CVE-2024-28835 5.0 MEDIUM CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): HIGH created 6 months, 3 weeks ago Gnutls: potential crash during chain building/verification A flaw has been discovered in GnuTLS where an application crash can be induced when attempting to verify a specially crafted .pem bundle using the "certtool --verify-chain" command. Affected products gnutls ==3.8.3 * Matching in nixpkgs pkgs.gnutls GNU Transport Layer Security Library nixos-25.05 ??? nixos-25.05-small 3.8.9 nixos-unstable 3.8.6 nixos-unstable-small 3.8.6 nixpkgs-unstable 3.8.6 pkgs.guile-gnutls Guile bindings for GnuTLS library nixos-25.05 ??? nixos-25.05-small 4.0.1 nixos-unstable 4.0.0 nixos-unstable-small 4.0.0 nixpkgs-unstable 4.0.0 pkgs.python311Packages.python3-gnutls Python wrapper for the GnuTLS library nixos-unstable python3-gnutls-3.1.10 nixos-unstable-small python3-gnutls-3.1.10 nixpkgs-unstable python3-gnutls-3.1.10 pkgs.python312Packages.python3-gnutls Python wrapper for the GnuTLS library nixos-25.05 ??? nixos-25.05-small python3-gnutls-3.1.10 nixos-unstable python3-gnutls-3.1.10 nixos-unstable-small python3-gnutls-3.1.10 nixpkgs-unstable python3-gnutls-3.1.10 pkgs.python313Packages.python3-gnutls Python wrapper for the GnuTLS library nixos-25.05 ??? nixos-25.05-small python3-gnutls-3.1.10 pkgs.python312Packages.python3-gnutls.x86_64-linux Python wrapper for the GnuTLS library nixos-unstable python3-gnutls-3.1.10 pkgs.python312Packages.python3-gnutls.aarch64-linux Python wrapper for the GnuTLS library nixos-unstable python3-gnutls-3.1.10 pkgs.python312Packages.python3-gnutls.x86_64-darwin Python wrapper for the GnuTLS library nixos-unstable python3-gnutls-3.1.10 pkgs.python312Packages.python3-gnutls.aarch64-darwin Python wrapper for the GnuTLS library nixos-unstable python3-gnutls-3.1.10 Package maintainers: 3 @charlieshanley Charlie Hanley <charlieshanley@gmail.com> @vcunat Vladimír Čunát <v@cunat.cz> @foo-dogsquared Gabriel Arazas <foodogsquared@foodogsquared.one>
pkgs.gnutls GNU Transport Layer Security Library nixos-25.05 ??? nixos-25.05-small 3.8.9 nixos-unstable 3.8.6 nixos-unstable-small 3.8.6 nixpkgs-unstable 3.8.6
pkgs.guile-gnutls Guile bindings for GnuTLS library nixos-25.05 ??? nixos-25.05-small 4.0.1 nixos-unstable 4.0.0 nixos-unstable-small 4.0.0 nixpkgs-unstable 4.0.0
pkgs.python311Packages.python3-gnutls Python wrapper for the GnuTLS library nixos-unstable python3-gnutls-3.1.10 nixos-unstable-small python3-gnutls-3.1.10 nixpkgs-unstable python3-gnutls-3.1.10
pkgs.python312Packages.python3-gnutls Python wrapper for the GnuTLS library nixos-25.05 ??? nixos-25.05-small python3-gnutls-3.1.10 nixos-unstable python3-gnutls-3.1.10 nixos-unstable-small python3-gnutls-3.1.10 nixpkgs-unstable python3-gnutls-3.1.10
pkgs.python313Packages.python3-gnutls Python wrapper for the GnuTLS library nixos-25.05 ??? nixos-25.05-small python3-gnutls-3.1.10
pkgs.python312Packages.python3-gnutls.x86_64-linux Python wrapper for the GnuTLS library nixos-unstable python3-gnutls-3.1.10
pkgs.python312Packages.python3-gnutls.aarch64-linux Python wrapper for the GnuTLS library nixos-unstable python3-gnutls-3.1.10
pkgs.python312Packages.python3-gnutls.x86_64-darwin Python wrapper for the GnuTLS library nixos-unstable python3-gnutls-3.1.10
pkgs.python312Packages.python3-gnutls.aarch64-darwin Python wrapper for the GnuTLS library nixos-unstable python3-gnutls-3.1.10
CVE-2025-30193 7.5 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): HIGH created 6 months, 4 weeks ago Denial of service via crafted TCP exchange In some circumstances, when DNSdist is configured to allow an unlimited number of queries on a single, incoming TCP connection from a client, an attacker can cause a denial of service by crafting a TCP exchange that triggers an exhaustion of the stack and a crash of DNSdist, causing a denial of service. The remedy is: upgrade to the patched 1.9.10 version. A workaround is to restrict the maximum number of queries on incoming TCP connections to a safe value, like 50, via the setMaxTCPQueriesPerConnection setting. We would like to thank Renaud Allard for bringing this issue to our attention. Affected products dnsdist ==1.9.10 Matching in nixpkgs pkgs.dnsdist DNS Loadbalancer nixos-25.05 ??? nixos-25.05-small 1.9.9 nixos-unstable 1.8.3 nixos-unstable-small 1.8.3 nixpkgs-unstable 1.8.3 Package maintainers: 1 @jojosch Johannes Schleifenbaum <johannes@js-webcoding.de>
