CVE-2025-30596 6.5 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): NONE Availability impact (A): NONE updated 8 months, 1 week ago by @LeSuisse Activity log Created automatic suggestion 8 months, 1 week ago @LeSuisse dismissed 8 months, 1 week ago WordPress include-file <= 1 - Arbitrary File Download Vulnerability Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in NotFound include-file allows Path Traversal. This issue affects include-file: from n/a through 1. Affected products include-file =<1 Matching in nixpkgs pkgs.haskellPackages.include-file Inclusion of files in executables at compile-time nixos-unstable 0.1.0.4 nixos-unstable-small 0.1.0.4 nixpkgs-unstable 0.1.0.4 pkgs.haskellPackages.include-file.x86_64-linux Inclusion of files in executables at compile-time nixos-unstable ??? nixpkgs-unstable 0.1.0.4 pkgs.haskellPackages.include-file.aarch64-linux Inclusion of files in executables at compile-time nixos-unstable ??? nixpkgs-unstable 0.1.0.4 pkgs.haskellPackages.include-file.x86_64-darwin Inclusion of files in executables at compile-time nixos-unstable ??? nixpkgs-unstable 0.1.0.4 pkgs.haskellPackages.include-file.aarch64-darwin Inclusion of files in executables at compile-time nixos-unstable ??? nixpkgs-unstable 0.1.0.4
pkgs.haskellPackages.include-file Inclusion of files in executables at compile-time nixos-unstable 0.1.0.4 nixos-unstable-small 0.1.0.4 nixpkgs-unstable 0.1.0.4
pkgs.haskellPackages.include-file.x86_64-linux Inclusion of files in executables at compile-time nixos-unstable ??? nixpkgs-unstable 0.1.0.4
pkgs.haskellPackages.include-file.aarch64-linux Inclusion of files in executables at compile-time nixos-unstable ??? nixpkgs-unstable 0.1.0.4
pkgs.haskellPackages.include-file.x86_64-darwin Inclusion of files in executables at compile-time nixos-unstable ??? nixpkgs-unstable 0.1.0.4
pkgs.haskellPackages.include-file.aarch64-darwin Inclusion of files in executables at compile-time nixos-unstable ??? nixpkgs-unstable 0.1.0.4
CVE-2025-32250 5.4 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): LOW Availability impact (A): LOW updated 8 months, 1 week ago by @LeSuisse Activity log Created automatic suggestion 8 months, 1 week ago @LeSuisse dismissed 8 months, 1 week ago WordPress Rollbar plugin <= 2.7.1 - Cross Site Request Forgery (CSRF) vulnerability Cross-Site Request Forgery (CSRF) vulnerability in rollbar Rollbar allows Cross Site Request Forgery. This issue affects Rollbar: from n/a through 2.7.1. Affected products rollbar =<2.7.1 Matching in nixpkgs pkgs.haskellPackages.rollbar error tracking through rollbar.com nixos-unstable 1.1.3 nixos-unstable-small 1.1.3 nixpkgs-unstable 1.1.3 pkgs.python311Packages.rollbar Error tracking and logging from Python to Rollbar nixos-unstable 1.0.0 nixos-unstable-small 1.0.0 nixpkgs-unstable 1.0.0 pkgs.python312Packages.rollbar Error tracking and logging from Python to Rollbar nixos-unstable 1.0.0 nixos-unstable-small 1.0.0 nixpkgs-unstable 1.0.0 pkgs.vimPlugins.nvim-scrollbar nixos-unstable 2024-10-17 nixos-unstable-small 2024-10-17 nixpkgs-unstable 2024-10-17 pkgs.vimPlugins.scrollbar-nvim nixos-unstable 2024-11-28 nixos-unstable-small 2024-11-28 nixpkgs-unstable 2024-11-28 pkgs.python312Packages.rollbar.x86_64-linux Error tracking and logging from Python to Rollbar nixos-unstable 1.0.0 pkgs.python312Packages.rollbar.aarch64-linux Error tracking and logging from Python to Rollbar nixos-unstable 1.0.0 pkgs.python312Packages.rollbar.x86_64-darwin Error tracking and logging from Python to Rollbar nixos-unstable 1.0.0 pkgs.python312Packages.rollbar.aarch64-darwin Error tracking and logging from Python to Rollbar nixos-unstable 1.0.0
pkgs.haskellPackages.rollbar error tracking through rollbar.com nixos-unstable 1.1.3 nixos-unstable-small 1.1.3 nixpkgs-unstable 1.1.3
pkgs.python311Packages.rollbar Error tracking and logging from Python to Rollbar nixos-unstable 1.0.0 nixos-unstable-small 1.0.0 nixpkgs-unstable 1.0.0
