|
1 | 1 | { |
2 | 2 | "vcs_url": "https://github.com/nixos/nixpkgs", |
3 | 3 | "vulnerabilities": { |
| 4 | + "CVE-2026-5160": { |
| 5 | + "ffaf4a61127477ba92c7d83e9194710b1a93dfe4": "goshs: fix CVE-2026-5160\n\nUpdate goldmark to 1.7.17, the first patched version.\n\nhttps://pkg.go.dev/vuln/GO-2026-5320\n\nAssisted-by: pi coding agent / Mika (OpenAI gpt-5.6-sol)" |
| 6 | + }, |
| 7 | + "CVE-2026-32853": { |
| 8 | + "fc61be98dd8db5dcf0092364f9bdd70b501338c2": "[Backport release-26.05] libvncserver: backport CVE-2026-32853 and CVE-2026-32854 fixes (#548487)", |
| 9 | + "4cf468acf47540b7b9848031da17e3f613c50a35": "libvncserver: backport CVE-2026-32853 and CVE-2026-32854 fixes\n\nBackport the complete upstream bounds checks for UltraZip decoding and malformed HTTP proxy requests.\n\nhttps://github.com/LibVNC/libvncserver/security/advisories/GHSA-87q7-v983-qwcj\nhttps://github.com/LibVNC/libvncserver/security/advisories/GHSA-xjp8-4qqv-5x4x\n\nAssisted-by: pi coding agent / Mika (OpenAI gpt-5.6-sol)\n(cherry picked from commit 2cd494ee4e0b6f0b4bb9e7f05df557a0ba06786d)", |
| 10 | + "6e1c1648c76c042338d14316edee68cf38ff8c9e": "libvncserver: backport CVE-2026-32853 and CVE-2026-32854 fixes (#545890)", |
| 11 | + "2cd494ee4e0b6f0b4bb9e7f05df557a0ba06786d": "libvncserver: backport CVE-2026-32853 and CVE-2026-32854 fixes\n\nBackport the complete upstream bounds checks for UltraZip decoding and malformed HTTP proxy requests.\n\nhttps://github.com/LibVNC/libvncserver/security/advisories/GHSA-87q7-v983-qwcj\nhttps://github.com/LibVNC/libvncserver/security/advisories/GHSA-xjp8-4qqv-5x4x\n\nAssisted-by: pi coding agent / Mika (OpenAI gpt-5.6-sol)" |
| 12 | + }, |
| 13 | + "CVE-2026-32854": { |
| 14 | + "fc61be98dd8db5dcf0092364f9bdd70b501338c2": "[Backport release-26.05] libvncserver: backport CVE-2026-32853 and CVE-2026-32854 fixes (#548487)", |
| 15 | + "4cf468acf47540b7b9848031da17e3f613c50a35": "libvncserver: backport CVE-2026-32853 and CVE-2026-32854 fixes\n\nBackport the complete upstream bounds checks for UltraZip decoding and malformed HTTP proxy requests.\n\nhttps://github.com/LibVNC/libvncserver/security/advisories/GHSA-87q7-v983-qwcj\nhttps://github.com/LibVNC/libvncserver/security/advisories/GHSA-xjp8-4qqv-5x4x\n\nAssisted-by: pi coding agent / Mika (OpenAI gpt-5.6-sol)\n(cherry picked from commit 2cd494ee4e0b6f0b4bb9e7f05df557a0ba06786d)", |
| 16 | + "6e1c1648c76c042338d14316edee68cf38ff8c9e": "libvncserver: backport CVE-2026-32853 and CVE-2026-32854 fixes (#545890)", |
| 17 | + "2cd494ee4e0b6f0b4bb9e7f05df557a0ba06786d": "libvncserver: backport CVE-2026-32853 and CVE-2026-32854 fixes\n\nBackport the complete upstream bounds checks for UltraZip decoding and malformed HTTP proxy requests.\n\nhttps://github.com/LibVNC/libvncserver/security/advisories/GHSA-87q7-v983-qwcj\nhttps://github.com/LibVNC/libvncserver/security/advisories/GHSA-xjp8-4qqv-5x4x\n\nAssisted-by: pi coding agent / Mika (OpenAI gpt-5.6-sol)" |
| 18 | + }, |
4 | 19 | "CVE-2026-60074": { |
| 20 | + "efeafb47364537971d3d00dec9da5c1bff1b1a52": "[Backport release-26.05] perlPackages.DateManip: fix CVE-2026-60074 and CVE-2026-60075 (#548464)", |
