Dismissed suggestions Untriaged suggestions Draft issues Published issues Automatically generated suggestions Create Draft to queue a suggestion for refinement. Dismiss to remove a suggestion from the queue. CVE-2023-6478 7.6 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): LOW Availability impact (A): LOW created 3 months, 2 weeks ago Xorg-x11-server: out-of-bounds memory read in rrchangeoutputproperty and rrchangeproviderproperty A flaw was found in xorg-server. A specially crafted request to RRChangeProviderProperty or RRChangeOutputProperty can trigger an integer overflow which may lead to a disclosure of sensitive information. tigervnc * xorg-x11-server * xorg-x11-server-Xwayland * pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-25.05 1.14.0 nixpkgs-25.05-darwin 1.14.0 nixos-25.05-small 1.14.0 nixos-unstable 1.15.0 nixos-unstable-small 1.15.0 nixpkgs-unstable 1.14.0 CVE-2023-5367 7.8 HIGH CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 3 months, 2 weeks ago Xorg-x11-server: out-of-bounds write in xichangedeviceproperty/rrchangeoutputproperty A out-of-bounds write flaw was found in the xorg-x11-server. This issue occurs due to an incorrect calculation of a buffer offset when copying data stored in the heap in the XIChangeDeviceProperty function in Xi/xiproperty.c and in RRChangeOutputProperty function in randr/rrproperty.c, allowing for possible escalation of privileges or denial of service. tigervnc * xorg-x11-server * xorg-x11-server-Xwayland * pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-25.05 1.14.0 nixpkgs-25.05-darwin 1.14.0 nixos-25.05-small 1.14.0 nixos-unstable 1.15.0 nixos-unstable-small 1.15.0 nixpkgs-unstable 1.14.0 CVE-2023-6377 7.8 HIGH CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 3 months, 2 weeks ago Xorg-x11-server: out-of-bounds memory reads/writes in xkb button actions A flaw was found in xorg-server. Querying or changing XKB button actions such as moving from a touchpad to a mouse can result in out-of-bounds memory reads and writes. This may allow local privilege escalation or possible remote code execution in cases where X11 forwarding is involved. tigervnc * xorg-x11-server * xorg-x11-server-Xwayland * pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-25.05 1.14.0 nixpkgs-25.05-darwin 1.14.0 nixos-25.05-small 1.14.0 nixos-unstable 1.15.0 nixos-unstable-small 1.15.0 nixpkgs-unstable 1.14.0 CVE-2024-0229 7.8 HIGH CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 3 months, 2 weeks ago Xorg-x11-server: reattaching to different master device may lead to out-of-bounds memory access An out-of-bounds memory access flaw was found in the X.Org server. This issue can be triggered when a device frozen by a sync grab is reattached to a different master device. This issue may lead to an application crash, local privilege escalation (if the server runs with extended privileges), or remote code execution in SSH X11 forwarding environments. tigervnc * xorg-server <21.1.11 xorg-x11-server * xorg-x11-server-Xwayland * pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-25.05 1.14.0 nixpkgs-25.05-darwin 1.14.0 nixos-25.05-small 1.14.0 nixos-unstable 1.15.0 nixos-unstable-small 1.15.0 nixpkgs-unstable 1.14.0 pkgs.xorg.xvfb nixos-25.05 21.1.16 nixpkgs-25.05-darwin 21.1.16 nixos-25.05-small 21.1.16 nixos-unstable 21.1.14 nixos-unstable-small 21.1.16 nixpkgs-unstable 21.1.16 pkgs.xorg.xorgserver nixos-25.05 21.1.16 nixpkgs-25.05-darwin 21.1.16 nixos-25.05-small 21.1.16 nixos-unstable 21.1.14 nixos-unstable-small 21.1.16 nixpkgs-unstable 21.1.16 CVE-2023-5574 7.0 HIGH CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): HIGH Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 3 months, 2 weeks ago Xorg-x11-server: use-after-free bug in damagedestroy A use-after-free flaw was found in xorg-x11-server-Xvfb. This issue occurs in Xvfb with a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode). If the pointer is warped from a screen 1 to a screen 0, a use-after-free issue may be triggered during shutdown or reset of the Xvfb server, allowing for possible escalation of privileges or denial of service. tigervnc * xorg-x11-server xorg-x11-server-Xwayland pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-25.05 1.14.0 nixpkgs-25.05-darwin 1.14.0 nixos-25.05-small 1.14.0 nixos-unstable 1.15.0 nixos-unstable-small 1.15.0 nixpkgs-unstable 1.14.0 CVE-2025-53512 6.5 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): NONE Availability impact (A): NONE created 3 months, 2 weeks ago Sensitive log retrieval in Juju The /log endpoint on a Juju controller lacked sufficient authorization checks, allowing unauthorized users to access debug messages that could contain sensitive information. juju <3.6.8 <2.9.52 pkgs.juju Open source modelling tool for operating software in the cloud nixos-25.05 3.6.5 nixpkgs-25.05-darwin 3.6.5 nixos-25.05-small 3.6.5 nixos-unstable 3.5.4 nixos-unstable-small 3.6.5 nixpkgs-unstable 3.6.5 pkgs.jujutsu Git-compatible DVCS that is both simple and powerful nixos-25.05 0.29.0 nixpkgs-25.05-darwin 0.29.0 nixos-25.05-small 0.29.0 nixos-unstable 0.24.0 nixos-unstable-small 0.29.0 nixpkgs-unstable 0.29.0 pkgs.jujuutils Utilities around FireWire devices connected to a Linux computer nixos-25.05 0.2 nixpkgs-25.05-darwin 0.2 nixos-25.05-small 0.2 nixos-unstable 0.2 nixos-unstable-small 0.2 nixpkgs-unstable 0.2 pkgs.juju.x86_64-linux Open source modelling tool for operating software in the cloud nixos-unstable ??? nixpkgs-unstable 3.5.4 pkgs.juju.aarch64-linux Open source modelling tool for operating software in the cloud nixos-unstable ??? nixpkgs-unstable 3.5.4 pkgs.juju.x86_64-darwin Open source modelling tool for operating software in the cloud nixos-unstable ??? nixpkgs-unstable 3.5.4 pkgs.juju.aarch64-darwin Open source modelling tool for operating software in the cloud nixos-unstable ??? nixpkgs-unstable 3.5.4 pkgs.jujutsu.x86_64-linux Git-compatible DVCS that is both simple and powerful nixos-unstable ??? nixpkgs-unstable 0.24.0 pkgs.jujutsu.aarch64-linux Git-compatible DVCS that is both simple and powerful nixos-unstable ??? nixpkgs-unstable 0.24.0 pkgs.jujutsu.x86_64-darwin Git-compatible DVCS that is both simple and powerful nixos-unstable ??? nixpkgs-unstable 0.24.0 pkgs.jujutsu.aarch64-darwin Git-compatible DVCS that is both simple and powerful nixos-unstable ??? nixpkgs-unstable 0.24.0 pkgs.jujuutils.x86_64-linux Utilities around FireWire devices connected to a Linux computer nixos-unstable ??? nixpkgs-unstable 0.2 pkgs.jujuutils.aarch64-linux