Dismissed suggestions Untriaged suggestions Draft issues Published issues Automatically generated suggestions Create Draft to queue a suggestion for refinement. Dismiss to remove a suggestion from the queue. CVE-2023-4042 5.5 MEDIUM CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): HIGH created 3 months, 3 weeks ago Ghostscript: incomplete fix for cve-2020-16305 A flaw was found in ghostscript. The fix for CVE-2020-16305 in ghostscript was not included in RHSA-2021:1852-06 advisory as it was claimed to be. This issue only affects the ghostscript package as shipped with Red Hat Enterprise Linux 8. ghostscript * gimp:flatpak/ghostscript pkgs.ghostscriptX PostScript interpreter (mainline version) nixos-25.05 10.05.1 nixpkgs-25.05-darwin 10.05.1 nixos-25.05-small 10.05.1 nixos-unstable 10.04.0 nixos-unstable-small 10.05.1 nixpkgs-unstable 10.05.1 pkgs.ghostscript_headless PostScript interpreter (mainline version) nixos-25.05 10.05.1 nixpkgs-25.05-darwin 10.05.1 nixos-25.05-small 10.05.1 nixos-unstable 10.04.0 nixos-unstable-small 10.05.1 nixpkgs-unstable 10.05.1 pkgs.python312Packages.ghostscript Interface to the Ghostscript C-API using ctypes. nixos-25.05 0.7 nixpkgs-25.05-darwin 0.7 nixos-25.05-small 0.7 nixos-unstable 0.7 nixos-unstable-small 0.7 nixpkgs-unstable 0.7 pkgs.python313Packages.ghostscript Interface to the Ghostscript C-API using ctypes. nixos-25.05 0.7 nixpkgs-25.05-darwin 0.7 nixos-25.05-small 0.7 nixos-unstable 0.7 nixos-unstable-small 0.7 nixpkgs-unstable 0.7 pkgs.tests.texlive.dvipng.ghostscript nixos-unstable ??? nixos-unstable-small nixpkgs-unstable pkgs.haskellPackages.ghostscript-parallel Let Ghostscript render pages in parallel nixos-25.05 0.0.1 nixpkgs-25.05-darwin 0.0.1 nixos-25.05-small 0.0.1 nixos-unstable 0.0.1 nixos-unstable-small 0.0.1 nixpkgs-unstable 0.0.1 Package maintainers: 2 @tobim Tobias Mayer <nix@tobim.fastmail.fm> @flokli Florian Klink <flokli@flokli.de> CVE-2025-53331 7.1 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): CHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 3 months, 4 weeks ago WordPress RSS Digest plugin <= 1.5 - Cross Site Request Forgery (CSRF) Vulnerability Cross-Site Request Forgery (CSRF) vulnerability in samcharrington RSS Digest allows Stored XSS. This issue affects RSS Digest: from n/a through 1.5. rss-digest =<1.5 pkgs.matcha-rss-digest Daily digest generator from a list of RSS feeds nixos-25.05 0.7.1 nixpkgs-25.05-darwin 0.7.1 nixos-25.05-small 0.7.1 nixos-unstable 0.6.1 nixos-unstable-small 0.7.1 nixpkgs-unstable 0.7.1 Package maintainers: 1 @foo-dogsquared Gabriel Arazas <foodogsquared@foodogsquared.one> CVE-2025-53200 4.3 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): LOW Availability impact (A): NONE created 3 months, 4 weeks ago WordPress ChatBot plugin <= 6.7.3 - Broken Access Control Vulnerability Missing Authorization vulnerability in QuantumCloud ChatBot allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ChatBot: from n/a through 6.7.3. chatbot =<6.7.3 pkgs.gnomeExtensions.penguin-ai-chatbot A GNOME Shell extension that provides a chatbot interface using various LLM providers, including Anthropic, OpenAI, Gemini, and OpenRouter. Features include multiple provider support, customizable models, chat history, customizable appearance, a keyboard shortcut, and copy-to-clipboard functionality. nixos-25.05 22 nixpkgs-25.05-darwin 22 nixos-25.05-small 22 nixos-unstable 22 nixos-unstable-small 22 nixpkgs-unstable 22 Package maintainers: 1 @honnip Jung seungwoo <me@honnip.page> CVE-2025-52826 8.8 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 3 months, 4 weeks ago WordPress Sala theme <= 1.1.3 - PHP Object Injection Vulnerability Deserialization of Untrusted Data vulnerability in uxper Sala allows Object Injection. This issue affects Sala: from n/a through 1.1.3. sala =<1.1.3 pkgs.python311Packages.datasalad Pure-Python library with a collection of utilities for working with Git and git-annex nixos-unstable 0.4.0 nixos-unstable-small 0.4.0 nixpkgs-unstable 0.4.0 pkgs.python312Packages.datasalad Pure-Python library with a collection of utilities for working with Git and git-annex nixos-25.05 0.4.0 nixpkgs-25.05-darwin 0.4.0 nixos-25.05-small 0.4.0 nixos-unstable 0.4.0 nixos-unstable-small 0.4.0 nixpkgs-unstable 0.4.0 pkgs.python313Packages.datasalad Pure-Python library with a collection of utilities for working with Git and git-annex nixos-25.05 0.4.0 nixpkgs-25.05-darwin 0.4.0 nixos-25.05-small 0.4.0 nixos-unstable 0.4.0 nixos-unstable-small 0.4.0 nixpkgs-unstable 0.4.0 pkgs.python311Packages.schema-salad Semantic Annotations for Linked Avro Data nixos-unstable 8.7.20241021092521 nixos-unstable-small 8.7.20241021092521 nixpkgs-unstable 8.7.20241021092521 pkgs.python312Packages.schema-salad Semantic Annotations for Linked Avro Data nixos-25.05 8.8.20250205075315 nixpkgs-25.05-darwin 8.8.20250205075315 nixos-25.05-small 8.8.20250205075315 nixos-unstable 8.8.20250205075315 nixos-unstable-small 8.7.20241021092521 nixpkgs-unstable 8.8.20250205075315 pkgs.python313Packages.schema-salad Semantic Annotations for Linked Avro Data nixos-25.05 8.8.20250205075315 nixpkgs-25.05-darwin 8.8.20250205075315 nixos-25.05-small 8.8.20250205075315 nixos-unstable 8.8.20250205075315 nixos-unstable-small 8.8.20250205075315 nixpkgs-unstable 8.8.20250205075315 pkgs.python312Packages.schema-salad.x86_64-linux Semantic Annotations for Linked Avro Data nixos-unstable 8.7.20241021092521 pkgs.python312Packages.schema-salad.aarch64-linux Semantic Annotations for Linked Avro Data nixos-unstable 8.7.20241021092521 pkgs.python312Packages.schema-salad.x86_64-darwin Semantic Annotations for Linked Avro Data nixos-unstable 8.7.20241021092521 pkgs.python312Packages.schema-salad.aarch64-darwin Semantic Annotations for Linked Avro Data nixos-unstable 8.7.20241021092521 Package maintainers: 2 @gador Florian Brandes <florian.brandes@posteo.de> @veprbl Dmitry Kalinkin <veprbl@gmail.com> CVE-2025-52816 8.1 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 3 months, 4 weeks ago WordPress Zita theme <= 1.6.5 - Local File Inclusion Vulnerability Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themehunk Zita allows PHP Local File Inclusion. This issue affects Zita: from n/a through 1.6.5. zita =<1.6.5 pkgs.zitadel Identity and access management platform nixos-25.05 2.71.7 nixpkgs-25.05-darwin 2.71.7 nixos-25.05-small 2.71.7 nixos-unstable 2.58.3 nixos-unstable-small 2.58.3 nixpkgs-unstable 2.71.7 pkgs.zita-at1 Autotuner Jack application to correct the pitch of vocal tracks nixos-25.05 at1-0.8.2 nixpkgs-25.05-darwin at1-0.8.2 nixos-25.05-small at1-0.8.2 nixos-unstable at1-0.8.2 nixos-unstable-small at1-0.8.2 nixpkgs-unstable at1-0.8.2 pkgs.zita-ajbridge Connect additional ALSA devices to JACK nixos-25.05 0.8.4 nixpkgs-25.05-darwin 0.8.4 nixos-25.05-small 0.8.4 nixos-unstable 0.8.4 nixos-unstable-small 0.8.4 nixpkgs-unstable 0.8.4 pkgs.zita-njbridge command line Jack clients to transmit full quality multichannel