Published issues
NIXPKGS-2025-0008
published on
Permalink
CVE-2025-53882
9.1 CRITICAL
-
CVSS version: 3.1
-
Attack vector (AV): NETWORK
-
Attack complexity (AC): LOW
-
Privileges required (PR): NONE
-
User interaction (UI): NONE
-
Scope (S): UNCHANGED
-
Confidentiality impact (C): HIGH
-
Integrity impact (I): HIGH
-
Availability impact (A): NONE
updated 6 months, 3 weeks ago
by @Erethon
Activity log
-
Created automatic suggestion
8 months, 3 weeks ago
-
@Erethon
accepted
8 months, 2 weeks ago
-
@Erethon
published on GitHub
6 months, 3 weeks ago
python-mailmans logrotate configuration allows potential escalation from mailman to root
A Reliance on Untrusted Inputs in a Security Decision vulnerability in the logrotate configuration for openSUSEs mailman3 package allows potential escalation from mailman to rootThis issue affects openSUSE Tumbleweed: from ? before 3.3.10-2.1.
Matching in nixpkgs
Django library for Mailman UIs
Django library for Mailman UIs
NIXPKGS-2025-0007
published on
Permalink
CVE-2025-30192
7.5 HIGH
-
CVSS version: 3.1
-
Attack vector (AV): NETWORK
-
Attack complexity (AC): LOW
-
Privileges required (PR): NONE
-
User interaction (UI): NONE
-
Scope (S): UNCHANGED
-
Confidentiality impact (C): NONE
-
Integrity impact (I): NONE
-
Availability impact (A): HIGH
updated 6 months, 3 weeks ago
by @Erethon
Activity log
-
Created automatic suggestion
8 months, 3 weeks ago
-
@Erethon
accepted
8 months, 2 weeks ago
-
@Erethon
deleted
maintainer @rnhmjoj
6 months, 3 weeks ago
maintainer.delete
-
@Erethon
added
maintainer @Erethon
6 months, 3 weeks ago
maintainer.add
-
@Erethon
published on GitHub
6 months, 3 weeks ago
A Recursor configured to send out ECS enabled queries can be sensitive to spoofing attempts
An attacker spoofing answers to ECS enabled requests sent out by the Recursor has a chance of success higher than non-ECS enabled queries.
The updated version include various mitigations against spoofing attempts of ECS enabled queries by chaining ECS enabled requests and enforcing stricter validation of the received answers.
The most strict mitigation done when the new setting outgoing.edns_subnet_harden (old style name edns-subnet-harden) is enabled.
Package maintainers
Ignored maintainers (1)
NIXPKGS-2025-0006
published on
Permalink
CVE-2025-47444
7.5 HIGH
-
CVSS version: 3.1
-
Attack vector (AV): NETWORK
-
Attack complexity (AC): LOW
-
Privileges required (PR): NONE
-
User interaction (UI): NONE
-
Scope (S): UNCHANGED
-
Confidentiality impact (C): HIGH
-
Integrity impact (I): NONE
-
Availability impact (A): NONE
updated 6 months, 4 weeks ago
by @Erethon
Activity log
-
Created automatic suggestion
8 months ago
-
@Erethon
accepted
6 months, 4 weeks ago
-
@Erethon
published on GitHub
6 months, 4 weeks ago
WordPress GiveWP Plugin < 4.6.1 is vulnerable to Sensitive Data (PII) Exposure
Insertion of Sensitive Information Into Sent Data vulnerability in Liquid Web GiveWP allows Retrieve Embedded Sensitive Data.This issue affects GiveWP: from n/a before 4.6.1.
Matching in nixpkgs
Easy p2p file sending program
NIXPKGS-2025-0005
published on
Permalink
CVE-2023-39327
4.3 MEDIUM
-
CVSS version: 3.1
-
Attack vector (AV): NETWORK
-
Attack complexity (AC): LOW
-
Privileges required (PR): NONE
-
User interaction (UI): REQUIRED
-
Scope (S): UNCHANGED
-
Confidentiality impact (C): NONE
-
Integrity impact (I): NONE
-
Availability impact (A): LOW
updated 6 months, 4 weeks ago
by @Erethon
Activity log
-
Created automatic suggestion
8 months, 1 week ago
-
@Erethon
accepted
6 months, 4 weeks ago
-
@Erethon
published on GitHub
6 months, 4 weeks ago
Openjpeg: malicious files can cause the program to enter a large loop
A flaw was found in OpenJPEG. Maliciously constructed pictures can cause the program to enter a large loop and continuously print warning messages on the terminal.