Utilities around FireWire devices connected to a Linux computer nixos-unstable ??? nixpkgs-unstable 0.2 Package maintainers: 5 @RealityAnomaly Alex Zero <alex@arctarus.co.uk> @thoughtpolice Austin Seipp <aseipp@pobox.com> @0x4A6F Joachim Ernst <mail-maintainer@0x4A6F.dev> @emilazy Emily <nixpkgs@emily.moe> @bbigras Bruno Bigras <bigras.bruno@gmail.com> CVE-2025-0928 8.8 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 3 months, 2 weeks ago Arbitrary executable upload via authenticated endpoint In Juju versions prior to 3.6.8 and 2.9.52, any authenticated controller user was allowed to upload arbitrary agent binaries to any model or to the controller itself, without verifying model membership or requiring explicit permissions. This enabled the distribution of poisoned binaries to new or upgraded machines, potentially resulting in remote code execution. juju <3.6.8 <2.9.52 pkgs.juju Open source modelling tool for operating software in the cloud nixos-25.05 3.6.5 nixpkgs-25.05-darwin 3.6.5 nixos-25.05-small 3.6.5 nixos-unstable 3.5.4 nixos-unstable-small 3.6.5 nixpkgs-unstable 3.6.5 pkgs.jujutsu Git-compatible DVCS that is both simple and powerful nixos-25.05 0.29.0 nixpkgs-25.05-darwin 0.29.0 nixos-25.05-small 0.29.0 nixos-unstable 0.24.0 nixos-unstable-small 0.29.0 nixpkgs-unstable 0.29.0 pkgs.jujuutils Utilities around FireWire devices connected to a Linux computer nixos-25.05 0.2 nixpkgs-25.05-darwin 0.2 nixos-25.05-small 0.2 nixos-unstable 0.2 nixos-unstable-small 0.2 nixpkgs-unstable 0.2 pkgs.juju.x86_64-linux Open source modelling tool for operating software in the cloud nixos-unstable ??? nixpkgs-unstable 3.5.4 pkgs.juju.aarch64-linux Open source modelling tool for operating software in the cloud nixos-unstable ??? nixpkgs-unstable 3.5.4 pkgs.juju.x86_64-darwin Open source modelling tool for operating software in the cloud nixos-unstable ??? nixpkgs-unstable 3.5.4 pkgs.juju.aarch64-darwin Open source modelling tool for operating software in the cloud nixos-unstable ??? nixpkgs-unstable 3.5.4 pkgs.jujutsu.x86_64-linux Git-compatible DVCS that is both simple and powerful nixos-unstable ??? nixpkgs-unstable 0.24.0 pkgs.jujutsu.aarch64-linux Git-compatible DVCS that is both simple and powerful nixos-unstable ??? nixpkgs-unstable 0.24.0 pkgs.jujutsu.x86_64-darwin Git-compatible DVCS that is both simple and powerful nixos-unstable ??? nixpkgs-unstable 0.24.0 pkgs.jujutsu.aarch64-darwin Git-compatible DVCS that is both simple and powerful nixos-unstable ??? nixpkgs-unstable 0.24.0 pkgs.jujuutils.x86_64-linux Utilities around FireWire devices connected to a Linux computer nixos-unstable ??? nixpkgs-unstable 0.2 pkgs.jujuutils.aarch64-linux Utilities around FireWire devices connected to a Linux computer nixos-unstable ??? nixpkgs-unstable 0.2 Package maintainers: 5 @RealityAnomaly Alex Zero <alex@arctarus.co.uk> @thoughtpolice Austin Seipp <aseipp@pobox.com> @0x4A6F Joachim Ernst <mail-maintainer@0x4A6F.dev> @emilazy Emily <nixpkgs@emily.moe> @bbigras Bruno Bigras <bigras.bruno@gmail.com> CVE-2025-53513 8.8 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 3 months, 2 weeks ago Zip slip vulnerability in Juju The /charms endpoint on a Juju controller lacked sufficient authorization checks, allowing any user with an account on the controller to upload a charm. Uploading a malicious charm that exploits a Zip Slip vulnerability could allow an attacker to gain access to a machine running a unit through the affected charm. juju <3.6.8 <2.9.52 pkgs.juju Open source modelling tool for operating software in the cloud nixos-25.05 3.6.5 nixpkgs-25.05-darwin 3.6.5 nixos-25.05-small 3.6.5 nixos-unstable 3.5.4 nixos-unstable-small 3.6.5 nixpkgs-unstable 3.6.5 pkgs.jujutsu Git-compatible DVCS that is both simple and powerful nixos-25.05 0.29.0 nixpkgs-25.05-darwin 0.29.0 nixos-25.05-small 0.29.0 nixos-unstable 0.24.0 nixos-unstable-small 0.29.0 nixpkgs-unstable 0.29.0 pkgs.jujuutils Utilities around FireWire devices connected to a Linux computer nixos-25.05 0.2 nixpkgs-25.05-darwin 0.2 nixos-25.05-small 0.2 nixos-unstable 0.2 nixos-unstable-small 0.2 nixpkgs-unstable 0.2 pkgs.juju.x86_64-linux Open source modelling tool for operating software in the cloud nixos-unstable ??? nixpkgs-unstable 3.5.4 pkgs.juju.aarch64-linux Open source modelling tool for operating software in the cloud nixos-unstable ??? nixpkgs-unstable 3.5.4 pkgs.juju.x86_64-darwin Open source modelling tool for operating software in the cloud nixos-unstable ??? nixpkgs-unstable 3.5.4 pkgs.juju.aarch64-darwin Open source modelling tool for operating software in the cloud nixos-unstable ??? nixpkgs-unstable 3.5.4 pkgs.jujutsu.x86_64-linux Git-compatible DVCS that is both simple and powerful nixos-unstable ??? nixpkgs-unstable 0.24.0 pkgs.jujutsu.aarch64-linux Git-compatible DVCS that is both simple and powerful nixos-unstable ??? nixpkgs-unstable 0.24.0 pkgs.jujutsu.x86_64-darwin Git-compatible DVCS that is both simple and powerful nixos-unstable ??? nixpkgs-unstable 0.24.0 pkgs.jujutsu.aarch64-darwin Git-compatible DVCS that is both simple and powerful nixos-unstable ??? nixpkgs-unstable 0.24.0 pkgs.jujuutils.x86_64-linux Utilities around FireWire devices connected to a Linux computer nixos-unstable ??? nixpkgs-unstable 0.2 pkgs.jujuutils.aarch64-linux Utilities around FireWire devices connected to a Linux computer nixos-unstable ??? nixpkgs-unstable 0.2 Package maintainers: 5 @RealityAnomaly Alex Zero <alex@arctarus.co.uk> @thoughtpolice Austin Seipp <aseipp@pobox.com> @0x4A6F Joachim Ernst <mail-maintainer@0x4A6F.dev> @emilazy Emily <nixpkgs@emily.moe> @bbigras Bruno Bigras <bigras.bruno@gmail.com> CVE-2025-5987 5.0 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 3 months, 2 weeks ago Libssh: invalid return code for chacha20 poly1305 with openssl backend A flaw was found in libssh when using the ChaCha20 cipher with the OpenSSL library. If an attacker manages to exhaust the heap space, this error is not detected and may lead to libssh using a partially initialized cipher context. This occurs because the OpenSSL error code returned aliases with the SSH_OK code, resulting in libssh not properly detecting the error returned by the OpenSSL library. This issue can lead to undefined behavior, including compromised data confidentiality and integrity or crashes. rhcos libssh <0.11.2 libssh2 pkgs.libssh SSH client library nixos-25.05 0.11.1 nixpkgs-25.05-darwin 0.11.1 nixos-25.05-small 0.11.1 nixos-unstable 0.11.1 nixos-unstable-small 0.11.1 nixpkgs-unstable 0.11.1 