5 | 21 | "e63e3c448f10ebac24ed508e7878d5b10e4aa9f1": "perlPackages.DateManip: fix CVE-2026-60074 and CVE-2026-60075\n\nApply CPAN Security's complete fixes for rejecting non-ASCII numeric\ndate fields and bounding parser input before expensive regular\nexpressions run.\n\nMove the existing date fallback substitution to postPatch so the\nstandard patch phase applies the security patches first.\n\nAssisted-by: pi coding agent / Mika (OpenAI gpt-5.6-sol)\n(cherry picked from commit 7e09d3726c5850ddb11930780212eb14776e704e)", |
6 | 22 | "6d23509948f9e8cb740f2b018bb9d2ed262f732b": "perlPackages.DateManip: fix CVE-2026-60074 and CVE-2026-60075 (#548409)", |
7 | 23 | "7e09d3726c5850ddb11930780212eb14776e704e": "perlPackages.DateManip: fix CVE-2026-60074 and CVE-2026-60075\n\nApply CPAN Security's complete fixes for rejecting non-ASCII numeric\ndate fields and bounding parser input before expensive regular\nexpressions run.\n\nMove the existing date fallback substitution to postPatch so the\nstandard patch phase applies the security patches first.\n\nAssisted-by: pi coding agent / Mika (OpenAI gpt-5.6-sol)" |
8 | 24 | }, |
9 | 25 | "CVE-2026-60075": { |
| 26 | + "efeafb47364537971d3d00dec9da5c1bff1b1a52": "[Backport release-26.05] perlPackages.DateManip: fix CVE-2026-60074 and CVE-2026-60075 (#548464)", |
10 | 27 | "e63e3c448f10ebac24ed508e7878d5b10e4aa9f1": "perlPackages.DateManip: fix CVE-2026-60074 and CVE-2026-60075\n\nApply CPAN Security's complete fixes for rejecting non-ASCII numeric\ndate fields and bounding parser input before expensive regular\nexpressions run.\n\nMove the existing date fallback substitution to postPatch so the\nstandard patch phase applies the security patches first.\n\nAssisted-by: pi coding agent / Mika (OpenAI gpt-5.6-sol)\n(cherry picked from commit 7e09d3726c5850ddb11930780212eb14776e704e)", |
11 | 28 | "6d23509948f9e8cb740f2b018bb9d2ed262f732b": "perlPackages.DateManip: fix CVE-2026-60074 and CVE-2026-60075 (#548409)", |
12 | 29 | "7e09d3726c5850ddb11930780212eb14776e704e": "perlPackages.DateManip: fix CVE-2026-60074 and CVE-2026-60075\n\nApply CPAN Security's complete fixes for rejecting non-ASCII numeric\ndate fields and bounding parser input before expensive regular\nexpressions run.\n\nMove the existing date fallback substitution to postPatch so the\nstandard patch phase applies the security patches first.\n\nAssisted-by: pi coding agent / Mika (OpenAI gpt-5.6-sol)" |
13 | 30 | }, |
| 31 | + "CVE-2026-1466": { |
| 32 | + "d6fb3e88631c45422b4c5627262241857906cc4a": "jirafeau: 4.4.0 -> 4.7.2\n\nhttps://gitlab.com/jirafeau/Jirafeau/-/blob/4.7.2/CHANGELOG.md\n\nUpdate to the continued official project namespace. This release contains the fix for CVE-2026-1466; extend the NixOS test with the vulnerable preview contract.\n\nAssisted-by: pi coding agent / Mika (OpenAI gpt-5.6-sol)\n(cherry picked from commit 44bfa48ab50ed97c09e4f674dcc755075c573a3f)", |
