|
1 | 1 | { |
2 | 2 | "vcs_url": "https://github.com/nixos/nixpkgs", |
3 | 3 | "vulnerabilities": { |
4 | | - "GHSA-VCC4-2C75-VC9V": { |
5 | | - "96d8886cd7065323c5c85179e1a0bf3226452f7f": "caddy: 2.11.3 -> 2.11.4\n\nhttps://github.com/caddyserver/caddy/releases/tag/v2.11.4\n\nFixes: GHSA-vcc4-2c75-vc9v (https://github.com/caddyserver/caddy/pull/7785)\n(cherry picked from commit e7e7984e947e6f41ceae21727cd74aa5fa269648)", |
6 | | - "27259aeb2271c8301a741c7c0aeaff6ab15aff1a": "caddy: 2.11.3 -> 2.11.4\n\nhttps://github.com/caddyserver/caddy/releases/tag/v2.11.4\n\nFixes: GHSA-vcc4-2c75-vc9v (https://github.com/caddyserver/caddy/pull/7785)\n(cherry picked from commit e7e7984e947e6f41ceae21727cd74aa5fa269648)", |
7 | | - "e7e7984e947e6f41ceae21727cd74aa5fa269648": "caddy: 2.11.3 -> 2.11.4\n\nhttps://github.com/caddyserver/caddy/releases/tag/v2.11.4\n\nFixes: GHSA-vcc4-2c75-vc9v (https://github.com/caddyserver/caddy/pull/7785)" |
8 | | - }, |
9 | 4 | "CVE-2026-6873": { |
| 5 | + "ac986b65d9eff37f2168d2817564780263e27337": "python3Packages.django_6: 6.0.5 -> 6.0.6\n\nhttps://docs.djangoproject.com/en/6.0/releases/6.0.6/\nhttps://www.djangoproject.com/weblog/2026/jun/03/security-releases/\n\nFixes:\nCVE-2026-6873, CVE-2026-7666, CVE-2026-8404, CVE-2026-35193,\nCVE-2026-48587\n\n(cherry picked from commit 2dc12f9e904942f8f5ef9baf5263caddf40f347a)", |
10 | 6 | "32ff989879ca372003d44ee8421d81f3353c8ac0": "python3Packages.django_5: 5.2.14 -> 5.2.15\n\nhttps://docs.djangoproject.com/en/5.2/releases/5.2.15/\nhttps://www.djangoproject.com/weblog/2026/jun/03/security-releases/\n\nFixes:\nCVE-2026-6873, CVE-2026-7666, CVE-2026-8404, CVE-2026-35193,\nCVE-2026-48587\n\n(cherry picked from commit 3b5d44bff532312e311282d9768c5204fc8d601a)", |
11 | 7 | "3b5d44bff532312e311282d9768c5204fc8d601a": "python3Packages.django_5: 5.2.14 -> 5.2.15\n\nhttps://docs.djangoproject.com/en/5.2/releases/5.2.15/\nhttps://www.djangoproject.com/weblog/2026/jun/03/security-releases/\n\nFixes:\nCVE-2026-6873, CVE-2026-7666, CVE-2026-8404, CVE-2026-35193,\nCVE-2026-48587", |
12 | 8 | "2dc12f9e904942f8f5ef9baf5263caddf40f347a": "python3Packages.django_6: 6.0.5 -> 6.0.6\n\nhttps://docs.djangoproject.com/en/6.0/releases/6.0.6/\nhttps://www.djangoproject.com/weblog/2026/jun/03/security-releases/\n\nFixes:\nCVE-2026-6873, CVE-2026-7666, CVE-2026-8404, CVE-2026-35193,\nCVE-2026-48587" |
13 | 9 | }, |
14 | 10 | "CVE-2026-7666": { |