pkgs.libssh2 Client-side C library implementing the SSH2 protocol nixos-25.05 1.11.1 nixpkgs-25.05-darwin 1.11.1 nixos-25.05-small 1.11.1 nixos-unstable 1.11.1 nixos-unstable-small 1.11.1 nixpkgs-unstable 1.11.1 pkgs.libssh.x86_64-linux SSH client library nixos-unstable ??? nixos-unstable-small 0.11.1 pkgs.libssh.aarch64-linux SSH client library nixos-unstable ??? nixos-unstable-small 0.11.1 pkgs.libssh.x86_64-darwin SSH client library nixos-unstable ??? nixos-unstable-small 0.11.1 pkgs.libssh2.x86_64-linux Client-side C library implementing the SSH2 protocol nixos-unstable ??? nixos-unstable-small 1.11.1 pkgs.libssh.aarch64-darwin SSH client library nixos-unstable ??? nixos-unstable-small 0.11.1 pkgs.libssh2.aarch64-linux Client-side C library implementing the SSH2 protocol nixos-unstable ??? nixos-unstable-small 1.11.1 pkgs.libssh2.x86_64-darwin Client-side C library implementing the SSH2 protocol nixos-unstable ??? nixos-unstable-small 1.11.1 pkgs.haskellPackages.libssh libssh bindings nixos-25.05 0.1.0.0 nixpkgs-25.05-darwin 0.1.0.0 nixos-25.05-small 0.1.0.0 nixos-unstable 0.1.0.0 nixos-unstable-small 0.1.0.0 nixpkgs-unstable 0.1.0.0 pkgs.libssh2.aarch64-darwin Client-side C library implementing the SSH2 protocol nixos-unstable ??? nixos-unstable-small 1.11.1 pkgs.haskellPackages.libssh2 FFI bindings to libssh2 SSH2 client library (http://libssh2.org/) nixos-unstable 0.2.0.9 nixos-unstable-small 0.2.0.9 nixpkgs-unstable 0.2.0.9 pkgs.haskellPackages.libssh2-conduit Conduit wrappers for libssh2 FFI bindings (see libssh2 package) nixos-unstable 0.2.1 nixos-unstable-small 0.2.1 nixpkgs-unstable 0.2.1 pkgs.python311Packages.ansible-pylibssh Python bindings to client functionality of libssh specific to Ansible use case nixos-unstable 1.2.2 nixos-unstable-small 1.2.2 nixpkgs-unstable 1.2.2 pkgs.python312Packages.ansible-pylibssh Python bindings to client functionality of libssh specific to Ansible use case nixos-25.05 1.2.2 nixpkgs-25.05-darwin 1.2.2 nixos-25.05-small 1.2.2 nixos-unstable 1.2.2 nixos-unstable-small 1.2.2 nixpkgs-unstable 1.2.2 pkgs.python313Packages.ansible-pylibssh Python bindings to client functionality of libssh specific to Ansible use case nixos-25.05 1.2.2 nixpkgs-25.05-darwin 1.2.2 nixos-25.05-small 1.2.2 nixos-unstable 1.2.2 nixos-unstable-small 1.2.2 nixpkgs-unstable 1.2.2 pkgs.haskellPackages.libssh.x86_64-linux libssh bindings nixos-unstable ??? nixpkgs-unstable 0.1.0.0 pkgs.haskellPackages.libssh.aarch64-linux libssh bindings nixos-unstable ??? nixpkgs-unstable 0.1.0.0 pkgs.haskellPackages.libssh.x86_64-darwin libssh bindings nixos-unstable ??? nixpkgs-unstable 0.1.0.0 pkgs.haskellPackages.libssh2.x86_64-linux FFI bindings to libssh2 SSH2 client library (http://libssh2.org/) nixos-unstable ??? nixpkgs-unstable 0.2.0.9 pkgs.haskellPackages.libssh.aarch64-darwin libssh bindings nixos-unstable ??? nixpkgs-unstable 0.1.0.0 pkgs.haskellPackages.libssh2.aarch64-linux FFI bindings to libssh2 SSH2 client library (http://libssh2.org/) nixos-unstable ??? nixpkgs-unstable 0.2.0.9 pkgs.haskellPackages.libssh2.x86_64-darwin FFI bindings to libssh2 SSH2 client library (http://libssh2.org/) nixos-unstable ??? nixpkgs-unstable 0.2.0.9 pkgs.haskellPackages.libssh2.aarch64-darwin FFI bindings to libssh2 SSH2 client library (http://libssh2.org/) nixos-unstable ??? nixpkgs-unstable 0.2.0.9 pkgs.haskellPackages.libssh2-conduit.x86_64-linux Conduit wrappers for libssh2 FFI bindings (see libssh2 package) nixos-unstable ??? nixpkgs-unstable 0.2.1 pkgs.haskellPackages.libssh2-conduit.aarch64-linux Conduit wrappers for libssh2 FFI bindings (see libssh2 package) nixos-unstable ??? nixpkgs-unstable 0.2.1 pkgs.haskellPackages.libssh2-conduit.x86_64-darwin Conduit wrappers for libssh2 FFI bindings (see libssh2 package) nixos-unstable ??? nixpkgs-unstable 0.2.1 pkgs.haskellPackages.libssh2-conduit.aarch64-darwin Conduit wrappers for libssh2 FFI bindings (see libssh2 package) nixos-unstable ??? nixpkgs-unstable 0.2.1 pkgs.tests.pkg-config.defaultPkgConfigPackages.libssh2 Test whether libssh2-1.11.1 exposes pkg-config modules libssh2 nixos-25.05 libssh2 nixpkgs-25.05-darwin libssh2 nixos-25.05-small libssh2 nixos-unstable libssh2 nixos-unstable-small libssh2 nixpkgs-unstable libssh2 Package maintainers: 3 @geluk Johan Geluk <johan+nix@geluk.io> @svanderburg Sander van der Burg <s.vanderburg@tudelft.nl> @SuperSandro2000 Sandro Jäckel <sandro.jaeckel@gmail.com> CVE-2024-3019 8.8 HIGH CVSS version: 3.1 Attack vector (AV): ADJACENT_NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 3 months, 2 weeks ago Pcp: exposure of the redis server backend allows remote command execution via pmproxy A flaw was found in PCP. The default pmproxy configuration exposes the Redis server backend to the local network, allowing remote command execution with the privileges of the Redis user. This issue can only be exploited when pmproxy is running. By default, pmproxy is not running and needs to be started manually. The pmproxy service is usually started from the 'Metrics settings' page of the Cockpit web interface. This flaw affects PCP versions 4.3.4 and newer. pcp * * pkgs.pcp Command line peer-to-peer data transfer tool based on libp2p nixos-25.05 0.4.0 nixpkgs-25.05-darwin 0.4.0 nixos-25.05-small 0.4.0 nixos-unstable 0.4.0 nixos-unstable-small 0.4.0 nixpkgs-unstable 0.4.0 pkgs.ncmpcpp Featureful ncurses based MPD client inspired by ncmpc nixos-25.05 0.10.1 nixpkgs-25.05-darwin 0.10.1 nixos-25.05-small 0.10.1 nixos-unstable 0.10 nixos-unstable-small 0.10.1 nixpkgs-unstable 0.10.1 pkgs.libamqpcpp Library for communicating with a RabbitMQ server nixos-25.05 4.3.27 nixpkgs-25.05-darwin 4.3.27 nixos-25.05-small 4.3.27 nixos-unstable 4.3.27 nixos-unstable-small 4.3.27 nixpkgs-unstable 4.3.27 pkgs.python311Packages.pcpp C99 preprocessor written in pure Python nixos-unstable 1.30 nixos-unstable-small 1.30 nixpkgs-unstable 1.30 pkgs.python312Packages.pcpp C99 preprocessor written in pure Python nixos-25.05 1.30 nixpkgs-25.05-darwin 1.30 nixos-25.05-small 1.30 nixos-unstable 1.30 nixos-unstable-small 1.30 nixpkgs-unstable 1.30 pkgs.python313Packages.pcpp C99 preprocessor written in pure Python nixos-25.05 1.30 nixpkgs-25.05-darwin 1.30 nixos-25.05-small 1.30 nixos-unstable 1.30 nixos-unstable-small 1.30 nixpkgs-unstable 1.30 pkgs.python312Packages.pcpp.x86_64-linux C99 preprocessor written in pure Python nixos-unstable 1.30 pkgs.python312Packages.pcpp.aarch64-linux C99 preprocessor written in pure Python nixos-unstable 1.30 pkgs.python312Packages.pcpp.x86_64-darwin C99 preprocessor written in pure Python nixos-unstable 1.30 pkgs.python312Packages.pcpp.aarch64-darwin C99 preprocessor written in pure Python nixos-unstable 1.30 Package maintainers: 5 @MikePlayle Mike Playle <mike@mythik.co.uk> @k0ral Koral <koral@mailoo.org> @lovek323 Jason O'Conal <jason@oconal.id.au> @Rakesh4G Rakesh Gupta <rakeshgupta4u@gmail.com> @MatthewCroughan Matthew Croughan <matt@croughan.sh>