pkgs.python312Packages.rollbar Error tracking and logging from Python to Rollbar nixos-unstable 1.0.0 nixos-unstable-small 1.0.0 nixpkgs-unstable 1.0.0
pkgs.vimPlugins.nvim-scrollbar nixos-unstable 2024-10-17 nixos-unstable-small 2024-10-17 nixpkgs-unstable 2024-10-17
pkgs.vimPlugins.scrollbar-nvim nixos-unstable 2024-11-28 nixos-unstable-small 2024-11-28 nixpkgs-unstable 2024-11-28
pkgs.python312Packages.rollbar.x86_64-linux Error tracking and logging from Python to Rollbar nixos-unstable 1.0.0
pkgs.python312Packages.rollbar.aarch64-linux Error tracking and logging from Python to Rollbar nixos-unstable 1.0.0
pkgs.python312Packages.rollbar.x86_64-darwin Error tracking and logging from Python to Rollbar nixos-unstable 1.0.0
pkgs.python312Packages.rollbar.aarch64-darwin Error tracking and logging from Python to Rollbar nixos-unstable 1.0.0
CVE-2025-32272 4.3 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): LOW Availability impact (A): NONE updated 8 months, 1 week ago by @LeSuisse Activity log Created automatic suggestion 8 months, 1 week ago @LeSuisse dismissed 8 months, 1 week ago WordPress Wishlist Plugin <= 1.0.44 - Cross Site Request Forgery (CSRF) vulnerability Cross-Site Request Forgery (CSRF) vulnerability in PickPlugins Wishlist allows Cross Site Request Forgery. This issue affects Wishlist: from n/a through 1.0.44. Affected products wishlist =<1.0.44 Matching in nixpkgs pkgs.wishlist Single entrypoint for multiple SSH endpoints nixos-unstable 0.15.0 nixos-unstable-small 0.15.0 nixpkgs-unstable 0.15.0 Package maintainers: 2 @caarlos0 Carlos A Becker <carlos@becker.software> @penguwin Nicolas Martin <penguwin@penguwin.eu>
pkgs.wishlist Single entrypoint for multiple SSH endpoints nixos-unstable 0.15.0 nixos-unstable-small 0.15.0 nixpkgs-unstable 0.15.0
CVE-2025-31407 6.5 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): REQUIRED Scope (S): CHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW updated 8 months, 1 week ago by @LeSuisse Activity log Created automatic suggestion 8 months, 1 week ago @LeSuisse dismissed 8 months, 1 week ago WordPress Tiger theme <= 2.0 - Cross Site Scripting (XSS) vulnerability Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hutsixdigital Tiger allows Stored XSS.This issue affects Tiger: from n/a through 2.0. Affected products tiger =<2.0 Matching in nixpkgs pkgs.libtiger Rendering library for Kate streams using Pango and Cairo nixos-unstable 0.3.4 nixos-unstable-small 0.3.4 nixpkgs-unstable 0.3.4 pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-unstable 1.14.0 nixos-unstable-small 1.14.0 nixpkgs-unstable 1.14.0 pkgs.wiredtiger nixos-unstable 3.2.1 nixos-unstable-small 3.2.1 nixpkgs-unstable 3.2.1 pkgs.tigerbeetle Financial accounting database designed to be distributed and fast nixos-unstable 0.16.14 nixos-unstable-small 0.16.14 nixpkgs-unstable 0.16.14 pkgs.tigerjython Simple development environment for programming in Python nixos-unstable 2.39 nixos-unstable-small 2.39 nixpkgs-unstable 2.39 pkgs.libtiger.x86_64-linux Rendering library for Kate streams using Pango and Cairo nixos-unstable ??? nixos-unstable-small 0.3.4 pkgs.libtiger.aarch64-linux Rendering library for Kate streams using Pango and Cairo nixos-unstable ??? nixos-unstable-small 0.3.4 pkgs.libtiger.x86_64-darwin Rendering library for Kate streams using Pango and Cairo nixos-unstable ??? nixos-unstable-small 0.3.4 pkgs.libtiger.aarch64-darwin Rendering library for Kate streams using Pango and Cairo nixos-unstable ??? nixos-unstable-small 0.3.4 pkgs.tree-sitter-grammars.tree-sitter-tiger nixos-unstable 0.24.3 nixos-unstable-small 0.24.3 nixpkgs-unstable 0.24.3 pkgs.chickenPackages_5.chickenEggs.tiger-hash Tiger/192 Message Digest nixos-unstable 4.1.2 nixos-unstable-small 4.1.2 nixpkgs-unstable 4.1.2 pkgs.vimPlugins.nvim-treesitter-parsers.tiger nixos-unstable ??? nixos-unstable-small nixpkgs-unstable Package maintainers: 4 @matthewbauer Matthew Bauer <mjbauer95@gmail.com> @nwjsmith Nate Smith <nate@theinternate.com> @DanielSidhion Daniel Sidhion <nixpkgs@sidhion.com> @rcmlz rcmlz <haguga-nixos@yahoo.com>