audio over a local IP network nixos-25.05 0.4.8 nixpkgs-25.05-darwin 0.4.8 nixos-25.05-small 0.4.8 nixos-unstable 0.4.8 nixos-unstable-small 0.4.8 nixpkgs-unstable 0.4.8 pkgs.zitadel-tools Helper tools for zitadel nixos-25.05 0.5.0 nixpkgs-25.05-darwin 0.5.0 nixos-25.05-small 0.5.0 nixos-unstable 0.5.0 nixos-unstable-small 0.5.0 nixpkgs-unstable 0.5.0 pkgs.zita-alsa-pcmi Successor of clalsadrv, provides easy access to ALSA PCM devices nixos-25.05 0.6.1 nixpkgs-25.05-darwin 0.6.1 nixos-25.05-small 0.6.1 nixos-unstable 0.6.1 nixos-unstable-small 0.6.1 nixpkgs-unstable 0.6.1 pkgs.zita-convolver Convolution library by Fons Adriaensen nixos-25.05 4.0.3 nixpkgs-25.05-darwin 4.0.3 nixos-25.05-small 4.0.3 nixos-unstable 4.0.3 nixos-unstable-small 4.0.3 nixpkgs-unstable 4.0.3 pkgs.zita-resampler Resample library by Fons Adriaensen nixos-25.05 1.8.0 nixpkgs-25.05-darwin 1.8.0 nixos-25.05-small 1.8.0 nixos-unstable 1.8.0 nixos-unstable-small 1.8.0 nixpkgs-unstable 1.8.0 Package maintainers: 3 @orivej Orivej Desh <orivej@gmx.fr> @magnetophon Bart Brouns <bart@magnetophon.nl> @nrabulinski Nikodem Rabuliński <1337-nix@nrab.lol> CVE-2024-6174 8.8 HIGH CVSS version: 3.1 Attack vector (AV): ADJACENT_NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 3 months, 4 weeks ago When a non-x86 platform is detected, cloud-init grants root access … When a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP address. To prevent this, cloud-init default configurations disable platform enumeration. cloud-init <25.1.3 pkgs.cloud-init Provides configuration and customization of cloud instance nixos-unstable 24.2 nixpkgs-unstable 24.2 Package maintainers: 2 @jfroche Jean-François Roche <jfroche@pyxel.be> @illustris Harikrishnan R <me@illustris.tech> CVE-2024-11584 5.9 MEDIUM CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 3 months, 4 weeks ago cloud-init through 25.1.2 includes the systemd socket unit cloud-init-hotplugd.socket with … cloud-init through 25.1.2 includes the systemd socket unit cloud-init-hotplugd.socket with default SocketMode that grants 0666 permissions, making it world-writable. This is used for the "/run/cloud-init/hook-hotplug-cmd" FIFO. An unprivileged user could trigger hotplug-hook commands. cloud-init <25.1.3 pkgs.cloud-init Provides configuration and customization of cloud instance nixos-25.05 24.2 nixpkgs-25.05-darwin 24.2 nixos-25.05-small 24.2 nixos-unstable 24.2 nixos-unstable-small 24.2 nixpkgs-unstable 24.2 Package maintainers: 2 @jfroche Jean-François Roche <jfroche@pyxel.be> @illustris Harikrishnan R <me@illustris.tech> CVE-2024-6126 3.2 LOW CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): REQUIRED Scope (S): CHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): LOW created 3 months, 4 weeks ago Cockpit: authenticated user can kill any process when enabling pam_env's user_readenv option A flaw was found in the cockpit package. This flaw allows an authenticated user to kill any process when enabling the pam_env's user_readenv option, which leads to a denial of service (DoS) attack. cockpit * pkgs.cockpit Web-based graphical interface for servers nixos-25.05 338 nixpkgs-25.05-darwin 338 nixos-25.05-small 338 nixos-unstable 329.1 nixos-unstable-small 340 nixpkgs-unstable 338 pkgs.emacsPackages.test-cockpit nixos-unstable 20240604.1943 nixos-unstable-small 20240604.1943 nixpkgs-unstable 20240604.1943 Package maintainers: 1 @lucasew Lucas Eduardo Wendt <lucas59356@gmail.com> CVE-2025-5318 5.4 