CVE-2023-6478 7.6 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): LOW Availability impact (A): LOW created 3 months, 2 weeks ago Xorg-x11-server: out-of-bounds memory read in rrchangeoutputproperty and rrchangeproviderproperty A flaw was found in xorg-server. A specially crafted request to RRChangeProviderProperty or RRChangeOutputProperty can trigger an integer overflow which may lead to a disclosure of sensitive information. tigervnc * xorg-x11-server * xorg-x11-server-Xwayland * pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-25.05 1.14.0 nixpkgs-25.05-darwin 1.14.0 nixos-25.05-small 1.14.0 nixos-unstable 1.15.0 nixos-unstable-small 1.15.0 nixpkgs-unstable 1.14.0
pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-25.05 1.14.0 nixpkgs-25.05-darwin 1.14.0 nixos-25.05-small 1.14.0 nixos-unstable 1.15.0 nixos-unstable-small 1.15.0 nixpkgs-unstable 1.14.0
CVE-2023-5367 7.8 HIGH CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 3 months, 2 weeks ago Xorg-x11-server: out-of-bounds write in xichangedeviceproperty/rrchangeoutputproperty A out-of-bounds write flaw was found in the xorg-x11-server. This issue occurs due to an incorrect calculation of a buffer offset when copying data stored in the heap in the XIChangeDeviceProperty function in Xi/xiproperty.c and in RRChangeOutputProperty function in randr/rrproperty.c, allowing for possible escalation of privileges or denial of service. tigervnc * xorg-x11-server * xorg-x11-server-Xwayland * pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-25.05 1.14.0 nixpkgs-25.05-darwin 1.14.0 nixos-25.05-small 1.14.0 nixos-unstable 1.15.0 nixos-unstable-small 1.15.0 nixpkgs-unstable 1.14.0
pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-25.05 1.14.0 nixpkgs-25.05-darwin 1.14.0 nixos-25.05-small 1.14.0 nixos-unstable 1.15.0 nixos-unstable-small 1.15.0 nixpkgs-unstable 1.14.0
CVE-2023-6377 7.8 HIGH CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 3 months, 2 weeks ago Xorg-x11-server: out-of-bounds memory reads/writes in xkb button actions A flaw was found in xorg-server. Querying or changing XKB button actions such as moving from a touchpad to a mouse can result in out-of-bounds memory reads and writes. This may allow local privilege escalation or possible remote code execution in cases where X11 forwarding is involved. tigervnc * xorg-x11-server * xorg-x11-server-Xwayland * pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-25.05 1.14.0 nixpkgs-25.05-darwin 1.14.0 nixos-25.05-small 1.14.0 nixos-unstable 1.15.0 nixos-unstable-small 1.15.0 nixpkgs-unstable 1.14.0
pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-25.05 1.14.0 nixpkgs-25.05-darwin 1.14.0 nixos-25.05-small 1.14.0 nixos-unstable 1.15.0 nixos-unstable-small 1.15.0 nixpkgs-unstable 1.14.0
CVE-2024-0229 7.8 HIGH CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 3 months, 2 weeks ago Xorg-x11-server: reattaching to different master device may lead to out-of-bounds memory access An out-of-bounds memory access flaw was found in the X.Org server. This issue can be triggered when a device frozen by a sync grab is reattached to a different master device. This issue may lead to an application crash, local privilege escalation (if the server runs with extended privileges), or remote code execution in SSH X11 forwarding environments. tigervnc * xorg-server <21.1.11 xorg-x11-server * xorg-x11-server-Xwayland * pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-25.05 1.14.0 nixpkgs-25.05-darwin 1.14.0 nixos-25.05-small 1.14.0 nixos-unstable 1.15.0 nixos-unstable-small 1.15.0 nixpkgs-unstable 1.14.0 pkgs.xorg.xvfb nixos-25.05 21.1.16 nixpkgs-25.05-darwin 21.1.16 nixos-25.05-small 21.1.16 nixos-unstable 21.1.14 nixos-unstable-small 21.1.16 nixpkgs-unstable 21.1.16 pkgs.xorg.xorgserver nixos-25.05 21.1.16 nixpkgs-25.05-darwin 21.1.16 nixos-25.05-small 21.1.16 nixos-unstable 21.1.14 nixos-unstable-small 21.1.16 nixpkgs-unstable 21.1.16
pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-25.05 1.14.0 nixpkgs-25.05-darwin 1.14.0 nixos-25.05-small 1.14.0 nixos-unstable 1.15.0 nixos-unstable-small 1.15.0 nixpkgs-unstable 1.14.0
pkgs.xorg.xvfb nixos-25.05 21.1.16 nixpkgs-25.05-darwin 21.1.16 nixos-25.05-small 21.1.16 nixos-unstable 21.1.14 nixos-unstable-small 21.1.16 nixpkgs-unstable 21.1.16
pkgs.xorg.xorgserver nixos-25.05 21.1.16 nixpkgs-25.05-darwin 21.1.16 nixos-25.05-small 21.1.16 nixos-unstable 21.1.14 nixos-unstable-small 21.1.16 nixpkgs-unstable 21.1.16
CVE-2023-5574 7.0 HIGH CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): HIGH Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 3 months, 2 weeks ago Xorg-x11-server: use-after-free bug in damagedestroy A use-after-free flaw was found in xorg-x11-server-Xvfb. This issue occurs in Xvfb with a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode). If the pointer is warped from a screen 1 to a screen 0, a use-after-free issue may be triggered during shutdown or reset of the Xvfb server, allowing for possible escalation of privileges or denial of service. tigervnc * xorg-x11-server xorg-x11-server-Xwayland pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-25.05 1.14.0 nixpkgs-25.05-darwin 1.14.0 nixos-25.05-small 1.14.0 nixos-unstable 1.15.0 nixos-unstable-small 1.15.0 nixpkgs-unstable 1.14.0
pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-25.05 1.14.0 nixpkgs-25.05-darwin 1.14.0 nixos-25.05-small 1.14.0 nixos-unstable 1.15.0 nixos-unstable-small 1.15.0 nixpkgs-unstable 1.14.0
