Nixpkgs Security Tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Automatically generated suggestions

to remove a suggestion from the queue.

created 5 hours ago
Buffer Over-read in WLAN Firmware

Transient DOS when processing a received frame with an excessively large authentication information element.

Affected products

Snapdragon
  • ==QCA6564AU
  • ==QCA8081
  • ==QCA6688AQ
  • ==AR8035
  • ==QCC2073
  • ==WCD9380
  • ==QCN6274
  • ==SSG2115P
  • ==WCN7881
  • ==LeMans_AU_LGIT
  • ==WCD9378
  • ==SM8635P
  • ==WSA8845H
  • ==SA7775P
  • ==SRV1M
  • ==WCD9395
  • ==QFW7124
  • ==WCD9370
  • ==Snapdragon X75 5G Modem-RF System
  • ==QCA6698AU
  • ==Snapdragon X72 5G Modem-RF System
  • ==QCA6595
  • ==QCA6698AQ
  • ==QCA6574
  • ==X2000086
  • ==X2000090
  • ==FWA Gen 3 Ultra Platform
  • ==QCA6777AQ
  • ==QCN9011
  • ==QCA6554A
  • ==Snapdragon 8 Elite
  • ==WCN7861
  • ==SA9000P
  • ==WSA8840
  • ==Cologne
  • ==QCA6574A
  • ==SA8620P
  • ==WCD9385
  • ==SSG2125P
  • ==SA8770P
  • ==WSA8830
  • ==QMP1000
  • ==QAMSRV1H
  • ==SM8650Q
  • ==SA8255P
  • ==SAR2130P
  • ==QCA8337
  • ==XG101032
  • ==SM8635
  • ==XG101039
  • ==QCC710
  • ==QFW7114
  • ==X2000094
  • ==QAM8255P
  • ==WCD9378C
  • ==SM7675
  • ==QCA6595AU
  • ==X2000077
  • ==SXR2250P
  • ==QCA6696
  • ==WSA8835
  • ==WCN7880
  • ==WCN6755
  • ==QCC2076
  • ==Snapdragon 8 Gen 3 Mobile Platform
  • ==WCN7860
  • ==WSA8845
  • ==WSA8832
  • ==QCA6678AQ
  • ==SXR1230P
  • ==WCD9340
  • ==FastConnect 6900
  • ==WCD9375
  • ==WCD9390
  • ==QAMSRV1M
  • ==SRV1H
  • ==LeMansAU
  • ==FastConnect 7800
  • ==Snapdragon Auto 5G Modem-RF Gen 2
  • ==SM7675P
  • ==QCS8550
  • ==QCA6574AU
  • ==QCA6787AQ
  • ==X2000092
  • ==QCA6584AU
  • ==Orne
  • ==SM8750P
  • ==QCN9012
  • ==Palawan25
  • ==QCN6224
  • ==QCA6391
  • ==SA7255P
  • ==QCA6797AQ
  • ==XG101002

Matching in nixpkgs

pkgs.snapdragon-profiler

Profiler for Android devices running Snapdragon chips

created 5 hours ago
XSS in Special:ApiSandbox

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files resources/src/mediawiki.Special.Apisandbox/ApiSandbox.Js. This issue affects MediaWiki: from 1.27.0 before 1.39.13, 1.42.7 1.43.2, 1.44.0.

Affected products

MediaWiki
  • <1.39.13, 1.42.7 1.43.2, 1.44.0

Matching in nixpkgs

Package maintainers

created 5 hours ago
Missing Authorization in GitLab

A vulnerability has been discovered in GitLab CE/EE affecting all versions starting with 16.8 before 18.5.0 that could have allowed unauthorized edits to merge request approval rules under certain conditions.

Affected products

GitLab
  • <18.5.0

Matching in nixpkgs

pkgs.gitlab-duo

CLI for GitLab AI assistant

pkgs.gitlab-kas

Kubernetes Agent (Gitlab side)

pkgs.gitlab-ci-ls

GitLab CI Language Server (gitlab-ci-ls)

pkgs.danger-gitlab

Gem that exists to ensure all dependencies are set up for Danger with GitLab

pkgs.gitlab-clippy

Convert clippy warnings into GitLab Code Quality report

pkgs.gitlab-runner

GitLab Runner the continuous integration executor of GitLab

pkgs.gitlab-ci-local

Run gitlab pipelines locally as shell executor or docker executor

pkgs.gitlab-timelogs

CLI utility to support you with your time logs in GitLab

pkgs.gitlab-ci-linter

.gitlab-ci.yml lint helper tool

pkgs.gitlab-release-cli

Toolset to create, retrieve and update releases on GitLab

pkgs.ocamlPackages.gitlab

Native OCaml bindings to Gitlab REST API v4

pkgs.vimPlugins.gitlab-vim

Integrate GitLab Duo with Neovim

pkgs.gitlab-container-registry

GitLab Docker toolset to pack, ship, store, and deliver content

pkgs.ocamlPackages.gitlab-jsoo

Gitlab APIv4 JavaScript library

pkgs.ocamlPackages.gitlab-unix

Gitlab APIv4 Unix library

pkgs.rubyPackages.gitlab-markup

None

pkgs.terraform-providers.gitlab

None

pkgs.ocamlPackages_latest.gitlab

Native OCaml bindings to Gitlab REST API v4

pkgs.gitlab-elasticsearch-indexer

Indexes Git repositories into Elasticsearch for GitLab

pkgs.rubyPackages_3_1.gitlab-markup

None

pkgs.rubyPackages_3_2.gitlab-markup

None

pkgs.rubyPackages_3_5.gitlab-markup

None

  • nixos-25.11 -

pkgs.rubyPackages_4_0.gitlab-markup

None

pkgs.python312Packages.mkdocs-gitlab

MkDocs plugin to transform strings such as #1234, %56, or !789 into links to a Gitlab repository