pkgs.dnsdist DNS Loadbalancer nixos-25.05 ??? nixos-25.05-small 1.9.9 nixos-unstable 1.8.3 nixos-unstable-small 1.8.3 nixpkgs-unstable 1.8.3
CVE-2025-26867 5.3 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): LOW Availability impact (A): NONE created 6 months, 4 weeks ago WordPress Bulk theme <= 1.0.11 - Broken Access Control vulnerability Missing Authorization vulnerability in Themes4WP Bulk allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Bulk: from n/a through 1.0.11. Affected products bulk =<1.0.11 Matching in nixpkgs pkgs.bulky Bulk rename app nixos-25.05 ??? nixos-25.05-small 3.6 nixos-unstable 3.5 nixos-unstable-small 3.5 nixpkgs-unstable 3.5 pkgs.bulk_extractor Digital forensics tool for extracting information from file systems nixos-25.05 ??? nixos-25.05-small 2.1.1 nixos-unstable 2.1.1 nixos-unstable-small 2.1.1 nixpkgs-unstable 2.1.1 pkgs.python311Packages.rebulk Advanced string matching from simple patterns nixos-unstable 3.2.0 nixos-unstable-small 3.2.0 nixpkgs-unstable 3.2.0 pkgs.python312Packages.rebulk Advanced string matching from simple patterns nixos-25.05 ??? nixos-25.05-small 3.2.0 nixos-unstable 3.2.0 nixos-unstable-small 3.2.0 nixpkgs-unstable 3.2.0 pkgs.python313Packages.rebulk Advanced string matching from simple patterns nixos-25.05 ??? nixos-25.05-small 3.2.0 pkgs.python312Packages.rebulk.x86_64-linux Advanced string matching from simple patterns nixos-unstable 3.2.0 pkgs.python312Packages.rebulk.aarch64-linux Advanced string matching from simple patterns nixos-unstable 3.2.0 pkgs.python312Packages.rebulk.x86_64-darwin Advanced string matching from simple patterns nixos-unstable 3.2.0 pkgs.python312Packages.rebulk.aarch64-darwin Advanced string matching from simple patterns nixos-unstable 3.2.0 Package maintainers: 3 @D3vil0p3r Antonio Voza <vozaanthony@gmail.com> @bobby285271 Bobby Rong <rjl931189261@126.com> @mkg20001 Maciej Krüger <mkg20001+nix@gmail.com>
pkgs.bulky Bulk rename app nixos-25.05 ??? nixos-25.05-small 3.6 nixos-unstable 3.5 nixos-unstable-small 3.5 nixpkgs-unstable 3.5
pkgs.bulk_extractor Digital forensics tool for extracting information from file systems nixos-25.05 ??? nixos-25.05-small 2.1.1 nixos-unstable 2.1.1 nixos-unstable-small 2.1.1 nixpkgs-unstable 2.1.1
pkgs.python311Packages.rebulk Advanced string matching from simple patterns nixos-unstable 3.2.0 nixos-unstable-small 3.2.0 nixpkgs-unstable 3.2.0
pkgs.python312Packages.rebulk Advanced string matching from simple patterns nixos-25.05 ??? nixos-25.05-small 3.2.0 nixos-unstable 3.2.0 nixos-unstable-small 3.2.0 nixpkgs-unstable 3.2.0
pkgs.python313Packages.rebulk Advanced string matching from simple patterns nixos-25.05 ??? nixos-25.05-small 3.2.0
pkgs.python312Packages.rebulk.x86_64-linux Advanced string matching from simple patterns nixos-unstable 3.2.0
pkgs.python312Packages.rebulk.aarch64-linux Advanced string matching from simple patterns nixos-unstable 3.2.0
pkgs.python312Packages.rebulk.x86_64-darwin Advanced string matching from simple patterns nixos-unstable 3.2.0
pkgs.python312Packages.rebulk.aarch64-darwin Advanced string matching from simple patterns nixos-unstable 3.2.0