CVE-2025-53512 6.5 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): NONE Availability impact (A): NONE created 3 months, 2 weeks ago Sensitive log retrieval in Juju The /log endpoint on a Juju controller lacked sufficient authorization checks, allowing unauthorized users to access debug messages that could contain sensitive information. juju <3.6.8 <2.9.52 pkgs.juju Open source modelling tool for operating software in the cloud nixos-25.05 3.6.5 nixpkgs-25.05-darwin 3.6.5 nixos-25.05-small 3.6.5 nixos-unstable 3.5.4 nixos-unstable-small 3.6.5 nixpkgs-unstable 3.6.5 pkgs.jujutsu Git-compatible DVCS that is both simple and powerful nixos-25.05 0.29.0 nixpkgs-25.05-darwin 0.29.0 nixos-25.05-small 0.29.0 nixos-unstable 0.24.0 nixos-unstable-small 0.29.0 nixpkgs-unstable 0.29.0 pkgs.jujuutils Utilities around FireWire devices connected to a Linux computer nixos-25.05 0.2 nixpkgs-25.05-darwin 0.2 nixos-25.05-small 0.2 nixos-unstable 0.2 nixos-unstable-small 0.2 nixpkgs-unstable 0.2 pkgs.juju.x86_64-linux Open source modelling tool for operating software in the cloud nixos-unstable ??? nixpkgs-unstable 3.5.4 pkgs.juju.aarch64-linux Open source modelling tool for operating software in the cloud nixos-unstable ??? nixpkgs-unstable 3.5.4 pkgs.juju.x86_64-darwin Open source modelling tool for operating software in the cloud nixos-unstable ??? nixpkgs-unstable 3.5.4 pkgs.juju.aarch64-darwin Open source modelling tool for operating software in the cloud nixos-unstable ??? nixpkgs-unstable 3.5.4 pkgs.jujutsu.x86_64-linux Git-compatible DVCS that is both simple and powerful nixos-unstable ??? nixpkgs-unstable 0.24.0 pkgs.jujutsu.aarch64-linux Git-compatible DVCS that is both simple and powerful nixos-unstable ??? nixpkgs-unstable 0.24.0 pkgs.jujutsu.x86_64-darwin Git-compatible DVCS that is both simple and powerful nixos-unstable ??? nixpkgs-unstable 0.24.0 pkgs.jujutsu.aarch64-darwin Git-compatible DVCS that is both simple and powerful nixos-unstable ??? nixpkgs-unstable 0.24.0 pkgs.jujuutils.x86_64-linux Utilities around FireWire devices connected to a Linux computer nixos-unstable ??? nixpkgs-unstable 0.2 pkgs.jujuutils.aarch64-linux Utilities around FireWire devices connected to a Linux computer nixos-unstable ??? nixpkgs-unstable 0.2 Package maintainers: 5 @RealityAnomaly Alex Zero <alex@arctarus.co.uk> @thoughtpolice Austin Seipp <aseipp@pobox.com> @0x4A6F Joachim Ernst <mail-maintainer@0x4A6F.dev> @emilazy Emily <nixpkgs@emily.moe> @bbigras Bruno Bigras <bigras.bruno@gmail.com>
pkgs.juju Open source modelling tool for operating software in the cloud nixos-25.05 3.6.5 nixpkgs-25.05-darwin 3.6.5 nixos-25.05-small 3.6.5 nixos-unstable 3.5.4 nixos-unstable-small 3.6.5 nixpkgs-unstable 3.6.5
pkgs.jujutsu Git-compatible DVCS that is both simple and powerful nixos-25.05 0.29.0 nixpkgs-25.05-darwin 0.29.0 nixos-25.05-small 0.29.0 nixos-unstable 0.24.0 nixos-unstable-small 0.29.0 nixpkgs-unstable 0.29.0
pkgs.jujuutils Utilities around FireWire devices connected to a Linux computer nixos-25.05 0.2 nixpkgs-25.05-darwin 0.2 nixos-25.05-small 0.2 nixos-unstable 0.2 nixos-unstable-small 0.2 nixpkgs-unstable 0.2
pkgs.juju.x86_64-linux Open source modelling tool for operating software in the cloud nixos-unstable ??? nixpkgs-unstable 3.5.4
pkgs.juju.aarch64-linux Open source modelling tool for operating software in the cloud nixos-unstable ??? nixpkgs-unstable 3.5.4
pkgs.juju.x86_64-darwin Open source modelling tool for operating software in the cloud nixos-unstable ??? nixpkgs-unstable 3.5.4
pkgs.juju.aarch64-darwin Open source modelling tool for operating software in the cloud nixos-unstable ??? nixpkgs-unstable 3.5.4
pkgs.jujutsu.x86_64-linux Git-compatible DVCS that is both simple and powerful nixos-unstable ??? nixpkgs-unstable 0.24.0
pkgs.jujutsu.aarch64-linux Git-compatible DVCS that is both simple and powerful nixos-unstable ??? nixpkgs-unstable 0.24.0
pkgs.jujutsu.x86_64-darwin Git-compatible DVCS that is both simple and powerful nixos-unstable ??? nixpkgs-unstable 0.24.0
pkgs.jujutsu.aarch64-darwin Git-compatible DVCS that is both simple and powerful nixos-unstable ??? nixpkgs-unstable 0.24.0
pkgs.jujuutils.x86_64-linux Utilities around FireWire devices connected to a Linux computer nixos-unstable ??? nixpkgs-unstable 0.2
pkgs.jujuutils.aarch64-linux Utilities around FireWire devices connected to a Linux computer nixos-unstable ??? nixpkgs-unstable 0.2
CVE-2025-0928 8.8 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 3 months, 2 weeks ago Arbitrary executable upload via authenticated endpoint In Juju versions prior to 3.6.8 and 2.9.52, any authenticated controller user was allowed to upload arbitrary agent binaries to any model or to the controller itself, without verifying model membership or requiring explicit permissions. This enabled the distribution of poisoned binaries to new or upgraded machines, potentially resulting in remote code execution. juju <3.6.8 <2.9.52 pkgs.juju Open source modelling tool for operating software in the cloud nixos-25.05 3.6.5 nixpkgs-25.05-darwin 3.6.5 nixos-25.05-small 3.6.5 nixos-unstable 3.5.4 nixos-unstable-small 3.6.5 nixpkgs-unstable 3.6.5 pkgs.jujutsu Git-compatible DVCS that is both simple and powerful nixos-25.05 0.29.0 nixpkgs-25.05-darwin 0.29.0 nixos-25.05-small 0.29.0 nixos-unstable 0.24.0 nixos-unstable-small 0.29.0 nixpkgs-unstable 0.29.0 pkgs.jujuutils Utilities around FireWire devices connected to a Linux computer nixos-25.05 0.2 nixpkgs-25.05-darwin 0.2 nixos-25.05-small 0.2 nixos-unstable 0.2 nixos-unstable-small 0.2 nixpkgs-unstable 0.2 pkgs.juju.x86_64-linux Open source modelling tool for operating software in the cloud nixos-unstable ??? nixpkgs-unstable 3.5.4 pkgs.juju.aarch64-linux Open source modelling tool for operating software in the cloud nixos-unstable ??? nixpkgs-unstable 3.5.4 pkgs.juju.x86_64-darwin Open source modelling tool for operating software in the cloud nixos-unstable ??? nixpkgs-unstable 3.5.4 pkgs.juju.aarch64-darwin Open source modelling tool for operating software in the cloud nixos-unstable ??? nixpkgs-unstable 3.5.4 pkgs.jujutsu.x86_64-linux Git-compatible DVCS that is both simple and powerful nixos-unstable ??? nixpkgs-unstable 0.24.0 pkgs.jujutsu.aarch64-linux Git-compatible DVCS that is both simple and powerful nixos-unstable ??? nixpkgs-unstable 0.24.0 pkgs.jujutsu.x86_64-darwin Git-compatible DVCS that is both simple and powerful nixos-unstable ??? nixpkgs-unstable 0.24.0 pkgs.jujutsu.aarch64-darwin Git-compatible DVCS that is both simple and powerful nixos-unstable ??? nixpkgs-unstable 0.24.0 pkgs.jujuutils.x86_64-linux Utilities around FireWire devices connected to a Linux computer nixos-unstable ??? nixpkgs-unstable 0.2 pkgs.jujuutils.aarch64-linux Utilities around FireWire devices connected to a Linux computer nixos-unstable ??? nixpkgs-unstable 0.2 Package maintainers: 5 @RealityAnomaly Alex Zero <alex@arctarus.co.uk> @thoughtpolice Austin Seipp <aseipp@pobox.com> @0x4A6F Joachim Ernst <mail-maintainer@0x4A6F.dev> @emilazy Emily <nixpkgs@emily.moe> @bbigras Bruno Bigras <bigras.bruno@gmail.com>