| 11 | + "ac986b65d9eff37f2168d2817564780263e27337": "python3Packages.django_6: 6.0.5 -> 6.0.6\n\nhttps://docs.djangoproject.com/en/6.0/releases/6.0.6/\nhttps://www.djangoproject.com/weblog/2026/jun/03/security-releases/\n\nFixes:\nCVE-2026-6873, CVE-2026-7666, CVE-2026-8404, CVE-2026-35193,\nCVE-2026-48587\n\n(cherry picked from commit 2dc12f9e904942f8f5ef9baf5263caddf40f347a)", |
15 | 12 | "32ff989879ca372003d44ee8421d81f3353c8ac0": "python3Packages.django_5: 5.2.14 -> 5.2.15\n\nhttps://docs.djangoproject.com/en/5.2/releases/5.2.15/\nhttps://www.djangoproject.com/weblog/2026/jun/03/security-releases/\n\nFixes:\nCVE-2026-6873, CVE-2026-7666, CVE-2026-8404, CVE-2026-35193,\nCVE-2026-48587\n\n(cherry picked from commit 3b5d44bff532312e311282d9768c5204fc8d601a)", |
16 | 13 | "3b5d44bff532312e311282d9768c5204fc8d601a": "python3Packages.django_5: 5.2.14 -> 5.2.15\n\nhttps://docs.djangoproject.com/en/5.2/releases/5.2.15/\nhttps://www.djangoproject.com/weblog/2026/jun/03/security-releases/\n\nFixes:\nCVE-2026-6873, CVE-2026-7666, CVE-2026-8404, CVE-2026-35193,\nCVE-2026-48587", |
17 | 14 | "2dc12f9e904942f8f5ef9baf5263caddf40f347a": "python3Packages.django_6: 6.0.5 -> 6.0.6\n\nhttps://docs.djangoproject.com/en/6.0/releases/6.0.6/\nhttps://www.djangoproject.com/weblog/2026/jun/03/security-releases/\n\nFixes:\nCVE-2026-6873, CVE-2026-7666, CVE-2026-8404, CVE-2026-35193,\nCVE-2026-48587" |
18 | 15 | }, |
19 | 16 | "CVE-2026-8404": { |
| 17 | + "ac986b65d9eff37f2168d2817564780263e27337": "python3Packages.django_6: 6.0.5 -> 6.0.6\n\nhttps://docs.djangoproject.com/en/6.0/releases/6.0.6/\nhttps://www.djangoproject.com/weblog/2026/jun/03/security-releases/\n\nFixes:\nCVE-2026-6873, CVE-2026-7666, CVE-2026-8404, CVE-2026-35193,\nCVE-2026-48587\n\n(cherry picked from commit 2dc12f9e904942f8f5ef9baf5263caddf40f347a)", |
20 | 18 | "32ff989879ca372003d44ee8421d81f3353c8ac0": "python3Packages.django_5: 5.2.14 -> 5.2.15\n\nhttps://docs.djangoproject.com/en/5.2/releases/5.2.15/\nhttps://www.djangoproject.com/weblog/2026/jun/03/security-releases/\n\nFixes:\nCVE-2026-6873, CVE-2026-7666, CVE-2026-8404, CVE-2026-35193,\nCVE-2026-48587\n\n(cherry picked from commit 3b5d44bff532312e311282d9768c5204fc8d601a)", |
21 | 19 | "3b5d44bff532312e311282d9768c5204fc8d601a": "python3Packages.django_5: 5.2.14 -> 5.2.15\n\nhttps://docs.djangoproject.com/en/5.2/releases/5.2.15/\nhttps://www.djangoproject.com/weblog/2026/jun/03/security-releases/\n\nFixes:\nCVE-2026-6873, CVE-2026-7666, CVE-2026-8404, CVE-2026-35193,\nCVE-2026-48587", |
22 | 20 | "2dc12f9e904942f8f5ef9baf5263caddf40f347a": "python3Packages.django_6: 6.0.5 -> 6.0.6\n\nhttps://docs.djangoproject.com/en/6.0/releases/6.0.6/\nhttps://www.djangoproject.com/weblog/2026/jun/03/security-releases/\n\nFixes:\nCVE-2026-6873, CVE-2026-7666, CVE-2026-8404, CVE-2026-35193,\nCVE-2026-48587" |
