Nixpkgs
NixOS · 6 CVEs
CVE-2026-61828
HIGH
nixos/mysql : `services.mysql` is configured with insecure authentication by default when used with `mysql` or `percona…
Jul 15, 2026
CVE-2026-25740
MEDIUM
Privilege escalation to the `CAP_NET_RAW` capability via the `programs.captive-browser` NixOS module
Feb 9, 2026
CVE-2026-25137
CRITICAL
NixOs Odoo database and filestore publicly accessible with default odoo configuration
Feb 2, 2026
CVE-2026-23838
HIGH
Tandoor Recipes module allows SQLite database to be externally accessible with the default settings
Jan 19, 2026
CVE-2025-64766
MEDIUM
NixOS has hardcoded credentials in Onlyoffice module
Nov 17, 2025
CVE-2025-32438
HIGH
Local privilege escalation in make-initrd-ng
Apr 15, 2025
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-61828 | nixos/mysql : `services.mysql` is configured with insecure authentication by default when used with `mysql` or `percona-server` | HIGH | 0.15% | Jul 15, 2026 |
| CVE-2026-25740 | Privilege escalation to the `CAP_NET_RAW` capability via the `programs.captive-browser` NixOS module | MEDIUM | 0.17% | Feb 9, 2026 |
| CVE-2026-25137 | NixOs Odoo database and filestore publicly accessible with default odoo configuration | CRITICAL | 10.48% | Feb 2, 2026 |
| CVE-2026-23838 | Tandoor Recipes module allows SQLite database to be externally accessible with the default settings | HIGH | 0.52% | Jan 19, 2026 |
| CVE-2025-64766 | NixOS has hardcoded credentials in Onlyoffice module | MEDIUM | 0.28% | Nov 17, 2025 |
| CVE-2025-32438 | Local privilege escalation in make-initrd-ng | HIGH | 0.19% | Apr 15, 2025 |
Showing 1 to 6 of 6 CVEs