CVE-2025-31027 7.1 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): CHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 6 months, 4 weeks ago WordPress Tiger theme <= 2.0 - Reflected Cross Site Scripting (XSS) vulnerability Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jocoxdesign Tiger tiger allows Reflected XSS.This issue affects Tiger: from n/a through 2.0. Affected products tiger =<2.0 Matching in nixpkgs pkgs.libtiger Rendering library for Kate streams using Pango and Cairo nixos-25.05 ??? nixos-25.05-small 0.3.4 nixos-unstable 0.3.4 nixos-unstable-small 0.3.4 nixpkgs-unstable 0.3.4 pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-25.05 ??? nixos-25.05-small 1.14.0 nixos-unstable 1.14.0 nixos-unstable-small 1.14.0 nixpkgs-unstable 1.14.0 pkgs.wiredtiger nixos-25.05 ??? nixos-25.05-small 3.2.1 nixos-unstable 3.2.1 nixos-unstable-small 3.2.1 nixpkgs-unstable 3.2.1 pkgs.tigerbeetle Financial accounting database designed to be distributed and fast nixos-25.05 ??? nixos-25.05-small 0.16.39 nixos-unstable 0.16.14 nixos-unstable-small 0.16.14 nixpkgs-unstable 0.16.14 pkgs.tigerjython Simple development environment for programming in Python nixos-25.05 ??? nixos-25.05-small 2.40 nixos-unstable 2.39 nixos-unstable-small 2.39 nixpkgs-unstable 2.39 pkgs.libtiger.x86_64-linux Rendering library for Kate streams using Pango and Cairo nixos-unstable ??? nixos-unstable-small 0.3.4 pkgs.libtiger.aarch64-linux Rendering library for Kate streams using Pango and Cairo nixos-unstable ??? nixos-unstable-small 0.3.4 pkgs.libtiger.x86_64-darwin Rendering library for Kate streams using Pango and Cairo nixos-unstable ??? nixos-unstable-small 0.3.4 pkgs.libtiger.aarch64-darwin Rendering library for Kate streams using Pango and Cairo nixos-unstable ??? nixos-unstable-small 0.3.4 pkgs.tree-sitter-grammars.tree-sitter-tiger nixos-25.05 ??? nixos-25.05-small 0.25.3 nixos-unstable 0.24.3 nixos-unstable-small 0.24.3 nixpkgs-unstable 0.24.3 pkgs.chickenPackages_5.chickenEggs.tiger-hash Tiger/192 Message Digest nixos-25.05 ??? nixos-25.05-small 4.1.3 nixos-unstable 4.1.2 nixos-unstable-small 4.1.2 nixpkgs-unstable 4.1.2 pkgs.vimPlugins.nvim-treesitter-parsers.tiger nixos-25.05 ??? nixos-25.05-small nixos-unstable ??? nixos-unstable-small nixpkgs-unstable pkgs.python312Packages.tree-sitter-grammars.tree-sitter-tiger Python bindings for tree-sitter-tiger nixos-25.05 ??? nixos-25.05-small 0.25.3 pkgs.python313Packages.tree-sitter-grammars.tree-sitter-tiger Python bindings for tree-sitter-tiger nixos-25.05 ??? nixos-25.05-small 0.25.3 Package maintainers: 8 @matthewbauer Matthew Bauer <mjbauer95@gmail.com> @nwjsmith Nate Smith <nate@theinternate.com> @DanielSidhion Daniel Sidhion <nixpkgs@sidhion.com> @rcmlz rcmlz <haguga-nixos@yahoo.com> @stepbrobd Yifei Sun <ysun@hey.com> @adfaure Adrien Faure <adfaure@pm.me> @mightyiam Shahar "Dawn" Or <mightyiampresence@gmail.com> @A-jay98 Ali Jamadi <ali@jamadi.me>
pkgs.libtiger Rendering library for Kate streams using Pango and Cairo nixos-25.05 ??? nixos-25.05-small 0.3.4 nixos-unstable 0.3.4 nixos-unstable-small 0.3.4 nixpkgs-unstable 0.3.4
pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-25.05 ??? nixos-25.05-small 1.14.0 nixos-unstable 1.14.0 nixos-unstable-small 1.14.0 nixpkgs-unstable 1.14.0
pkgs.wiredtiger nixos-25.05 ??? nixos-25.05-small 3.2.1 nixos-unstable 3.2.1 nixos-unstable-small 3.2.1 nixpkgs-unstable 3.2.1
pkgs.tigerbeetle Financial accounting database designed to be distributed and fast nixos-25.05 ??? nixos-25.05-small 0.16.39 nixos-unstable 0.16.14 nixos-unstable-small 0.16.14 nixpkgs-unstable 0.16.14
pkgs.tigerjython Simple development environment for programming in Python nixos-25.05 ??? nixos-25.05-small 2.40 nixos-unstable 2.39 nixos-unstable-small 2.39 nixpkgs-unstable 2.39
pkgs.libtiger.x86_64-linux Rendering library for Kate streams using Pango and Cairo nixos-unstable ??? nixos-unstable-small 0.3.4
pkgs.libtiger.aarch64-linux Rendering library for Kate streams using Pango and Cairo nixos-unstable ??? nixos-unstable-small 0.3.4
pkgs.libtiger.x86_64-darwin Rendering library for Kate streams using Pango and Cairo nixos-unstable ??? nixos-unstable-small 0.3.4
pkgs.libtiger.aarch64-darwin Rendering library for Kate streams using Pango and Cairo nixos-unstable ??? nixos-unstable-small 0.3.4
pkgs.tree-sitter-grammars.tree-sitter-tiger nixos-25.05 ??? nixos-25.05-small 0.25.3 nixos-unstable 0.24.3 nixos-unstable-small 0.24.3 nixpkgs-unstable 0.24.3