| 33 | + "44bfa48ab50ed97c09e4f674dcc755075c573a3f": "jirafeau: 4.4.0 -> 4.7.2\n\nhttps://gitlab.com/jirafeau/Jirafeau/-/blob/4.7.2/CHANGELOG.md\n\nUpdate to the continued official project namespace. This release contains the fix for CVE-2026-1466; extend the NixOS test with the vulnerable preview contract.\n\nAssisted-by: pi coding agent / Mika (OpenAI gpt-5.6-sol)" |
| 34 | + }, |
| 35 | + "GHSA-87Q7-V983-QWCJ": { |
| 36 | + "4cf468acf47540b7b9848031da17e3f613c50a35": "libvncserver: backport CVE-2026-32853 and CVE-2026-32854 fixes\n\nBackport the complete upstream bounds checks for UltraZip decoding and malformed HTTP proxy requests.\n\nhttps://github.com/LibVNC/libvncserver/security/advisories/GHSA-87q7-v983-qwcj\nhttps://github.com/LibVNC/libvncserver/security/advisories/GHSA-xjp8-4qqv-5x4x\n\nAssisted-by: pi coding agent / Mika (OpenAI gpt-5.6-sol)\n(cherry picked from commit 2cd494ee4e0b6f0b4bb9e7f05df557a0ba06786d)", |
| 37 | + "2cd494ee4e0b6f0b4bb9e7f05df557a0ba06786d": "libvncserver: backport CVE-2026-32853 and CVE-2026-32854 fixes\n\nBackport the complete upstream bounds checks for UltraZip decoding and malformed HTTP proxy requests.\n\nhttps://github.com/LibVNC/libvncserver/security/advisories/GHSA-87q7-v983-qwcj\nhttps://github.com/LibVNC/libvncserver/security/advisories/GHSA-xjp8-4qqv-5x4x\n\nAssisted-by: pi coding agent / Mika (OpenAI gpt-5.6-sol)" |
| 38 | + }, |
| 39 | + "GHSA-XJP8-4QQV-5X4X": { |
| 40 | + "4cf468acf47540b7b9848031da17e3f613c50a35": "libvncserver: backport CVE-2026-32853 and CVE-2026-32854 fixes\n\nBackport the complete upstream bounds checks for UltraZip decoding and malformed HTTP proxy requests.\n\nhttps://github.com/LibVNC/libvncserver/security/advisories/GHSA-87q7-v983-qwcj\nhttps://github.com/LibVNC/libvncserver/security/advisories/GHSA-xjp8-4qqv-5x4x\n\nAssisted-by: pi coding agent / Mika (OpenAI gpt-5.6-sol)\n(cherry picked from commit 2cd494ee4e0b6f0b4bb9e7f05df557a0ba06786d)", |
| 41 | + "2cd494ee4e0b6f0b4bb9e7f05df557a0ba06786d": "libvncserver: backport CVE-2026-32853 and CVE-2026-32854 fixes\n\nBackport the complete upstream bounds checks for UltraZip decoding and malformed HTTP proxy requests.\n\nhttps://github.com/LibVNC/libvncserver/security/advisories/GHSA-87q7-v983-qwcj\nhttps://github.com/LibVNC/libvncserver/security/advisories/GHSA-xjp8-4qqv-5x4x\n\nAssisted-by: pi coding agent / Mika (OpenAI gpt-5.6-sol)" |
| 42 | + }, |
14 | 43 | "CVE-2026-54387": { |
15 | 44 | "24d8bf6dbc2092d18a27272bc63eefefcb41b496": "[Backport release-26.05] tinyproxy: fix CVE-2026-54387, CVE-2026-54388 and CVE-2026-55202 (#548448)", |
16 | 45 | "dbd6ccb0175da77556187fadcf2d8354a4d50300": "tinyproxy: fix CVE-2026-54387, CVE-2026-54388 and CVE-2026-55202\n\nApply upstream fixes for ambiguous HTTP request framing and inconsistent stathost authentication and routing. No upstream release containing these fixes is available.\n\nAssisted-by: pi coding agent / Mika (OpenAI gpt-5.6-sol)\n(cherry picked from commit 4d53f69eb7681739a0811914d7f47addd6fac7ff)", |
|
33 | 62 | "939d0f3039a001dd0d21e3574c38a78f93ee1032": "kanidm_1_10: 1.10.4 -> 1.10.5\n\nhttps://github.com/kanidm/kanidm/releases/tag/v1.10.5\nhttps://github.com/kanidm/kanidm/security/advisories/GHSA-2pm5-6m23-h692\n\nFixes: GHSA-2pm5-6m23-h692\n(cherry picked from commit 1bb58b274f3d0067bb462b1fb42e8c844f0b4712)", |