pkgs.juju Open source modelling tool for operating software in the cloud nixos-25.05 3.6.5 nixpkgs-25.05-darwin 3.6.5 nixos-25.05-small 3.6.5 nixos-unstable 3.5.4 nixos-unstable-small 3.6.5 nixpkgs-unstable 3.6.5
pkgs.jujutsu Git-compatible DVCS that is both simple and powerful nixos-25.05 0.29.0 nixpkgs-25.05-darwin 0.29.0 nixos-25.05-small 0.29.0 nixos-unstable 0.24.0 nixos-unstable-small 0.29.0 nixpkgs-unstable 0.29.0
pkgs.jujuutils Utilities around FireWire devices connected to a Linux computer nixos-25.05 0.2 nixpkgs-25.05-darwin 0.2 nixos-25.05-small 0.2 nixos-unstable 0.2 nixos-unstable-small 0.2 nixpkgs-unstable 0.2
pkgs.juju.x86_64-linux Open source modelling tool for operating software in the cloud nixos-unstable ??? nixpkgs-unstable 3.5.4
pkgs.juju.aarch64-linux Open source modelling tool for operating software in the cloud nixos-unstable ??? nixpkgs-unstable 3.5.4
pkgs.juju.x86_64-darwin Open source modelling tool for operating software in the cloud nixos-unstable ??? nixpkgs-unstable 3.5.4
pkgs.juju.aarch64-darwin Open source modelling tool for operating software in the cloud nixos-unstable ??? nixpkgs-unstable 3.5.4
pkgs.jujutsu.x86_64-linux Git-compatible DVCS that is both simple and powerful nixos-unstable ??? nixpkgs-unstable 0.24.0
pkgs.jujutsu.aarch64-linux Git-compatible DVCS that is both simple and powerful nixos-unstable ??? nixpkgs-unstable 0.24.0
pkgs.jujutsu.x86_64-darwin Git-compatible DVCS that is both simple and powerful nixos-unstable ??? nixpkgs-unstable 0.24.0
pkgs.jujutsu.aarch64-darwin Git-compatible DVCS that is both simple and powerful nixos-unstable ??? nixpkgs-unstable 0.24.0
pkgs.jujuutils.x86_64-linux Utilities around FireWire devices connected to a Linux computer nixos-unstable ??? nixpkgs-unstable 0.2
pkgs.jujuutils.aarch64-linux Utilities around FireWire devices connected to a Linux computer nixos-unstable ??? nixpkgs-unstable 0.2
CVE-2025-53513 8.8 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 3 months, 2 weeks ago Zip slip vulnerability in Juju The /charms endpoint on a Juju controller lacked sufficient authorization checks, allowing any user with an account on the controller to upload a charm. Uploading a malicious charm that exploits a Zip Slip vulnerability could allow an attacker to gain access to a machine running a unit through the affected charm. juju <3.6.8 <2.9.52 pkgs.juju Open source modelling tool for operating software in the cloud nixos-25.05 3.6.5 nixpkgs-25.05-darwin 3.6.5 nixos-25.05-small 3.6.5 nixos-unstable 3.5.4 nixos-unstable-small 3.6.5 nixpkgs-unstable 3.6.5 pkgs.jujutsu Git-compatible DVCS that is both simple and powerful nixos-25.05 0.29.0 nixpkgs-25.05-darwin 0.29.0 nixos-25.05-small 0.29.0 nixos-unstable 0.24.0 nixos-unstable-small 0.29.0 nixpkgs-unstable 0.29.0 pkgs.jujuutils Utilities around FireWire devices connected to a Linux computer nixos-25.05 0.2 nixpkgs-25.05-darwin 0.2 nixos-25.05-small 0.2 nixos-unstable 0.2 nixos-unstable-small 0.2 nixpkgs-unstable 0.2 pkgs.juju.x86_64-linux Open source modelling tool for operating software in the cloud nixos-unstable ??? nixpkgs-unstable 3.5.4 pkgs.juju.aarch64-linux Open source modelling tool for operating software in the cloud nixos-unstable ??? nixpkgs-unstable 3.5.4 pkgs.juju.x86_64-darwin Open source modelling tool for operating software in the cloud nixos-unstable ??? nixpkgs-unstable 3.5.4 pkgs.juju.aarch64-darwin Open source modelling tool for operating software in the cloud nixos-unstable ??? nixpkgs-unstable 3.5.4 pkgs.jujutsu.x86_64-linux Git-compatible DVCS that is both simple and powerful nixos-unstable ??? nixpkgs-unstable 0.24.0 pkgs.jujutsu.aarch64-linux Git-compatible DVCS that is both simple and powerful nixos-unstable ??? nixpkgs-unstable 0.24.0 pkgs.jujutsu.x86_64-darwin Git-compatible DVCS that is both simple and powerful nixos-unstable ??? nixpkgs-unstable 0.24.0 pkgs.jujutsu.aarch64-darwin Git-compatible DVCS that is both simple and powerful nixos-unstable ??? nixpkgs-unstable 0.24.0 pkgs.jujuutils.x86_64-linux Utilities around FireWire devices connected to a Linux computer nixos-unstable ??? nixpkgs-unstable 0.2 pkgs.jujuutils.aarch64-linux Utilities around FireWire devices connected to a Linux computer nixos-unstable ??? nixpkgs-unstable 0.2 Package maintainers: 5 @RealityAnomaly Alex Zero <alex@arctarus.co.uk> @thoughtpolice Austin Seipp <aseipp@pobox.com> @0x4A6F Joachim Ernst <mail-maintainer@0x4A6F.dev> @emilazy Emily <nixpkgs@emily.moe> @bbigras Bruno Bigras <bigras.bruno@gmail.com>
pkgs.juju Open source modelling tool for operating software in the cloud nixos-25.05 3.6.5 nixpkgs-25.05-darwin 3.6.5 nixos-25.05-small 3.6.5 nixos-unstable 3.5.4 nixos-unstable-small 3.6.5 nixpkgs-unstable 3.6.5
pkgs.jujutsu Git-compatible DVCS that is both simple and powerful nixos-25.05 0.29.0 nixpkgs-25.05-darwin 0.29.0 nixos-25.05-small 0.29.0 nixos-unstable 0.24.0 nixos-unstable-small 0.29.0 nixpkgs-unstable 0.29.0
pkgs.jujuutils Utilities around FireWire devices connected to a Linux computer nixos-25.05 0.2 nixpkgs-25.05-darwin 0.2 nixos-25.05-small 0.2 nixos-unstable 0.2 nixos-unstable-small 0.2 nixpkgs-unstable 0.2
pkgs.juju.x86_64-linux Open source modelling tool for operating software in the cloud nixos-unstable ??? nixpkgs-unstable 3.5.4
pkgs.juju.aarch64-linux Open source modelling tool for operating software in the cloud nixos-unstable ??? nixpkgs-unstable 3.5.4
pkgs.juju.x86_64-darwin Open source modelling tool for operating software in the cloud nixos-unstable ??? nixpkgs-unstable 3.5.4
pkgs.juju.aarch64-darwin Open source modelling tool for operating software in the cloud nixos-unstable ??? nixpkgs-unstable 3.5.4
pkgs.jujutsu.x86_64-linux Git-compatible DVCS that is both simple and powerful nixos-unstable ??? nixpkgs-unstable 0.24.0
pkgs.jujutsu.aarch64-linux Git-compatible DVCS that is both simple and powerful nixos-unstable ??? nixpkgs-unstable 0.24.0
pkgs.jujutsu.x86_64-darwin Git-compatible DVCS that is both simple and powerful nixos-unstable ??? nixpkgs-unstable 0.24.0
pkgs.jujutsu.aarch64-darwin Git-compatible DVCS that is both simple and powerful nixos-unstable ??? nixpkgs-unstable 0.24.0
pkgs.jujuutils.x86_64-linux Utilities around FireWire devices connected to a Linux computer nixos-unstable ??? nixpkgs-unstable 0.2
pkgs.jujuutils.aarch64-linux Utilities around FireWire devices connected to a Linux computer nixos-unstable ??? nixpkgs-unstable 0.2