pkgs.chickenPackages_5.chickenEggs.tiger-hash Tiger/192 Message Digest nixos-25.05 ??? nixos-25.05-small 4.1.3 nixos-unstable 4.1.2 nixos-unstable-small 4.1.2 nixpkgs-unstable 4.1.2
pkgs.vimPlugins.nvim-treesitter-parsers.tiger nixos-25.05 ??? nixos-25.05-small nixos-unstable ??? nixos-unstable-small nixpkgs-unstable
pkgs.python312Packages.tree-sitter-grammars.tree-sitter-tiger Python bindings for tree-sitter-tiger nixos-25.05 ??? nixos-25.05-small 0.25.3
pkgs.python313Packages.tree-sitter-grammars.tree-sitter-tiger Python bindings for tree-sitter-tiger nixos-25.05 ??? nixos-25.05-small 0.25.3
CVE-2025-23988 7.1 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): CHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 6 months, 4 weeks ago WordPress ghostwriter theme <= 1.4 - Reflected Cross Site Scripting (XSS) vulnerability Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bruno Cavalcante Ghostwriter allows Reflected XSS.This issue affects Ghostwriter: from n/a through 1.4. Affected products ghostwriter =<1.4 Matching in nixpkgs pkgs.libsForQt5.ghostwriter Cross-platform, aesthetic, distraction-free Markdown editor nixos-25.05 ??? nixos-25.05-small 23.08.5 nixos-unstable 23.08.5 nixos-unstable-small 23.08.5 nixpkgs-unstable 23.08.5 pkgs.kdePackages.ghostwriter Text editor for Markdown nixos-25.05 ??? nixos-25.05-small 25.04.1 nixos-unstable 24.08.3 nixos-unstable-small 24.08.3 nixpkgs-unstable 24.08.3 pkgs.plasma5Packages.ghostwriter Cross-platform, aesthetic, distraction-free Markdown editor nixos-25.05 ??? nixos-25.05-small 23.08.5 nixos-unstable 23.08.5 nixos-unstable-small 23.08.5 nixpkgs-unstable 23.08.5 pkgs.libsForQt5.ghostwriter.x86_64-linux Cross-platform, aesthetic, distraction-free Markdown editor nixos-unstable ??? nixos-unstable-small 23.08.5 pkgs.libsForQt5.ghostwriter.aarch64-linux Cross-platform, aesthetic, distraction-free Markdown editor nixos-unstable ??? nixos-unstable-small 23.08.5 pkgs.plasma5Packages.ghostwriter.x86_64-linux Cross-platform, aesthetic, distraction-free Markdown editor nixos-unstable ??? nixpkgs-unstable 23.08.5 pkgs.plasma5Packages.ghostwriter.aarch64-linux Cross-platform, aesthetic, distraction-free Markdown editor nixos-unstable ??? nixpkgs-unstable 23.08.5 Package maintainers: 9 @ilya-fedin Ilya Fedin <fedin-ilja2010@ya.ru> @K900 Ilya K. <me@0upti.me> @ttuegel Thomas Tuegel <ttuegel@mailbox.org> @NickCao Nick Cao <nickcao@nichi.co> @LunNova Luna Nova <nixpkgs-maintainer@lunnova.dev> @SuperSandro2000 Sandro Jäckel <sandro.jaeckel@gmail.com> @mjm Matt Moriarity <matt@mattmoriarity.com> @erictapen Kerstin Humm <kerstin@erictapen.name> @dotlambda Robert Schütz <rschuetz17@gmail.com>
pkgs.libsForQt5.ghostwriter Cross-platform, aesthetic, distraction-free Markdown editor nixos-25.05 ??? nixos-25.05-small 23.08.5 nixos-unstable 23.08.5 nixos-unstable-small 23.08.5 nixpkgs-unstable 23.08.5
pkgs.kdePackages.ghostwriter Text editor for Markdown nixos-25.05 ??? nixos-25.05-small 25.04.1 nixos-unstable 24.08.3 nixos-unstable-small 24.08.3 nixpkgs-unstable 24.08.3
pkgs.plasma5Packages.ghostwriter Cross-platform, aesthetic, distraction-free Markdown editor nixos-25.05 ??? nixos-25.05-small 23.08.5 nixos-unstable 23.08.5 nixos-unstable-small 23.08.5 nixpkgs-unstable 23.08.5
pkgs.libsForQt5.ghostwriter.x86_64-linux Cross-platform, aesthetic, distraction-free Markdown editor nixos-unstable ??? nixos-unstable-small 23.08.5
pkgs.libsForQt5.ghostwriter.aarch64-linux Cross-platform, aesthetic, distraction-free Markdown editor nixos-unstable ??? nixos-unstable-small 23.08.5
pkgs.plasma5Packages.ghostwriter.x86_64-linux Cross-platform, aesthetic, distraction-free Markdown editor nixos-unstable ??? nixpkgs-unstable 23.08.5
pkgs.plasma5Packages.ghostwriter.aarch64-linux Cross-platform, aesthetic, distraction-free Markdown editor nixos-unstable ??? nixpkgs-unstable 23.08.5