pkgs.python312Packages.python-gitlab

Interact with GitLab API

pkgs.python313Packages.mkdocs-gitlab

MkDocs plugin to transform strings such as #1234, %56, or !789 into links to a Gitlab repository

pkgs.python313Packages.python-gitlab

Interact with GitLab API

pkgs.python314Packages.mkdocs-gitlab

MkDocs plugin to transform strings into links to a Gitlab repository

pkgs.python314Packages.python-gitlab

Interact with GitLab API

pkgs.ocamlPackages_latest.gitlab-jsoo

Gitlab APIv4 JavaScript library

pkgs.ocamlPackages_latest.gitlab-unix

Gitlab APIv4 Unix library

pkgs.terraform-providers.gitlabhq_gitlab

None

pkgs.prometheus-gitlab-ci-pipelines-exporter

Prometheus / OpenMetrics exporter for GitLab CI pipelines insights

pkgs.vscode-extensions.gitlab.gitlab-workflow

GitLab extension for Visual Studio Code

pkgs.perlPackages.AlienBuildPluginDownloadGitLab

Alien::Build plugin to download from GitLab

pkgs.perl5Packages.AlienBuildPluginDownloadGitLab

Alien::Build plugin to download from GitLab

  • nixos-unstable -

pkgs.perl538Packages.AlienBuildPluginDownloadGitLab

Alien::Build plugin to download from GitLab

pkgs.perl540Packages.AlienBuildPluginDownloadGitLab

Alien::Build plugin to download from GitLab

  • nixos-25.05 -

Package maintainers

created 5 hours ago
Suppressed blocked IP is visible in Special:BlockList, RC, and other places

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/logging/ManualLogEntry.Php, includes/recentchanges/RecentChangeFactory.Php, includes/recentchanges/RecentChangeStore.Php. This issue affects MediaWiki: from * before 1.39.14, 1.43.4, 1.44.1.

Affected products

MediaWiki
  • <1.39.14, 1.43.4, 1.44.1

Matching in nixpkgs

Package maintainers

created 5 hours ago
Sanitizer::validateAttributes data-XSS

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki, Wikimedia Foundation Parsoid. This vulnerability is associated with program files includes/parser/Sanitizer.Php, src/Core/Sanitizer.Php. This issue affects MediaWiki: from * before 1.39.14, 1.43.4, 1.44.1; Parsoid: from * before 0.16.6, 0.20.4, 0.21.1.

Affected products

Parsoid
  • <0.16.6, 0.20.4, 0.21.1
MediaWiki
  • <1.39.14, 1.43.4, 1.44.1

Matching in nixpkgs

Package maintainers

created 5 hours ago
"{{SITENAME}} registered email address has been changed" email sent to unverified email addresses

Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/user/User.Php. This issue affects MediaWiki: from 1.27.0 before 1.39.13, 1.42.7 1.43.2, 1.44.0.

Affected products

MediaWiki
  • <1.39.13, 1.42.7 1.43.2, 1.44.0

Matching in nixpkgs

Package maintainers

created 5 hours ago
Improper Validation in Conduit-derived homeservers resulting in Unintended Proxy or Intermediary ('Confused Deputy')

continuwuity is a Matrix homeserver written in Rust. This vulnerability allows an attacker with a malicious remote server to cause the local server to sign an arbitrary event upon user interaction. Upon a user account leaving a room (rejecting an invite), joining a room or knocking on a room, the victim server may ask a remote server for assistance. If the victim asks the attacker server for assistance the attacker is able to provide an arbitrary event, which the victim will sign and return to the attacker. For the /leave endpoint, this works for any event with a supported room version, where the origin and origin_server_ts is set by the victim. For the /join endpoint, an additionally victim-set content field in the format of a join membership is needed. For the /knock endpoint, an additional victim-set content field in the format of a knock membership and a room version not between 1 and 6 is needed. This was exploited as a part of a larger chain against the continuwuity.org homeserver. This vulnerability affects all Conduit-derived servers. This vulnerability is fixed in Continuwuity 0.5.1, Conduit 0.10.11, Grapevine 0aae932b, and Tuwunel 1.4.9.

Affected products

continuwuity
  • ==< 0.5.1

Matching in nixpkgs

Package maintainers

created 5 hours ago
HTML rest endpoint needs PoolCounter and proper parser cache check

Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Rest/Handler/PageHTMLHandler.Php. This issue affects MediaWiki: from * before 1.39.14, 1.43.4, 1.44.1.

Affected products

MediaWiki
  • <1.39.14, 1.43.4, 1.44.1

Matching in nixpkgs

Package maintainers

created 5 hours ago
API list=allpages with maxsize is making really slow queries

Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/api/ApiQueryAllPages.Php. This issue affects MediaWiki: from * before 1.39.14, 1.43.4, 1.44.1.

Affected products

MediaWiki
  • <1.39.14, 1.43.4, 1.44.1

Matching in nixpkgs

Package maintainers

created 5 hours ago
Stored XSS through system messages in MW Core

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files resources/src/mediawiki.Action/mediawiki.Action.Edit.Preview.Js, resources/src/mediawiki.Page.Preview.Js. This issue affects MediaWiki: from * before 1.39.14, 1.43.4, 1.44.1.

Affected products

MediaWiki
  • <1.39.14, 1.43.4, 1.44.1

Matching in nixpkgs

Package maintainers