34 | 63 | "1bb58b274f3d0067bb462b1fb42e8c844f0b4712": "kanidm_1_10: 1.10.4 -> 1.10.5\n\nhttps://github.com/kanidm/kanidm/releases/tag/v1.10.5\nhttps://github.com/kanidm/kanidm/security/advisories/GHSA-2pm5-6m23-h692\n\nFixes: GHSA-2pm5-6m23-h692" |
35 | 64 | }, |
| 65 | + "CVE-2026-59882": { |
| 66 | + "fb6d49e15e3ce6d36f4f7a942ef5a6a53dca6b44": "freescout: 1.8.230 -> 1.8.232\n\nhttps://github.com/freescout-help-desk/freescout/releases/tag/1.8.231\nhttps://github.com/freescout-help-desk/freescout/releases/tag/1.8.232\n\nFixes: CVE-2026-59882, CVE-2026-45294, CVE-2026-45294" |
| 67 | + }, |
| 68 | + "CVE-2026-45294": { |
| 69 | + "fb6d49e15e3ce6d36f4f7a942ef5a6a53dca6b44": "freescout: 1.8.230 -> 1.8.232\n\nhttps://github.com/freescout-help-desk/freescout/releases/tag/1.8.231\nhttps://github.com/freescout-help-desk/freescout/releases/tag/1.8.232\n\nFixes: CVE-2026-59882, CVE-2026-45294, CVE-2026-45294" |
| 70 | + }, |
| 71 | + "CVE-2026-66066": { |
| 72 | + "b17bb7d10488acdd296d3871816e759d88d54104": "[release-26.05] redmine: Update rails to 7.2.3.2\n\nFixes CVE-2026-66066.\n\nSigned-off-by: Felix Singer <felixsinger@posteo.net>\nNot-cherry-picked-because: master branch has different major version", |
| 73 | + "6f074996277234fff040ef1c10173d16f4cff8a8": "redmine: Update rails to 8.1.3.1\n\nFixes CVE-2026-66066.\n\nSigned-off-by: Felix Singer <felixsinger@posteo.net>", |
| 74 | + "0cf1b4f2c3ebd28764715903b078119e2ab4bc1c": "[26.05] dawarich: bump rails to 8.0.5.1 to fix CVE-2026-66066 (#547197)", |
| 75 | + "c4c92c3a936ea635d841d8ba3d4c3a9910819da9": "dawarich: 1.10.1 -> 1.10.3; fix CVE-2026-66066 (#546764)", |
| 76 | + "000b011aed1091cb8ac05de5d929125f0ac09ae0": "sure: 0.7.1 -> 0.7.2 && patch CVE-2026-66066 (#547318)", |
| 77 | + "4e1ce3ad1f32ef7b37323f882de01e6d4f22fcbf": "[Backport release-26.05] mastodon: patch CVE-2026-66066/GHSA-xr9x-r78c-5hrm in activesupport gem (#547370)", |
| 78 | + "542613d084c6ec5dd159dc7dc8147760274309d9": "mastodon: patch CVE-2026-66066/GHSA-xr9x-r78c-5hrm in activesupport gem\n\n(cherry picked from commit 54c08d3c5b637ab3b342af0012e3473cc97aae6e)", |
| 79 | + "8af8a1099c25904664679efc4a70e1b6ba7691cc": "mastodon: patch CVE-2026-66066/GHSA-xr9x-r78c-5hrm in activesupport gem (#547199)", |
| 80 | + "54c08d3c5b637ab3b342af0012e3473cc97aae6e": "mastodon: patch CVE-2026-66066/GHSA-xr9x-r78c-5hrm in activesupport gem", |
| 81 | + "14e9d479e60563b19205a3700be27228f46c0655": "sure: 0.7.1 -> 0.7.2 && patch CVE-2026-66066", |
| 82 | + "d995cbf84eece5ddcb5a5350b88d083418d0b83e": "dawarich: bump rails to 8.0.5.1 to fix CVE-2026-66066\n\nNot-cherry-picked-because: dawarich on stable is outdated and needs a\ndifferent patch", |
| 83 | + "3f8c8fd95629d1d6b97088680e30776e3615628e": "dawarich: bump rails to 8.1.3.1 to fix CVE-2026-66066" |
| 84 | + }, |
36 | 85 | "CVE-2026-54527": { |
37 | 86 | "9f6090dc2fba89c3f762370bb8d43ee63c6eca66": "[26.05] python3Packages.jupyterlab-git: fix CVE-2026-54527 and CVE-2026-54528 (#547982)", |