CVE-2025-26735 7.5 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 6 months, 4 weeks ago WordPress Grip theme <= 1.0.9 - Local File Inclusion vulnerability Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Candid themes Grip.This issue affects Grip: from n/a through 1.0.9. Affected products grip =<1.0.9 Matching in nixpkgs pkgs.grip GTK-based audio CD player/ripper nixos-25.05 ??? nixos-25.05-small 4.2.4 nixos-unstable 4.2.4 nixos-unstable-small 4.2.4 nixpkgs-unstable 4.2.4 pkgs.go-grip Preview Markdown files locally before committing them nixos-25.05 ??? nixos-25.05-small 0.5.6 pkgs.grip-grab Fast, more lightweight ripgrep alternative for daily use cases nixos-25.05 ??? nixos-25.05-small 0.6.7 nixos-unstable 0.6.7 nixos-unstable-small 0.6.7 nixpkgs-unstable 0.6.7 pkgs.regripper Open source forensic software used as a Windows Registry data extraction command line nixos-25.05 ??? nixos-25.05-small 0-unstable-2024-12-12 nixos-unstable 0-unstable-2024-11-02 nixos-unstable-small 0-unstable-2024-11-02 nixpkgs-unstable 0-unstable-2024-11-02 pkgs.grip-search Fast, indexed regexp search over large file trees nixos-25.05 ??? nixos-25.05-small 0.8 nixos-unstable 0.8 nixos-unstable-small 0.8 nixpkgs-unstable 0.8 pkgs.jetbrains.datagrip Database IDE from JetBrains nixos-25.05 ??? nixos-25.05-small 2025.1.2 nixos-unstable 2024.3 nixos-unstable-small 2024.3 nixpkgs-unstable 2024.3 pkgs.python311Packages.grip Preview GitHub Markdown files like Readme locally before committing them nixos-unstable 4.6.1 nixos-unstable-small 4.6.1 nixpkgs-unstable 4.6.1 pkgs.python312Packages.grip Preview GitHub Markdown files like Readme locally before committing them nixos-25.05 ??? nixos-25.05-small 4.6.1 nixos-unstable 4.6.1 nixos-unstable-small 4.6.1 nixpkgs-unstable 4.6.1 pkgs.python313Packages.grip Preview GitHub Markdown files like Readme locally before committing them nixos-25.05 ??? nixos-25.05-small 4.6.1 pkgs.regripper.x86_64-linux Open source forensic software used as a Windows Registry data extraction command line nixos-unstable 0-unstable-2024-11-02 pkgs.emacsPackages.grip-mode nixos-unstable 20240820.825 nixos-unstable-small 20240820.825 nixpkgs-unstable 20240820.825 pkgs.regripper.aarch64-linux Open source forensic software used as a Windows Registry data extraction command line nixos-unstable 0-unstable-2024-11-02 pkgs.regripper.x86_64-darwin Open source forensic software used as a Windows Registry data extraction command line nixos-unstable 0-unstable-2024-11-02 pkgs.regripper.aarch64-darwin Open source forensic software used as a Windows Registry data extraction command line nixos-unstable 0-unstable-2024-11-02 pkgs.python312Packages.grip.x86_64-linux Preview GitHub Markdown files like Readme locally before committing them nixos-unstable 4.6.1 pkgs.python312Packages.grip.aarch64-linux Preview GitHub Markdown files like Readme locally before committing them nixos-unstable 4.6.1 pkgs.python312Packages.grip.x86_64-darwin Preview GitHub Markdown files like Readme locally before committing them nixos-unstable 4.6.1 pkgs.python312Packages.grip.aarch64-darwin Preview GitHub Markdown files like Readme locally before committing them nixos-unstable 4.6.1 Package maintainers: 6 @k0ral Koral <koral@mailoo.org> @MarcWeber Marc Weber <marco-oweber@gmx.de> @luftmensch-luftmensch Valentino Bocchetti <valentinobocchetti59@gmail.com> @tex Milan Svoboda <milan.svoboda@centrum.cz> @heisfer Heisfer <heisfer@refract.dev> @D3vil0p3r Antonio Voza <vozaanthony@gmail.com>
pkgs.grip GTK-based audio CD player/ripper nixos-25.05 ??? nixos-25.05-small 4.2.4 nixos-unstable 4.2.4 nixos-unstable-small 4.2.4 nixpkgs-unstable 4.2.4
pkgs.go-grip Preview Markdown files locally before committing them nixos-25.05 ??? nixos-25.05-small 0.5.6
pkgs.grip-grab Fast, more lightweight ripgrep alternative for daily use cases nixos-25.05 ??? nixos-25.05-small 0.6.7 nixos-unstable 0.6.7 nixos-unstable-small 0.6.7 nixpkgs-unstable 0.6.7
pkgs.regripper Open source forensic software used as a Windows Registry data extraction command line nixos-25.05 ??? nixos-25.05-small 0-unstable-2024-12-12 nixos-unstable 0-unstable-2024-11-02 nixos-unstable-small 0-unstable-2024-11-02 nixpkgs-unstable 0-unstable-2024-11-02