23 | 21 | }, |
24 | 22 | "CVE-2026-35193": { |
| 23 | + "ac986b65d9eff37f2168d2817564780263e27337": "python3Packages.django_6: 6.0.5 -> 6.0.6\n\nhttps://docs.djangoproject.com/en/6.0/releases/6.0.6/\nhttps://www.djangoproject.com/weblog/2026/jun/03/security-releases/\n\nFixes:\nCVE-2026-6873, CVE-2026-7666, CVE-2026-8404, CVE-2026-35193,\nCVE-2026-48587\n\n(cherry picked from commit 2dc12f9e904942f8f5ef9baf5263caddf40f347a)", |
25 | 24 | "32ff989879ca372003d44ee8421d81f3353c8ac0": "python3Packages.django_5: 5.2.14 -> 5.2.15\n\nhttps://docs.djangoproject.com/en/5.2/releases/5.2.15/\nhttps://www.djangoproject.com/weblog/2026/jun/03/security-releases/\n\nFixes:\nCVE-2026-6873, CVE-2026-7666, CVE-2026-8404, CVE-2026-35193,\nCVE-2026-48587\n\n(cherry picked from commit 3b5d44bff532312e311282d9768c5204fc8d601a)", |
26 | 25 | "3b5d44bff532312e311282d9768c5204fc8d601a": "python3Packages.django_5: 5.2.14 -> 5.2.15\n\nhttps://docs.djangoproject.com/en/5.2/releases/5.2.15/\nhttps://www.djangoproject.com/weblog/2026/jun/03/security-releases/\n\nFixes:\nCVE-2026-6873, CVE-2026-7666, CVE-2026-8404, CVE-2026-35193,\nCVE-2026-48587", |
27 | 26 | "2dc12f9e904942f8f5ef9baf5263caddf40f347a": "python3Packages.django_6: 6.0.5 -> 6.0.6\n\nhttps://docs.djangoproject.com/en/6.0/releases/6.0.6/\nhttps://www.djangoproject.com/weblog/2026/jun/03/security-releases/\n\nFixes:\nCVE-2026-6873, CVE-2026-7666, CVE-2026-8404, CVE-2026-35193,\nCVE-2026-48587" |
28 | 27 | }, |
29 | 28 | "CVE-2026-48587": { |
| 29 | + "ac986b65d9eff37f2168d2817564780263e27337": "python3Packages.django_6: 6.0.5 -> 6.0.6\n\nhttps://docs.djangoproject.com/en/6.0/releases/6.0.6/\nhttps://www.djangoproject.com/weblog/2026/jun/03/security-releases/\n\nFixes:\nCVE-2026-6873, CVE-2026-7666, CVE-2026-8404, CVE-2026-35193,\nCVE-2026-48587\n\n(cherry picked from commit 2dc12f9e904942f8f5ef9baf5263caddf40f347a)", |
30 | 30 | "32ff989879ca372003d44ee8421d81f3353c8ac0": "python3Packages.django_5: 5.2.14 -> 5.2.15\n\nhttps://docs.djangoproject.com/en/5.2/releases/5.2.15/\nhttps://www.djangoproject.com/weblog/2026/jun/03/security-releases/\n\nFixes:\nCVE-2026-6873, CVE-2026-7666, CVE-2026-8404, CVE-2026-35193,\nCVE-2026-48587\n\n(cherry picked from commit 3b5d44bff532312e311282d9768c5204fc8d601a)", |
31 | 31 | "3b5d44bff532312e311282d9768c5204fc8d601a": "python3Packages.django_5: 5.2.14 -> 5.2.15\n\nhttps://docs.djangoproject.com/en/5.2/releases/5.2.15/\nhttps://www.djangoproject.com/weblog/2026/jun/03/security-releases/\n\nFixes:\nCVE-2026-6873, CVE-2026-7666, CVE-2026-8404, CVE-2026-35193,\nCVE-2026-48587", |