pkgs.libtiger Rendering library for Kate streams using Pango and Cairo nixos-unstable 0.3.4 nixos-unstable-small 0.3.4 nixpkgs-unstable 0.3.4
pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-unstable 1.14.0 nixos-unstable-small 1.14.0 nixpkgs-unstable 1.14.0
pkgs.tigerbeetle Financial accounting database designed to be distributed and fast nixos-unstable 0.16.14 nixos-unstable-small 0.16.14 nixpkgs-unstable 0.16.14
pkgs.tigerjython Simple development environment for programming in Python nixos-unstable 2.39 nixos-unstable-small 2.39 nixpkgs-unstable 2.39
pkgs.libtiger.x86_64-linux Rendering library for Kate streams using Pango and Cairo nixos-unstable ??? nixos-unstable-small 0.3.4
pkgs.libtiger.aarch64-linux Rendering library for Kate streams using Pango and Cairo nixos-unstable ??? nixos-unstable-small 0.3.4
pkgs.libtiger.x86_64-darwin Rendering library for Kate streams using Pango and Cairo nixos-unstable ??? nixos-unstable-small 0.3.4
pkgs.libtiger.aarch64-darwin Rendering library for Kate streams using Pango and Cairo nixos-unstable ??? nixos-unstable-small 0.3.4
pkgs.tree-sitter-grammars.tree-sitter-tiger nixos-unstable 0.24.3 nixos-unstable-small 0.24.3 nixpkgs-unstable 0.24.3
pkgs.chickenPackages_5.chickenEggs.tiger-hash Tiger/192 Message Digest nixos-unstable 4.1.2 nixos-unstable-small 4.1.2 nixpkgs-unstable 4.1.2
pkgs.vimPlugins.nvim-treesitter-parsers.tiger nixos-unstable ??? nixos-unstable-small nixpkgs-unstable
CVE-2023-26302 3.3 LOW CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): LOW updated 8 months, 4 weeks ago by @LeSuisse Activity log Created automatic suggestion 9 months ago @LeSuisse dismissed 8 months, 4 weeks ago markdown-it-py CLI crash on invalid UTF-8 characters Denial of service could be caused to the command line interface of markdown-it-py, before v2.2.0, if an attacker was allowed to use invalid UTF-8 characters as input. Affected products markdown-it-py <v2.2.0 Matching in nixpkgs pkgs.python311Packages.markdown-it-py Markdown parser in Python nixos-unstable 3.0.0 nixos-unstable-small 3.0.0 nixpkgs-unstable 3.0.0 pkgs.python312Packages.markdown-it-py Markdown parser in Python nixos-unstable 3.0.0 nixos-unstable-small 3.0.0 nixpkgs-unstable 3.0.0 pkgs.python312Packages.markdown-it-py.x86_64-linux Markdown parser in Python nixos-unstable 3.0.0 pkgs.python312Packages.markdown-it-py.aarch64-linux Markdown parser in Python nixos-unstable 3.0.0 pkgs.python312Packages.markdown-it-py.x86_64-darwin Markdown parser in Python nixos-unstable 3.0.0 pkgs.python312Packages.markdown-it-py.aarch64-darwin Markdown parser in Python nixos-unstable 3.0.0 Package maintainers: 1 @bhipple Benjamin Hipple <bhipple@protonmail.com>
pkgs.python311Packages.markdown-it-py Markdown parser in Python nixos-unstable 3.0.0 nixos-unstable-small 3.0.0 nixpkgs-unstable 3.0.0
pkgs.python312Packages.markdown-it-py Markdown parser in Python nixos-unstable 3.0.0 nixos-unstable-small 3.0.0 nixpkgs-unstable 3.0.0
CVE-2023-26303 3.3 LOW CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): LOW updated 8 months, 4 weeks ago by @LeSuisse Activity log Created automatic suggestion 9 months ago @LeSuisse dismissed 8 months, 4 weeks ago markdown-it-py crash on null assertions Denial of service could be caused to markdown-it-py, before v2.2.0, if an attacker was allowed to force null assertions with specially crafted input. Affected products markdown-it-py <v2.2.0 Matching in nixpkgs pkgs.python311Packages.markdown-it-py Markdown parser in Python nixos-unstable 3.0.0 nixos-unstable-small 3.0.0 nixpkgs-unstable 3.0.0 pkgs.python312Packages.markdown-it-py Markdown parser in Python nixos-unstable 3.0.0 nixos-unstable-small 3.0.0 nixpkgs-unstable 3.0.0 pkgs.python312Packages.markdown-it-py.x86_64-linux Markdown parser in Python nixos-unstable 3.0.0 pkgs.python312Packages.markdown-it-py.aarch64-linux Markdown parser in Python nixos-unstable 3.0.0 pkgs.python312Packages.markdown-it-py.x86_64-darwin Markdown parser in Python nixos-unstable 3.0.0 pkgs.python312Packages.markdown-it-py.aarch64-darwin Markdown parser in Python nixos-unstable 3.0.0 Package maintainers: 1 @bhipple Benjamin Hipple <bhipple@protonmail.com>