pkgs.grip-search Fast, indexed regexp search over large file trees nixos-25.05 ??? nixos-25.05-small 0.8 nixos-unstable 0.8 nixos-unstable-small 0.8 nixpkgs-unstable 0.8
pkgs.jetbrains.datagrip Database IDE from JetBrains nixos-25.05 ??? nixos-25.05-small 2025.1.2 nixos-unstable 2024.3 nixos-unstable-small 2024.3 nixpkgs-unstable 2024.3
pkgs.python311Packages.grip Preview GitHub Markdown files like Readme locally before committing them nixos-unstable 4.6.1 nixos-unstable-small 4.6.1 nixpkgs-unstable 4.6.1
pkgs.python312Packages.grip Preview GitHub Markdown files like Readme locally before committing them nixos-25.05 ??? nixos-25.05-small 4.6.1 nixos-unstable 4.6.1 nixos-unstable-small 4.6.1 nixpkgs-unstable 4.6.1
pkgs.python313Packages.grip Preview GitHub Markdown files like Readme locally before committing them nixos-25.05 ??? nixos-25.05-small 4.6.1
pkgs.regripper.x86_64-linux Open source forensic software used as a Windows Registry data extraction command line nixos-unstable 0-unstable-2024-11-02
pkgs.emacsPackages.grip-mode nixos-unstable 20240820.825 nixos-unstable-small 20240820.825 nixpkgs-unstable 20240820.825
pkgs.regripper.aarch64-linux Open source forensic software used as a Windows Registry data extraction command line nixos-unstable 0-unstable-2024-11-02
pkgs.regripper.x86_64-darwin Open source forensic software used as a Windows Registry data extraction command line nixos-unstable 0-unstable-2024-11-02
pkgs.regripper.aarch64-darwin Open source forensic software used as a Windows Registry data extraction command line nixos-unstable 0-unstable-2024-11-02
pkgs.python312Packages.grip.x86_64-linux Preview GitHub Markdown files like Readme locally before committing them nixos-unstable 4.6.1
pkgs.python312Packages.grip.aarch64-linux Preview GitHub Markdown files like Readme locally before committing them nixos-unstable 4.6.1
pkgs.python312Packages.grip.x86_64-darwin Preview GitHub Markdown files like Readme locally before committing them nixos-unstable 4.6.1
pkgs.python312Packages.grip.aarch64-darwin Preview GitHub Markdown files like Readme locally before committing them nixos-unstable 4.6.1
CVE-2025-4945 3.7 LOW CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): LOW Availability impact (A): NONE created 6 months, 4 weeks ago Libsoup: integer overflow in cookie expiration date handling in libsoup A flaw was found in the cookie parsing logic of the libsoup HTTP library, used in GNOME applications and other software. The vulnerability arises when processing the expiration date of cookies, where a specially crafted value can trigger an integer overflow. This may result in undefined behavior, allowing an attacker to bypass cookie expiration logic, causing persistent or unintended cookie behavior. The issue stems from improper validation of large integer inputs during date arithmetic operations within the cookie parsing routines. Affected products libsoup * =<3.6.5 libsoup3 * Matching in nixpkgs pkgs.libsoup_3 HTTP client/server library for GNOME nixos-25.05 ??? nixos-25.05-small 3.6.5 nixos-unstable 3.6.0 nixos-unstable-small 3.6.0 nixpkgs-unstable 3.6.0 pkgs.libsoup_2_4 HTTP client/server library for GNOME nixos-25.05 ??? nixos-25.05-small 2.74.3 nixos-unstable 2.74.3 nixos-unstable-small 2.74.3 nixpkgs-unstable 2.74.3 pkgs.libsoup_3.x86_64-linux HTTP client/server library for GNOME nixos-unstable ??? nixos-unstable-small 3.6.0 pkgs.libsoup_3.aarch64-linux HTTP client/server library for GNOME nixos-unstable ??? nixos-unstable-small 3.6.0 pkgs.libsoup_3.x86_64-darwin HTTP client/server library for GNOME nixos-unstable ??? nixos-unstable-small 3.6.0 pkgs.libsoup_2_4.x86_64-linux HTTP client/server library for GNOME nixos-unstable ??? nixos-unstable-small 2.74.3 pkgs.libsoup_3.aarch64-darwin HTTP client/server library for GNOME nixos-unstable ??? nixos-unstable-small 3.6.0 pkgs.libsoup_2_4.aarch64-linux HTTP