38 | 87 | "2b739debfe4694326fbe790e55ae071530f8243c": "python3Packages.jupyterlab-git: fix CVE-2026-54527 and CVE-2026-54528\n\nBackport the upstream fixes to 0.52.0. The master fix updates to\n0.54.0, whose multi-package workspace is not present on release-26.05.\n\nhttps://redirect.github.com/NixOS/nixpkgs/pull/547220\nhttps://redirect.github.com/jupyterlab/jupyterlab-git/commit/c6d37b88f36aa59aee317930b95e427fb9d6b09b\nhttps://redirect.github.com/jupyterlab/jupyterlab-git/commit/460035275b5963dc96e364e60ba6a73717fbd033\n\nAssisted-by: pi coding agent / Mika (OpenAI gpt-5.6-sol)", |
|
87 | 136 | "ab3328fca0bad0c6ab56df9df4ec0eafd2e062cc": "libssh2: patch CVE-2026-58050 and CVE-2026-58051 (#543937)", |
88 | 137 | "572bf8abb5d7a93705ecdf2834f0bd7d675c7e95": "libssh2: patch CVE-2026-58050 and CVE-2026-58051\n\npatch source: https://github.com/libssh2/libssh2/issues/1925#issuecomment-4938515829\n\nFixes: CVE-2026-58050, CVE-2026-58051" |
89 | 138 | }, |
90 | | - "CVE-2026-66066": { |
91 | | - "6f074996277234fff040ef1c10173d16f4cff8a8": "redmine: Update rails to 8.1.3.1\n\nFixes CVE-2026-66066.\n\nSigned-off-by: Felix Singer <felixsinger@posteo.net>", |
92 | | - "0cf1b4f2c3ebd28764715903b078119e2ab4bc1c": "[26.05] dawarich: bump rails to 8.0.5.1 to fix CVE-2026-66066 (#547197)", |
93 | | - "c4c92c3a936ea635d841d8ba3d4c3a9910819da9": "dawarich: 1.10.1 -> 1.10.3; fix CVE-2026-66066 (#546764)", |
94 | | - "000b011aed1091cb8ac05de5d929125f0ac09ae0": "sure: 0.7.1 -> 0.7.2 && patch CVE-2026-66066 (#547318)", |
95 | | - "4e1ce3ad1f32ef7b37323f882de01e6d4f22fcbf": "[Backport release-26.05] mastodon: patch CVE-2026-66066/GHSA-xr9x-r78c-5hrm in activesupport gem (#547370)", |
96 | | - "542613d084c6ec5dd159dc7dc8147760274309d9": "mastodon: patch CVE-2026-66066/GHSA-xr9x-r78c-5hrm in activesupport gem\n\n(cherry picked from commit 54c08d3c5b637ab3b342af0012e3473cc97aae6e)", |
97 | | - "8af8a1099c25904664679efc4a70e1b6ba7691cc": "mastodon: patch CVE-2026-66066/GHSA-xr9x-r78c-5hrm in activesupport gem (#547199)", |
98 | | - "54c08d3c5b637ab3b342af0012e3473cc97aae6e": "mastodon: patch CVE-2026-66066/GHSA-xr9x-r78c-5hrm in activesupport gem", |
99 | | - "14e9d479e60563b19205a3700be27228f46c0655": "sure: 0.7.1 -> 0.7.2 && patch CVE-2026-66066", |
100 | | - "d995cbf84eece5ddcb5a5350b88d083418d0b83e": "dawarich: bump rails to 8.0.5.1 to fix CVE-2026-66066\n\nNot-cherry-picked-because: dawarich on stable is outdated and needs a\ndifferent patch", |
101 | | - "3f8c8fd95629d1d6b97088680e30776e3615628e": "dawarich: bump rails to 8.1.3.1 to fix CVE-2026-66066" |
102 | | - }, |
103 | 139 | "CVE-2026-66063": { |
104 | 140 | "6e046a96da8cdd8e784a50f553d7f8357f3e3a47": "goshs: fix CVE-2026-66063 and CVE-2026-66064 (#547661)", |
105 | 141 | "e55b1ddf6b4b685949a6fc83fa08823ef28523c9": "goshs: fix CVE-2026-66063 and CVE-2026-66064\n\nBackport the upstream fixes for authorization bypasses caused by trailing slashes and multipart upload path traversal.\n\nAssisted-by: pi coding agent / Mika (OpenAI gpt-5.6-sol)" |
|
0 commit comments