32 | 32 | "2dc12f9e904942f8f5ef9baf5263caddf40f347a": "python3Packages.django_6: 6.0.5 -> 6.0.6\n\nhttps://docs.djangoproject.com/en/6.0/releases/6.0.6/\nhttps://www.djangoproject.com/weblog/2026/jun/03/security-releases/\n\nFixes:\nCVE-2026-6873, CVE-2026-7666, CVE-2026-8404, CVE-2026-35193,\nCVE-2026-48587" |
33 | 33 | }, |
| 34 | + "GHSA-VCC4-2C75-VC9V": { |
| 35 | + "96d8886cd7065323c5c85179e1a0bf3226452f7f": "caddy: 2.11.3 -> 2.11.4\n\nhttps://github.com/caddyserver/caddy/releases/tag/v2.11.4\n\nFixes: GHSA-vcc4-2c75-vc9v (https://github.com/caddyserver/caddy/pull/7785)\n(cherry picked from commit e7e7984e947e6f41ceae21727cd74aa5fa269648)", |
| 36 | + "27259aeb2271c8301a741c7c0aeaff6ab15aff1a": "caddy: 2.11.3 -> 2.11.4\n\nhttps://github.com/caddyserver/caddy/releases/tag/v2.11.4\n\nFixes: GHSA-vcc4-2c75-vc9v (https://github.com/caddyserver/caddy/pull/7785)\n(cherry picked from commit e7e7984e947e6f41ceae21727cd74aa5fa269648)", |
| 37 | + "e7e7984e947e6f41ceae21727cd74aa5fa269648": "caddy: 2.11.3 -> 2.11.4\n\nhttps://github.com/caddyserver/caddy/releases/tag/v2.11.4\n\nFixes: GHSA-vcc4-2c75-vc9v (https://github.com/caddyserver/caddy/pull/7785)" |
| 38 | + }, |
34 | 39 | "CVE-2026-28847": { |
35 | 40 | "79ac2b3e244b7ceb5bb9f31366a2f91158361b3a": "webkitgtk_6_0: 2.52.3 \u2192 2.52.4\n\nhttps://github.com/WebKit/WebKit/compare/webkitgtk-2.52.3...webkitgtk-2.52.4\nhttps://webkitgtk.org/2026/06/02/webkitgtk2.52.4-released.html\nhttps://webkitgtk.org/security/WSA-2026-0003.html\n\nCVE-2026-28847, CVE-2026-28883, CVE-2026-28901, CVE-2026-28902, CVE-2026-28903,\nCVE-2026-28904, CVE-2026-28905, CVE-2026-28907, CVE-2026-28942, CVE-2026-28946,\nCVE-2026-28947, CVE-2026-28953, CVE-2026-28955, CVE-2026-28958, CVE-2026-43658,\nCVE-2026-43660\n\n(cherry picked from commit f66b70ac403fce30d6276cdb376dc27c3ed96f12)", |
36 | 41 | "70becd4ad8b7d24e8da20b492103659858660ddb": "webkitgtk_6_0: 2.52.3 \u2192 2.52.4\n\nhttps://github.com/WebKit/WebKit/compare/webkitgtk-2.52.3...webkitgtk-2.52.4\nhttps://webkitgtk.org/2026/06/02/webkitgtk2.52.4-released.html\nhttps://webkitgtk.org/security/WSA-2026-0003.html\n\nCVE-2026-28847, CVE-2026-28883, CVE-2026-28901, CVE-2026-28902, CVE-2026-28903,\nCVE-2026-28904, CVE-2026-28905, CVE-2026-28907, CVE-2026-28942, CVE-2026-28946,\nCVE-2026-28947, CVE-2026-28953, CVE-2026-28955, CVE-2026-28958, CVE-2026-43658,\nCVE-2026-43660\n\n(cherry picked from commit f66b70ac403fce30d6276cdb376dc27c3ed96f12)", |
|
0 commit comments