client/server library for GNOME nixos-unstable ??? nixos-unstable-small 2.74.3 pkgs.libsoup_2_4.x86_64-darwin HTTP client/server library for GNOME nixos-unstable ??? nixos-unstable-small 2.74.3 pkgs.libsoup_2_4.aarch64-darwin HTTP client/server library for GNOME nixos-unstable ??? nixos-unstable-small 2.74.3 pkgs.tests.pkg-config.defaultPkgConfigPackages."libsoup-gnome-2.4" Test whether libsoup-2.74.3 exposes pkg-config modules libsoup-gnome-2.4 nixos-25.05 ??? nixos-25.05-small nixos-unstable 2.4 nixos-unstable-small 2.4 nixpkgs-unstable 2.4 Package maintainers: 6 @7c6f434c Michael Raskin <7c6f434c@mail.ru> @jtojnar Jan Tojnar <jtojnar@gmail.com> @lovek323 Jason O'Conal <jason@oconal.id.au> @dasj19 Daniel Șerbănescu <daniel@serbanescu.dk> @bobby285271 Bobby Rong <rjl931189261@126.com> @hedning Tor Hedin Brønner <torhedinbronner@gmail.com>
pkgs.libsoup_3 HTTP client/server library for GNOME nixos-25.05 ??? nixos-25.05-small 3.6.5 nixos-unstable 3.6.0 nixos-unstable-small 3.6.0 nixpkgs-unstable 3.6.0
pkgs.libsoup_2_4 HTTP client/server library for GNOME nixos-25.05 ??? nixos-25.05-small 2.74.3 nixos-unstable 2.74.3 nixos-unstable-small 2.74.3 nixpkgs-unstable 2.74.3
pkgs.libsoup_3.x86_64-linux HTTP client/server library for GNOME nixos-unstable ??? nixos-unstable-small 3.6.0
pkgs.libsoup_3.aarch64-linux HTTP client/server library for GNOME nixos-unstable ??? nixos-unstable-small 3.6.0
pkgs.libsoup_3.x86_64-darwin HTTP client/server library for GNOME nixos-unstable ??? nixos-unstable-small 3.6.0
pkgs.libsoup_2_4.x86_64-linux HTTP client/server library for GNOME nixos-unstable ??? nixos-unstable-small 2.74.3
pkgs.libsoup_3.aarch64-darwin HTTP client/server library for GNOME nixos-unstable ??? nixos-unstable-small 3.6.0
pkgs.libsoup_2_4.aarch64-linux HTTP client/server library for GNOME nixos-unstable ??? nixos-unstable-small 2.74.3
pkgs.libsoup_2_4.x86_64-darwin HTTP client/server library for GNOME nixos-unstable ??? nixos-unstable-small 2.74.3
pkgs.libsoup_2_4.aarch64-darwin HTTP client/server library for GNOME nixos-unstable ??? nixos-unstable-small 2.74.3
pkgs.tests.pkg-config.defaultPkgConfigPackages."libsoup-gnome-2.4" Test whether libsoup-2.74.3 exposes pkg-config modules libsoup-gnome-2.4 nixos-25.05 ??? nixos-25.05-small nixos-unstable 2.4 nixos-unstable-small 2.4 nixpkgs-unstable 2.4
CVE-2025-4948 7.5 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): HIGH created 6 months, 4 weeks ago Libsoup: integer underflow in soup_multipart_new_from_message() leading to denial of service in libsoup A flaw was found in the soup_multipart_new_from_message() function of the libsoup HTTP library, which is commonly used by GNOME and other applications to handle web communications. The issue occurs when the library processes specially crafted multipart messages. Due to improper validation, an internal calculation can go wrong, leading to an integer underflow. This can cause the program to access invalid memory and crash. As a result, any application or server using libsoup could be forced to exit unexpectedly, creating a denial-of-service (DoS) risk. Affected products libsoup * =<3.6.5 libsoup3 * Matching in nixpkgs pkgs.libsoup_3 HTTP client/server library for GNOME nixos-25.05 ??? nixos-25.05-small 3.6.5 nixos-unstable 3.6.0 nixos-unstable-small 3.6.0 nixpkgs-unstable 3.6.0 pkgs.libsoup_2_4 HTTP client/server library for GNOME nixos-25.05 ??? nixos-25.05-small 2.74.3 nixos-unstable 2.74.3 nixos-unstable-small 2.74.3 nixpkgs-unstable 2.74.3 pkgs.libsoup_3.x86_64-linux HTTP client/server library for GNOME nixos-unstable ??? nixos-unstable-small 3.6.0 pkgs.libsoup_3.aarch64-linux HTTP client/server library for GNOME nixos-unstable ??? nixos-unstable-small 3.6.0 pkgs.libsoup_3.x86_64-darwin HTTP client/server library for GNOME nixos-unstable ??? nixos-unstable-small 3.6.0 pkgs.libsoup_2_4.x86_64-linux HTTP client/server library for GNOME nixos-unstable ??? nixos-unstable-small 2.74.3 pkgs.libsoup_3.aarch64-darwin HTTP client/server library for