  • nixos-26.05 -
    • nixos-26.05-small 7.9

pkgs.maple-mono.NormalNL-NF-CN

Open source Normal No Ligature Nerd Font CN font with round corner and ligatures for IDE and command line

  • nixos-unstable -
    • nixos-unstable-small 7.9
  • nixos-26.05 -
    • nixos-26.05-small 7.9

pkgs.maple-mono.NormalNL-Woff2

Open source Normal No Ligature WOFF2.0 font with round corner and ligatures for IDE and command line

  • nixos-unstable -
    • nixos-unstable-small 7.9
  • nixos-26.05 -
    • nixos-26.05-small 7.9

pkgs.maple-mono.Normal-Variable

Open source Normal Ligature monospace variable font with round corner and ligatures for IDE and command line

  • nixos-unstable -
    • nixos-unstable-small 7.9
  • nixos-26.05 -
    • nixos-26.05-small 7.9

pkgs.maple-mono.NormalNL-Variable

Open source Normal No Ligature monospace variable font with round corner and ligatures for IDE and command line

  • nixos-unstable -
    • nixos-unstable-small 7.9
  • nixos-26.05 -
    • nixos-26.05-small 7.9

pkgs.maple-mono.Normal-CN-unhinted

Open source Normal Ligature monospace CN unhinted font with round corner and ligatures for IDE and command line

  • nixos-unstable -
    • nixos-unstable-small 7.9
  • nixos-26.05 -
    • nixos-26.05-small 7.9

pkgs.maple-mono.Normal-NF-unhinted

Open source Normal Ligature Nerd Font unhinted font with round corner and ligatures for IDE and command line

  • nixos-unstable -
    • nixos-unstable-small 7.9
  • nixos-26.05 -
    • nixos-26.05-small 7.9

pkgs.maple-mono.Normal-TTF-AutoHint

Open source Normal Ligature monospace ttf autohint font with round corner and ligatures for IDE and command line

  • nixos-unstable -
    • nixos-unstable-small 7.9
  • nixos-26.05 -
    • nixos-26.05-small 7.9

pkgs.maple-mono.NormalNL-CN-unhinted

Open source Normal No Ligature monospace CN unhinted font with round corner and ligatures for IDE and command line

  • nixos-unstable -
    • nixos-unstable-small 7.9
  • nixos-26.05 -
    • nixos-26.05-small 7.9

pkgs.maple-mono.NormalNL-NF-unhinted

Open source Normal No Ligature Nerd Font unhinted font with round corner and ligatures for IDE and command line

  • nixos-unstable -
    • nixos-unstable-small 7.9
  • nixos-26.05 -
    • nixos-26.05-small 7.9

pkgs.maple-mono.Normal-NF-CN-unhinted

Open source Normal Ligature Nerd Font CN unhinted font with round corner and ligatures for IDE and command line

  • nixos-unstable -
    • nixos-unstable-small 7.9
  • nixos-26.05 -
    • nixos-26.05-small 7.9

pkgs.maple-mono.NormalNL-TTF-AutoHint

Open source Normal No Ligature monospace ttf autohint font with round corner and ligatures for IDE and command line

  • nixos-unstable -
    • nixos-unstable-small 7.9
  • nixos-26.05 -
    • nixos-26.05-small 7.9

pkgs.maple-mono.NormalNL-NF-CN-unhinted

Open source Normal No Ligature Nerd Font CN unhinted font with round corner and ligatures for IDE and command line

  • nixos-unstable -
    • nixos-unstable-small 7.9
  • nixos-26.05 -
    • nixos-26.05-small 7.9

Package maintainers

created 1 month, 1 week ago Activity log
  • Created suggestion
Use after free in GPU in Google Chrome on Android …

Use after free in GPU in Google Chrome on Android prior to 150.0.7871.128 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

Affected products

Chrome
  • <150.0.7871.128

Matching in nixpkgs

pkgs.netflix

Open Netflix in Google Chrome app mode

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small
  • nixos-26.05 -
    • nixos-26.05-small
    • nixpkgs-26.05-darwin

pkgs.chrome-export

Scripts to save Google Chrome's bookmarks and history as HTML bookmarks files

pkgs.go-chromecast

CLI for Google Chromecast, Home devices and Cast Groups