pkgs.python311Packages.markdown-it-py Markdown parser in Python nixos-unstable 3.0.0 nixos-unstable-small 3.0.0 nixpkgs-unstable 3.0.0
pkgs.python312Packages.markdown-it-py Markdown parser in Python nixos-unstable 3.0.0 nixos-unstable-small 3.0.0 nixpkgs-unstable 3.0.0
CVE-2023-1314 7.5 HIGH CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): HIGH Privileges required (PR): LOW User interaction (UI): NONE Scope (S): CHANGED Confidentiality impact (C): NONE Integrity impact (I): HIGH Availability impact (A): HIGH updated 9 months ago by @LeSuisse Activity log Created automatic suggestion 9 months, 2 weeks ago @LeSuisse dismissed 9 months ago Local Privilege Escalation Vulnerability in cloudflared's Installer A vulnerability has been discovered in cloudflared's installer (<= 2023.3.0) for Windows 32-bits devices that allows a local attacker with no administrative permissions to escalate their privileges on the affected device. This vulnerability exists because the MSI installer used by cloudflared relied on a world-writable directory. An attacker with local access to the device (without Administrator rights) can use symbolic links to trick the MSI installer into deleting files in locations that the attacker would otherwise have no access to. By creating a symlink from the world-writable directory to the target file, the attacker can manipulate the MSI installer's repair functionality to delete the target file during the repair process. Exploitation of this vulnerability could allow an attacker to delete important system files or replace them with malicious files, potentially leading to the affected device being compromised. The cloudflared client itself is not affected by this vulnerability, only the installer for 32-bit Windows devices. Affected products cloudflared =<<=2023.3.0 Matching in nixpkgs pkgs.cloudflared Cloudflare Tunnel daemon, Cloudflare Access toolkit, and DNS-over-HTTPS client nixos-unstable 2024.11.0 nixos-unstable-small 2024.11.0 nixpkgs-unstable 2024.11.0 Package maintainers: 5 @piperswe Piper McCorkle <contact@piperswe.me> @ericnorris Eric Norris <erictnorris@gmail.com> @bbigras Bruno Bigras <bigras.bruno@gmail.com> @qjoly Quentin JOLY <github@une-pause-cafe.fr> @thoughtpolice Austin Seipp <aseipp@pobox.com>
pkgs.cloudflared Cloudflare Tunnel daemon, Cloudflare Access toolkit, and DNS-over-HTTPS client nixos-unstable 2024.11.0 nixos-unstable-small 2024.11.0 nixpkgs-unstable 2024.11.0
CVE-2023-46288 updated 9 months, 3 weeks ago by @fpletz Activity log Created automatic suggestion 10 months ago @fpletz dismissed 9 months, 3 weeks ago Apache Airflow: Sensitive parameters exposed in API when "non-sensitive-only" configuration is set Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Airflow.This issue affects Apache Airflow from 2.4.0 to 2.7.0. Sensitive configuration information has been exposed to authenticated users with the ability to read configuration via Airflow REST API for configuration even when the expose_config option is set to non-sensitive-only. The expose_config option is False by default. It is recommended to upgrade to a version that is not affected if you set expose_config to non-sensitive-only configuration. This is a different error than CVE-2023-45348 which allows authenticated user to retrieve individual configuration values in 2.7.* by specially crafting their request (solved in 2.7.2). Users are recommended to upgrade to version 2.7.2, which fixes the issue and additionally fixes CVE-2023-45348. Affected products apache-airflow <2.7.0 Matching in nixpkgs pkgs.apache-airflow Programmatically author, schedule and monitor data pipelines nixos-unstable 2.7.3 nixos-unstable-small 2.7.3 nixpkgs-unstable 2.7.3 Package maintainers: 3 @bhipple Benjamin Hipple <bhipple@protonmail.com> @gbpdt Graham Bennett <nix@pdtpartners.com> @ingenieroariel Ariel Nunez <ariel@nunez.co>