GNOME nixos-unstable ??? nixos-unstable-small 3.6.0 pkgs.libsoup_2_4.aarch64-linux HTTP client/server library for GNOME nixos-unstable ??? nixos-unstable-small 2.74.3 pkgs.libsoup_2_4.x86_64-darwin HTTP client/server library for GNOME nixos-unstable ??? nixos-unstable-small 2.74.3 pkgs.libsoup_2_4.aarch64-darwin HTTP client/server library for GNOME nixos-unstable ??? nixos-unstable-small 2.74.3 pkgs.tests.pkg-config.defaultPkgConfigPackages."libsoup-gnome-2.4" Test whether libsoup-2.74.3 exposes pkg-config modules libsoup-gnome-2.4 nixos-25.05 ??? nixos-25.05-small nixos-unstable 2.4 nixos-unstable-small 2.4 nixpkgs-unstable 2.4 Package maintainers: 6 @bobby285271 Bobby Rong <rjl931189261@126.com> @lovek323 Jason O'Conal <jason@oconal.id.au> @dasj19 Daniel Șerbănescu <daniel@serbanescu.dk> @jtojnar Jan Tojnar <jtojnar@gmail.com> @7c6f434c Michael Raskin <7c6f434c@mail.ru> @hedning Tor Hedin Brønner <torhedinbronner@gmail.com>
pkgs.libsoup_3 HTTP client/server library for GNOME nixos-25.05 ??? nixos-25.05-small 3.6.5 nixos-unstable 3.6.0 nixos-unstable-small 3.6.0 nixpkgs-unstable 3.6.0
pkgs.libsoup_2_4 HTTP client/server library for GNOME nixos-25.05 ??? nixos-25.05-small 2.74.3 nixos-unstable 2.74.3 nixos-unstable-small 2.74.3 nixpkgs-unstable 2.74.3
pkgs.libsoup_3.x86_64-linux HTTP client/server library for GNOME nixos-unstable ??? nixos-unstable-small 3.6.0
pkgs.libsoup_3.aarch64-linux HTTP client/server library for GNOME nixos-unstable ??? nixos-unstable-small 3.6.0
pkgs.libsoup_3.x86_64-darwin HTTP client/server library for GNOME nixos-unstable ??? nixos-unstable-small 3.6.0
pkgs.libsoup_2_4.x86_64-linux HTTP client/server library for GNOME nixos-unstable ??? nixos-unstable-small 2.74.3
pkgs.libsoup_3.aarch64-darwin HTTP client/server library for GNOME nixos-unstable ??? nixos-unstable-small 3.6.0
pkgs.libsoup_2_4.aarch64-linux HTTP client/server library for GNOME nixos-unstable ??? nixos-unstable-small 2.74.3
pkgs.libsoup_2_4.x86_64-darwin HTTP client/server library for GNOME nixos-unstable ??? nixos-unstable-small 2.74.3
pkgs.libsoup_2_4.aarch64-darwin HTTP client/server library for GNOME nixos-unstable ??? nixos-unstable-small 2.74.3
pkgs.tests.pkg-config.defaultPkgConfigPackages."libsoup-gnome-2.4" Test whether libsoup-2.74.3 exposes pkg-config modules libsoup-gnome-2.4 nixos-25.05 ??? nixos-25.05-small nixos-unstable 2.4 nixos-unstable-small 2.4 nixpkgs-unstable 2.4
CVE-2025-31063 4.3 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): LOW Availability impact (A): NONE created 7 months ago WordPress Wishlist <= 2.1.0 - Broken Access Control Vulnerability Missing Authorization vulnerability in redqteam Wishlist allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Wishlist: from n/a through 2.1.0. Affected products wishlist =<2.1.0 Matching in nixpkgs pkgs.wishlist Single entrypoint for multiple SSH endpoints nixos-unstable 0.15.0 nixos-unstable-small 0.15.0 nixpkgs-unstable 0.15.0 Package maintainers: 2 @caarlos0 Carlos A Becker <carlos@becker.software> @penguwin Nicolas Martin <penguwin@penguwin.eu>
pkgs.wishlist Single entrypoint for multiple SSH endpoints nixos-unstable 0.15.0 nixos-unstable-small 0.15.0 nixpkgs-unstable 0.15.0
CVE-2025-31062 4.3 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): NONE Availability impact (A): NONE created 7 months ago WordPress Wishlist <= 2.1.0 - Sensitive Data Exposure Vulnerability Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in redqteam Wishlist allows Retrieve Embedded Sensitive Data. This issue affects Wishlist: from n/a through 2.1.0. Affected products wishlist =<2.1.0 Matching in nixpkgs pkgs.wishlist Single entrypoint for multiple SSH endpoints nixos-unstable 0.15.0 nixos-unstable-small 0.15.0 nixpkgs-unstable 0.15.0 Package maintainers: 2 @caarlos0 Carlos A Becker <carlos@becker.software> @penguwin Nicolas Martin <penguwin@penguwin.eu>
pkgs.wishlist Single entrypoint for multiple SSH endpoints nixos-unstable 0.15.0 nixos-unstable-small 0.15.0 nixpkgs-unstable 0.15.0