CVE-2025-5987 5.0 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 3 months, 2 weeks ago Libssh: invalid return code for chacha20 poly1305 with openssl backend A flaw was found in libssh when using the ChaCha20 cipher with the OpenSSL library. If an attacker manages to exhaust the heap space, this error is not detected and may lead to libssh using a partially initialized cipher context. This occurs because the OpenSSL error code returned aliases with the SSH_OK code, resulting in libssh not properly detecting the error returned by the OpenSSL library. This issue can lead to undefined behavior, including compromised data confidentiality and integrity or crashes. rhcos libssh <0.11.2 libssh2 pkgs.libssh SSH client library nixos-25.05 0.11.1 nixpkgs-25.05-darwin 0.11.1 nixos-25.05-small 0.11.1 nixos-unstable 0.11.1 nixos-unstable-small 0.11.1 nixpkgs-unstable 0.11.1 pkgs.libssh2 Client-side C library implementing the SSH2 protocol nixos-25.05 1.11.1 nixpkgs-25.05-darwin 1.11.1 nixos-25.05-small 1.11.1 nixos-unstable 1.11.1 nixos-unstable-small 1.11.1 nixpkgs-unstable 1.11.1 pkgs.libssh.x86_64-linux SSH client library nixos-unstable ??? nixos-unstable-small 0.11.1 pkgs.libssh.aarch64-linux SSH client library nixos-unstable ??? nixos-unstable-small 0.11.1 pkgs.libssh.x86_64-darwin SSH client library nixos-unstable ??? nixos-unstable-small 0.11.1 pkgs.libssh2.x86_64-linux Client-side C library implementing the SSH2 protocol nixos-unstable ??? nixos-unstable-small 1.11.1 pkgs.libssh.aarch64-darwin SSH client library nixos-unstable ??? nixos-unstable-small 0.11.1 pkgs.libssh2.aarch64-linux Client-side C library implementing the SSH2 protocol nixos-unstable ??? nixos-unstable-small 1.11.1 pkgs.libssh2.x86_64-darwin Client-side C library implementing the SSH2 protocol nixos-unstable ??? nixos-unstable-small 1.11.1 pkgs.haskellPackages.libssh libssh bindings nixos-25.05 0.1.0.0 nixpkgs-25.05-darwin 0.1.0.0 nixos-25.05-small 0.1.0.0 nixos-unstable 0.1.0.0 nixos-unstable-small 0.1.0.0 nixpkgs-unstable 0.1.0.0 pkgs.libssh2.aarch64-darwin Client-side C library implementing the SSH2 protocol nixos-unstable ??? nixos-unstable-small 1.11.1 pkgs.haskellPackages.libssh2 FFI bindings to libssh2 SSH2 client library (http://libssh2.org/) nixos-unstable 0.2.0.9 nixos-unstable-small 0.2.0.9 nixpkgs-unstable 0.2.0.9 pkgs.haskellPackages.libssh2-conduit Conduit wrappers for libssh2 FFI bindings (see libssh2 package) nixos-unstable 0.2.1 nixos-unstable-small 0.2.1 nixpkgs-unstable 0.2.1 pkgs.python311Packages.ansible-pylibssh Python bindings to client functionality of libssh specific to Ansible use case nixos-unstable 1.2.2 nixos-unstable-small 1.2.2 nixpkgs-unstable 1.2.2 pkgs.python312Packages.ansible-pylibssh Python bindings to client functionality of libssh specific to Ansible use case nixos-25.05 1.2.2 nixpkgs-25.05-darwin 1.2.2 nixos-25.05-small 1.2.2 nixos-unstable 1.2.2 nixos-unstable-small 1.2.2 nixpkgs-unstable 1.2.2 pkgs.python313Packages.ansible-pylibssh Python bindings to client functionality of libssh specific to Ansible use case nixos-25.05 1.2.2 nixpkgs-25.05-darwin 1.2.2 nixos-25.05-small 1.2.2 nixos-unstable 1.2.2 nixos-unstable-small 1.2.2 nixpkgs-unstable 1.2.2 pkgs.haskellPackages.libssh.x86_64-linux libssh bindings nixos-unstable ??? nixpkgs-unstable 0.1.0.0 pkgs.haskellPackages.libssh.aarch64-linux libssh bindings nixos-unstable ??? nixpkgs-unstable 0.1.0.0 pkgs.haskellPackages.libssh.x86_64-darwin libssh bindings nixos-unstable ??? nixpkgs-unstable 0.1.0.0 pkgs.haskellPackages.libssh2.x86_64-linux FFI bindings to libssh2 SSH2 client library (http://libssh2.org/) nixos-unstable ??? nixpkgs-unstable 0.2.0.9 pkgs.haskellPackages.libssh.aarch64-darwin libssh bindings nixos-unstable ??? nixpkgs-unstable 0.1.0.0 pkgs.haskellPackages.libssh2.aarch64-linux FFI bindings to libssh2 SSH2 client library (http://libssh2.org/) nixos-unstable ??? nixpkgs-unstable 0.2.0.9 pkgs.haskellPackages.libssh2.x86_64-darwin FFI bindings to libssh2 SSH2 client library (http://libssh2.org/) nixos-unstable ??? nixpkgs-unstable 0.2.0.9 pkgs.haskellPackages.libssh2.aarch64-darwin FFI bindings to libssh2 SSH2 client library (http://libssh2.org/) nixos-unstable ??? nixpkgs-unstable 0.2.0.9 pkgs.haskellPackages.libssh2-conduit.x86_64-linux Conduit wrappers for libssh2 FFI bindings (see libssh2 package) nixos-unstable ??? nixpkgs-unstable 0.2.1 pkgs.haskellPackages.libssh2-conduit.aarch64-linux Conduit wrappers for libssh2 FFI bindings (see libssh2 package) nixos-unstable ??? nixpkgs-unstable 0.2.1 pkgs.haskellPackages.libssh2-conduit.x86_64-darwin Conduit wrappers for libssh2 FFI bindings (see libssh2 package) nixos-unstable ??? nixpkgs-unstable 0.2.1 pkgs.haskellPackages.libssh2-conduit.aarch64-darwin Conduit wrappers for libssh2 FFI bindings (see libssh2 package) nixos-unstable ??? nixpkgs-unstable 0.2.1 pkgs.tests.pkg-config.defaultPkgConfigPackages.libssh2 Test whether libssh2-1.11.1 exposes pkg-config modules libssh2 nixos-25.05 libssh2 nixpkgs-25.05-darwin libssh2 nixos-25.05-small libssh2 nixos-unstable libssh2 nixos-unstable-small libssh2 nixpkgs-unstable libssh2 Package maintainers: 3 @geluk Johan Geluk <johan+nix@geluk.io> @svanderburg Sander van der Burg <s.vanderburg@tudelft.nl> @SuperSandro2000 Sandro Jäckel <sandro.jaeckel@gmail.com>
pkgs.libssh SSH client library nixos-25.05 0.11.1 nixpkgs-25.05-darwin 0.11.1 nixos-25.05-small 0.11.1 nixos-unstable 0.11.1 nixos-unstable-small 0.11.1 nixpkgs-unstable 0.11.1
pkgs.libssh2 Client-side C library implementing the SSH2 protocol nixos-25.05 1.11.1 nixpkgs-25.05-darwin 1.11.1 nixos-25.05-small 1.11.1 nixos-unstable 1.11.1 nixos-unstable-small 1.11.1 nixpkgs-unstable 1.11.1
pkgs.libssh2.x86_64-linux Client-side C library implementing the SSH2 protocol nixos-unstable ??? nixos-unstable-small 1.11.1
pkgs.libssh2.aarch64-linux Client-side C library implementing the SSH2 protocol nixos-unstable ??? nixos-unstable-small 1.11.1
pkgs.libssh2.x86_64-darwin Client-side C library implementing the SSH2 protocol nixos-unstable ??? nixos-unstable-small 1.11.1
pkgs.haskellPackages.libssh libssh bindings nixos-25.05 0.1.0.0 nixpkgs-25.05-darwin 0.1.0.0 nixos-25.05-small 0.1.0.0 nixos-unstable 0.1.0.0 nixos-unstable-small 0.1.0.0 nixpkgs-unstable 0.1.0.0
pkgs.libssh2.aarch64-darwin Client-side C library implementing the SSH2 protocol nixos-unstable ??? nixos-unstable-small 1.11.1
pkgs.haskellPackages.libssh2 FFI bindings to libssh2 SSH2 client library (http://libssh2.org/) nixos-unstable 0.2.0.9 nixos-unstable-small 0.2.0.9 nixpkgs-unstable 0.2.0.9
pkgs.haskellPackages.libssh2-conduit Conduit wrappers for libssh2 FFI bindings (see libssh2 package) nixos-unstable 0.2.1 nixos-unstable-small 0.2.1 nixpkgs-unstable 0.2.1