Affected products
openjpeg
openjpeg2
gimp:flatpak/openjpeg2
inkscape:flatpak/openjpeg2
libreoffice:flatpak/openjpeg2
Matching in nixpkgs
Open-source JPEG 2000 codec written in C language
A J2K and JP2 plugin for pylibjpeg
A J2K and JP2 plugin for pylibjpeg
A J2K and JP2 plugin for pylibjpeg
NIXPKGS-2025-0004
published on
Permalink
CVE-2025-40920
8.6 HIGH
-
CVSS version: 3.1
-
Attack vector (AV): NETWORK
-
Attack complexity (AC): LOW
-
Privileges required (PR): NONE
-
User interaction (UI): NONE
-
Scope (S): UNCHANGED
-
Confidentiality impact (C): HIGH
-
Integrity impact (I): LOW
-
Availability impact (A): LOW
updated 6 months, 4 weeks ago
by @Erethon
Activity log
-
Created automatic suggestion
8 months ago
-
@Erethon
accepted
6 months, 4 weeks ago
-
@Erethon
published on GitHub
6 months, 4 weeks ago
Catalyst::Authentication::Credential::HTTP versions 1.018 and earlier for Perl use insecurely generated nonces
Catalyst::Authentication::Credential::HTTP versions 1.018 and earlier for Perl generate nonces using the Perl Data::UUID library. * Data::UUID does not use a strong cryptographic source for generating UUIDs.
* Data::UUID returns v3 UUIDs, which are generated from known information and are unsuitable for security, as per RFC 9562.
* The nonces should be generated from a strong cryptographic source, as per RFC 7616.
Affected products
Catalyst-Authentication-Credential-HTTP
Matching in nixpkgs
HTTP Basic and Digest authentication for Catalyst
HTTP Basic and Digest authentication for Catalyst
NIXPKGS-2025-0002
published on
updated 10 months, 3 weeks ago
by @fricklerhandwerk
Activity log
-
Created automatic suggestion
10 months, 3 weeks ago
-
@fricklerhandwerk
accepted
10 months, 3 weeks ago
-
@fricklerhandwerk
published on GitHub
10 months, 3 weeks ago
Regular Expression Denial of Service (ReDoS) in markedjs/marked
Marked prior to version 0.3.17 is vulnerable to a Regular Expression Denial of Service (ReDoS) attack due to catastrophic backtracking in several regular expressions used for parsing HTML tags and markdown links. An attacker can exploit this vulnerability by providing specially crafted markdown input, such as deeply nested or repetitively structured brackets or tag attributes, which cause the parser to hang and lead to a Denial of Service.
Matching in nixpkgs
Markdown to roff wrapper around marked
NIXPKGS-2025-0001
published on
Permalink
CVE-2025-26466
5.9 MEDIUM
-
CVSS version: 3.1
-
Attack vector (AV): NETWORK
-
Attack complexity (AC): HIGH
-
Privileges required (PR): NONE
-
User interaction (UI): NONE
-
Scope (S): UNCHANGED
-
Confidentiality impact (C): NONE
-
Integrity impact (I): NONE
-
Availability impact (A): HIGH
updated 11 months ago
by @mweinelt
Activity log
-
Created automatic suggestion
1 year, 1 month ago
-
@fricklerhandwerk
accepted
1 year, 1 month ago
-
@mweinelt
published on GitHub
11 months ago
Openssh: denial-of-service in openssh
A flaw was found in the OpenSSH package. For each ping packet the SSH server receives, a pong packet is allocated in a memory buffer and stored in a queue of packages. It is only freed when the server/client key exchange has finished. A malicious client may keep sending such packages, leading to an uncontrolled increase in memory consumption on the server side. Consequently, the server may become unavailable, resulting in a denial of service attack.
Matching in nixpkgs
Implementation of the SSH protocol
Implementation of the SSH protocol
Implementation of the SSH protocol with high performance networking patches
Implementation of the SSH protocol with GSSAPI support
NIXPKGS-2024-0001
published on
Permalink
CVE-2024-9675
4.4 MEDIUM
-
CVSS version: 3.1
-
Attack vector (AV): LOCAL
-
Attack complexity (AC): LOW
-
Privileges required (PR): LOW
-
User interaction (UI): NONE
-
Scope (S): UNCHANGED
-
Confidentiality impact (C): LOW
-
Integrity impact (I): LOW
-
Availability impact (A): NONE
created 1 year, 4 months ago
Buildah: buildah allows arbitrary directory mount
A vulnerability was found in Buildah. Cache mounts do not properly validate that user-specified paths for the cache are within our cache directory, allowing a `RUN` instruction in a Container file to mount an arbitrary directory from the host (read/write) into the container as long as those files can be accessed by the user running Buildah.
Affected products
cri-o
conmon
podman
skopeo
buildah
buildah-container
container-tools:rhel8
quay/quay-builder-rhel8
ocp-tools-4/jenkins-rhel8
container-tools:rhel8/conmon
container-tools:rhel8/podman
container-tools:rhel8/skopeo
container-tools:rhel8/buildah
openshift4/ose-docker-builder
openshift4/ose-docker-builder-rhel9
ocp-tools-4/jenkins-agent-base-rhel8
openshift-enterprise-builder-container
Matching in nixpkgs
Open Container Initiative-based implementation of the
Kubernetes Container Runtime Interface
OCI container runtime monitor
Program for managing pods, containers and container images
Command line utility for various operations on container images and image repositories
Tool which facilitates building OCI images
OCI container runtime monitor written in Rust
Implementation of docker-compose with podman backend
A graphical tool for developing on containers and Kubernetes
Open Container Initiative-based implementation of the
Kubernetes Container Runtime Interface
Tool which facilitates building OCI images
Podman task driver for Nomad
Python bindings for Podman's RESTful API
Python bindings for Podman's RESTful API