pkgs.apache-airflow Programmatically author, schedule and monitor data pipelines nixos-unstable 2.7.3 nixos-unstable-small 2.7.3 nixpkgs-unstable 2.7.3
CVE-2023-1999 5.3 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): NONE Availability impact (A): NONE updated 9 months, 3 weeks ago by @fpletz Activity log Created automatic suggestion 10 months ago @fpletz dismissed 9 months, 3 weeks ago Use after free in libwebp There exists a use after free/double free in libwebp. An attacker can use the ApplyFiltersAndEncode() function and loop through to free best.bw and assign best = trial pointer. The second loop will then return 0 because of an Out of memory error in VP8 encoder, the pointer is still assigned to trial and the AddressSanitizer will attempt a double free. Affected products libwebp <1.3.1 <1.3.0-8-ga486d800 Matching in nixpkgs pkgs.libwebp Tools and library for the WebP image format nixos-unstable 1.4.0 nixos-unstable-small 1.4.0 nixpkgs-unstable 1.4.0 pkgs.libwebp.x86_64-linux Tools and library for the WebP image format nixos-unstable ??? nixos-unstable-small 1.4.0 pkgs.libwebp.aarch64-linux Tools and library for the WebP image format nixos-unstable ??? nixos-unstable-small 1.4.0 pkgs.libwebp.x86_64-darwin Tools and library for the WebP image format nixos-unstable ??? nixos-unstable-small 1.4.0 pkgs.libwebp.aarch64-darwin Tools and library for the WebP image format nixos-unstable ??? nixos-unstable-small 1.4.0 Package maintainers: 1 @ajs124 Andreas Schrägle <nix@ajs124.de>
pkgs.libwebp Tools and library for the WebP image format nixos-unstable 1.4.0 nixos-unstable-small 1.4.0 nixpkgs-unstable 1.4.0
pkgs.libwebp.x86_64-linux Tools and library for the WebP image format nixos-unstable ??? nixos-unstable-small 1.4.0
pkgs.libwebp.aarch64-linux Tools and library for the WebP image format nixos-unstable ??? nixos-unstable-small 1.4.0
pkgs.libwebp.x86_64-darwin Tools and library for the WebP image format nixos-unstable ??? nixos-unstable-small 1.4.0
pkgs.libwebp.aarch64-darwin Tools and library for the WebP image format nixos-unstable ??? nixos-unstable-small 1.4.0
CVE-2025-1390 6.1 MEDIUM CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): HIGH Availability impact (A): NONE updated 9 months, 3 weeks ago by @fpletz Activity log Created automatic suggestion 9 months, 4 weeks ago @fpletz dismissed 9 months, 3 weeks ago pam_cap: Fix potential configuration parsing error The PAM module pam_cap.so of libcap configuration supports group names starting with “@”, during actual parsing, configurations not starting with “@” are incorrectly recognized as group names. This may result in nonintended users being granted an inherited capability set, potentially leading to security risks. Attackers can exploit this vulnerability to achieve local privilege escalation on systems where /etc/security/capability.conf is used to configure user inherited privileges by constructing specific usernames. Affected products libcap ==2.73;0 Matching in nixpkgs pkgs.libcap Library for working with POSIX capabilities nixos-unstable 2.70 nixos-unstable-small 2.70 nixpkgs-unstable 2.70 pkgs.libcap_ng Library for working with POSIX capabilities nixos-unstable 0.8.5 nixos-unstable-small 0.8.5 nixpkgs-unstable 0.8.5 pkgs.libcaption Free open-source CEA608 / CEA708 closed-caption encoder/decoder nixos-unstable 0.7 nixos-unstable-small 0.7 nixpkgs-unstable 0.7 Package maintainers: 1 @pschmitt Philipp Schmitt <philipp@schmitt.co>
pkgs.libcap Library for working with POSIX capabilities nixos-unstable 2.70 nixos-unstable-small 2.70 nixpkgs-unstable 2.70
pkgs.libcap_ng Library for working with POSIX capabilities nixos-unstable 0.8.5 nixos-unstable-small 0.8.5 nixpkgs-unstable 0.8.5
pkgs.libcaption Free open-source CEA608 / CEA708 closed-caption encoder/decoder nixos-unstable 0.7 nixos-unstable-small 0.7 nixpkgs-unstable 0.7