pkgs.python311Packages.ansible-pylibssh Python bindings to client functionality of libssh specific to Ansible use case nixos-unstable 1.2.2 nixos-unstable-small 1.2.2 nixpkgs-unstable 1.2.2
pkgs.python312Packages.ansible-pylibssh Python bindings to client functionality of libssh specific to Ansible use case nixos-25.05 1.2.2 nixpkgs-25.05-darwin 1.2.2 nixos-25.05-small 1.2.2 nixos-unstable 1.2.2 nixos-unstable-small 1.2.2 nixpkgs-unstable 1.2.2
pkgs.python313Packages.ansible-pylibssh Python bindings to client functionality of libssh specific to Ansible use case nixos-25.05 1.2.2 nixpkgs-25.05-darwin 1.2.2 nixos-25.05-small 1.2.2 nixos-unstable 1.2.2 nixos-unstable-small 1.2.2 nixpkgs-unstable 1.2.2
pkgs.haskellPackages.libssh.aarch64-linux libssh bindings nixos-unstable ??? nixpkgs-unstable 0.1.0.0
pkgs.haskellPackages.libssh.x86_64-darwin libssh bindings nixos-unstable ??? nixpkgs-unstable 0.1.0.0
pkgs.haskellPackages.libssh2.x86_64-linux FFI bindings to libssh2 SSH2 client library (http://libssh2.org/) nixos-unstable ??? nixpkgs-unstable 0.2.0.9
pkgs.haskellPackages.libssh.aarch64-darwin libssh bindings nixos-unstable ??? nixpkgs-unstable 0.1.0.0
pkgs.haskellPackages.libssh2.aarch64-linux FFI bindings to libssh2 SSH2 client library (http://libssh2.org/) nixos-unstable ??? nixpkgs-unstable 0.2.0.9
pkgs.haskellPackages.libssh2.x86_64-darwin FFI bindings to libssh2 SSH2 client library (http://libssh2.org/) nixos-unstable ??? nixpkgs-unstable 0.2.0.9
pkgs.haskellPackages.libssh2.aarch64-darwin FFI bindings to libssh2 SSH2 client library (http://libssh2.org/) nixos-unstable ??? nixpkgs-unstable 0.2.0.9
pkgs.haskellPackages.libssh2-conduit.x86_64-linux Conduit wrappers for libssh2 FFI bindings (see libssh2 package) nixos-unstable ??? nixpkgs-unstable 0.2.1
pkgs.haskellPackages.libssh2-conduit.aarch64-linux Conduit wrappers for libssh2 FFI bindings (see libssh2 package) nixos-unstable ??? nixpkgs-unstable 0.2.1
pkgs.haskellPackages.libssh2-conduit.x86_64-darwin Conduit wrappers for libssh2 FFI bindings (see libssh2 package) nixos-unstable ??? nixpkgs-unstable 0.2.1
pkgs.haskellPackages.libssh2-conduit.aarch64-darwin Conduit wrappers for libssh2 FFI bindings (see libssh2 package) nixos-unstable ??? nixpkgs-unstable 0.2.1
pkgs.tests.pkg-config.defaultPkgConfigPackages.libssh2 Test whether libssh2-1.11.1 exposes pkg-config modules libssh2 nixos-25.05 libssh2 nixpkgs-25.05-darwin libssh2 nixos-25.05-small libssh2 nixos-unstable libssh2 nixos-unstable-small libssh2 nixpkgs-unstable libssh2
CVE-2024-3019 8.8 HIGH CVSS version: 3.1 Attack vector (AV): ADJACENT_NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 3 months, 2 weeks ago Pcp: exposure of the redis server backend allows remote command execution via pmproxy A flaw was found in PCP. The default pmproxy configuration exposes the Redis server backend to the local network, allowing remote command execution with the privileges of the Redis user. This issue can only be exploited when pmproxy is running. By default, pmproxy is not running and needs to be started manually. The pmproxy service is usually started from the 'Metrics settings' page of the Cockpit web interface. This flaw affects PCP versions 4.3.4 and newer. pcp * * pkgs.pcp Command line peer-to-peer data transfer tool based on libp2p nixos-25.05 0.4.0 nixpkgs-25.05-darwin 0.4.0 nixos-25.05-small 0.4.0 nixos-unstable 0.4.0 nixos-unstable-small 0.4.0 nixpkgs-unstable 0.4.0 pkgs.ncmpcpp Featureful ncurses based MPD client inspired by ncmpc nixos-25.05 0.10.1 nixpkgs-25.05-darwin 0.10.1 nixos-25.05-small 0.10.1 nixos-unstable 0.10 nixos-unstable-small 0.10.1 nixpkgs-unstable 0.10.1 pkgs.libamqpcpp Library for communicating with a RabbitMQ server nixos-25.05 4.3.27 nixpkgs-25.05-darwin 4.3.27 nixos-25.05-small 4.3.27 nixos-unstable 4.3.27 nixos-unstable-small 4.3.27 nixpkgs-unstable 4.3.27 pkgs.python311Packages.pcpp C99 preprocessor written in pure Python nixos-unstable 1.30 nixos-unstable-small 1.30 nixpkgs-unstable 1.30 pkgs.python312Packages.pcpp C99 preprocessor written in pure Python nixos-25.05 1.30 nixpkgs-25.05-darwin 1.30 nixos-25.05-small 1.30 nixos-unstable 1.30 nixos-unstable-small 1.30 nixpkgs-unstable 1.30 pkgs.python313Packages.pcpp C99 preprocessor written in pure Python nixos-25.05 1.30 nixpkgs-25.05-darwin 1.30 nixos-25.05-small 1.30 nixos-unstable 1.30 nixos-unstable-small 1.30 nixpkgs-unstable 1.30 pkgs.python312Packages.pcpp.x86_64-linux C99 preprocessor written in pure Python nixos-unstable 1.30 pkgs.python312Packages.pcpp.aarch64-linux C99 preprocessor written in pure Python nixos-unstable 1.30 pkgs.python312Packages.pcpp.x86_64-darwin C99 preprocessor written in pure Python nixos-unstable 1.30 pkgs.python312Packages.pcpp.aarch64-darwin C99 preprocessor written in pure Python nixos-unstable 1.30 Package maintainers: 5 @MikePlayle Mike Playle <mike@mythik.co.uk> @k0ral Koral <koral@mailoo.org> @lovek323 Jason O'Conal <jason@oconal.id.au> @Rakesh4G Rakesh Gupta <rakeshgupta4u@gmail.com> @MatthewCroughan Matthew Croughan <matt@croughan.sh>
pkgs.pcp Command line peer-to-peer data transfer tool based on libp2p nixos-25.05 0.4.0 nixpkgs-25.05-darwin 0.4.0 nixos-25.05-small 0.4.0 nixos-unstable 0.4.0 nixos-unstable-small 0.4.0 nixpkgs-unstable 0.4.0
pkgs.ncmpcpp Featureful ncurses based MPD client inspired by ncmpc nixos-25.05 0.10.1 nixpkgs-25.05-darwin 0.10.1 nixos-25.05-small 0.10.1 nixos-unstable 0.10 nixos-unstable-small 0.10.1 nixpkgs-unstable 0.10.1
pkgs.libamqpcpp Library for communicating with a RabbitMQ server nixos-25.05 4.3.27 nixpkgs-25.05-darwin 4.3.27 nixos-25.05-small 4.3.27 nixos-unstable 4.3.27 nixos-unstable-small 4.3.27 nixpkgs-unstable 4.3.27
pkgs.python311Packages.pcpp C99 preprocessor written in pure Python nixos-unstable 1.30 nixos-unstable-small 1.30 nixpkgs-unstable 1.30
pkgs.python312Packages.pcpp C99 preprocessor written in pure Python nixos-25.05 1.30 nixpkgs-25.05-darwin 1.30 nixos-25.05-small 1.30 nixos-unstable 1.30 nixos-unstable-small 1.30 nixpkgs-unstable 1.30
pkgs.python313Packages.pcpp C99 preprocessor written in pure Python nixos-25.05 1.30 nixpkgs-25.05-darwin 1.30 nixos-25.05-small 1.30 nixos-unstable 1.30 nixos-unstable-small 1.30 nixpkgs-unstable 1.30
pkgs.python312Packages.pcpp.aarch64-linux C99 preprocessor written in pure Python nixos-unstable 1.30
pkgs.python312Packages.pcpp.x86_64-darwin C99 preprocessor written in pure Python nixos-unstable 1.30
pkgs.python312Packages.pcpp.aarch64-darwin C99 preprocessor written in pure Python nixos-unstable 1.30