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): NONE created 4 months ago Libssh: out-of-bounds read in sftp_handle() A flaw was found in the libssh library. An out-of-bounds read can be triggered in the sftp_handle function due to an incorrect comparison check that permits the function to access memory beyond the valid handle list and to return an invalid pointer, which is used in further processing. This vulnerability allows an authenticated remote attacker to potentially read unintended memory regions, exposing sensitive information or affect service behavior. rhcos libssh pkgs.libssh SSH client library nixos-25.05 0.11.1 nixpkgs-25.05-darwin 0.11.1 nixos-25.05-small 0.11.1 nixos-unstable 0.11.1 nixos-unstable-small 0.11.1 nixpkgs-unstable 0.11.1 pkgs.libssh2 Client-side C library implementing the SSH2 protocol nixos-25.05 1.11.1 nixpkgs-25.05-darwin 1.11.1 nixos-25.05-small 1.11.1 nixos-unstable 1.11.1 nixos-unstable-small 1.11.1 nixpkgs-unstable 1.11.1 pkgs.libssh.x86_64-linux SSH client library nixos-unstable ??? nixos-unstable-small 0.11.1 pkgs.libssh.aarch64-linux SSH client library nixos-unstable ??? nixos-unstable-small 0.11.1 pkgs.libssh.x86_64-darwin SSH client library nixos-unstable ??? nixos-unstable-small 0.11.1 pkgs.libssh2.x86_64-linux Client-side C library implementing the SSH2 protocol nixos-unstable ??? nixos-unstable-small 1.11.1 pkgs.libssh.aarch64-darwin SSH client library nixos-unstable ??? nixos-unstable-small 0.11.1 pkgs.libssh2.aarch64-linux Client-side C library implementing the SSH2 protocol nixos-unstable ??? nixos-unstable-small 1.11.1 pkgs.libssh2.x86_64-darwin Client-side C library implementing the SSH2 protocol nixos-unstable ??? nixos-unstable-small 1.11.1 pkgs.haskellPackages.libssh libssh bindings nixos-25.05 0.1.0.0 nixpkgs-25.05-darwin 0.1.0.0 nixos-25.05-small 0.1.0.0 nixos-unstable 0.1.0.0 nixos-unstable-small 0.1.0.0 nixpkgs-unstable 0.1.0.0 pkgs.libssh2.aarch64-darwin Client-side C library implementing the SSH2 protocol nixos-unstable ??? nixos-unstable-small 1.11.1 pkgs.haskellPackages.libssh2 FFI bindings to libssh2 SSH2 client library (http://libssh2.org/) nixos-unstable 0.2.0.9 nixos-unstable-small 0.2.0.9 nixpkgs-unstable 0.2.0.9 pkgs.haskellPackages.libssh2-conduit Conduit wrappers for libssh2 FFI bindings (see libssh2 package) nixos-unstable 0.2.1 nixos-unstable-small 0.2.1 nixpkgs-unstable 0.2.1 pkgs.python311Packages.ansible-pylibssh Python bindings to client functionality of libssh specific to Ansible use case nixos-unstable 1.2.2 nixos-unstable-small 1.2.2 nixpkgs-unstable 1.2.2 pkgs.python312Packages.ansible-pylibssh Python bindings to client functionality of libssh specific to Ansible use case nixos-25.05 1.2.2 nixpkgs-25.05-darwin 1.2.2 nixos-25.05-small 1.2.2 nixos-unstable 1.2.2 nixos-unstable-small 1.2.2 nixpkgs-unstable 1.2.2 pkgs.python313Packages.ansible-pylibssh Python bindings to client functionality of libssh specific to Ansible use case nixos-25.05 1.2.2 nixpkgs-25.05-darwin 1.2.2 nixos-25.05-small 1.2.2 nixos-unstable 1.2.2 nixos-unstable-small 1.2.2 nixpkgs-unstable 1.2.2 pkgs.haskellPackages.libssh.x86_64-linux libssh bindings nixos-unstable ??? nixpkgs-unstable 0.1.0.0 pkgs.haskellPackages.libssh.aarch64-linux libssh bindings nixos-unstable ??? nixpkgs-unstable 0.1.0.0 pkgs.haskellPackages.libssh.x86_64-darwin libssh bindings nixos-unstable ??? nixpkgs-unstable 0.1.0.0 pkgs.haskellPackages.libssh2.x86_64-linux FFI bindings to libssh2 SSH2 client library (http://libssh2.org/) nixos-unstable ??? nixpkgs-unstable 0.2.0.9 pkgs.haskellPackages.libssh.aarch64-darwin libssh bindings nixos-unstable ??? nixpkgs-unstable 0.1.0.0 pkgs.haskellPackages.libssh2.aarch64-linux FFI bindings to libssh2 SSH2 client library (http://libssh2.org/) nixos-unstable ??? nixpkgs-unstable 0.2.0.9 pkgs.haskellPackages.libssh2.x86_64-darwin FFI bindings to libssh2 SSH2 client library (http://libssh2.org/) nixos-unstable ??? nixpkgs-unstable 0.2.0.9 pkgs.haskellPackages.libssh2.aarch64-darwin FFI bindings to libssh2 SSH2 client library (http://libssh2.org/) nixos-unstable ??? nixpkgs-unstable 0.2.0.9 pkgs.haskellPackages.libssh2-conduit.x86_64-linux Conduit wrappers for libssh2 FFI bindings (see libssh2 package) nixos-unstable ??? nixpkgs-unstable 0.2.1 pkgs.haskellPackages.libssh2-conduit.aarch64-linux Conduit wrappers for libssh2 FFI bindings (see libssh2 package) nixos-unstable ??? nixpkgs-unstable 0.2.1 pkgs.haskellPackages.libssh2-conduit.x86_64-darwin Conduit wrappers for libssh2 FFI bindings (see libssh2 package) nixos-unstable ??? nixpkgs-unstable 0.2.1 pkgs.haskellPackages.libssh2-conduit.aarch64-darwin Conduit wrappers for libssh2 FFI bindings (see libssh2 package) nixos-unstable ??? nixpkgs-unstable 0.2.1 pkgs.tests.pkg-config.defaultPkgConfigPackages.libssh2 Test whether libssh2-1.11.1 exposes pkg-config modules libssh2 nixos-25.05 libssh2 nixpkgs-25.05-darwin libssh2 nixos-25.05-small libssh2 nixos-unstable libssh2 nixos-unstable-small libssh2 nixpkgs-unstable libssh2 Package maintainers: 3 @geluk Johan Geluk <johan+nix@geluk.io> @svanderburg Sander van der Burg <s.vanderburg@tudelft.nl> @SuperSandro2000 Sandro Jäckel <sandro.jaeckel@gmail.com> CVE-2025-6547 created 4 months ago On Node.js < 3, pbkdf2 silently disregards Uint8Array input, returning static keys Improper Input Validation vulnerability in pbkdf2 allows Signature Spoofing by Improper Validation.This issue affects pbkdf2: <=3.1.2. pbkdf2 ==<=3.1.2 pkgs.fastpbkdf2 Fast PBKDF2-HMAC-{SHA1,SHA256,SHA512} implementation in C nixos-25.05 1.0.0 nixpkgs-25.05-darwin 1.0.0 nixos-25.05-small 1.0.0 nixos-unstable 1.0.0 nixos-unstable-small 1.0.0 nixpkgs-unstable 1.0.0 pkgs.python311Packages.pbkdf2 nixos-unstable pbkdf2-1.3 nixos-unstable-small pbkdf2-1.3 nixpkgs-unstable pbkdf2-1.3 pkgs.python312Packages.pbkdf2 nixos-25.05 pbkdf2-1.3 nixpkgs-25.05-darwin pbkdf2-1.3 nixos-25.05-small pbkdf2-1.3 nixos-unstable pbkdf2-1.3 nixos-unstable-small pbkdf2-1.3 nixpkgs-unstable pbkdf2-1.3 pkgs.python313Packages.pbkdf2 nixos-25.05 pbkdf2-1.3 nixpkgs-25.05-darwin pbkdf2-1.3 nixos-25.05-small pbkdf2-1.3 nixos-unstable pbkdf2-1.3 nixos-unstable-small pbkdf2-1.3 nixpkgs-unstable pbkdf2-1.3 pkgs.emacsPackages.kaesar-pbkdf2 nixos-unstable pbkdf2-20230626.2314 nixos-unstable-small pbkdf2-20230626.2314 nixpkgs-unstable pbkdf2-20230626.2314 pkgs.python311Packages.fastpbkdf2 Python bindings for fastpbkdf2 nixos-unstable fastpbkdf2-0.2 nixos-unstable-small fastpbkdf2-0.2 nixpkgs-unstable fastpbkdf2-0.2 pkgs.python312Packages.fastpbkdf2 Python bindings for fastpbkdf2 nixos-25.05 fastpbkdf2-0.2 nixpkgs-25.05-darwin fastpbkdf2-0.2 nixos-25.05-small fastpbkdf2-0.2 nixos-unstable fastpbkdf2-0.2 nixos-unstable-small fastpbkdf2-0.2 nixpkgs-unstable fastpbkdf2-0.2 pkgs.python313Packages.fastpbkdf2 Python bindings for fastpbkdf2 nixos-25.05 fastpbkdf2-0.2 nixpkgs-25.05-darwin fastpbkdf2-0.2 nixos-25.05-small fastpbkdf2-0.2 nixos-unstable fastpbkdf2-0.2 nixos-unstable-small fastpbkdf2-0.2 nixpkgs-unstable fastpbkdf2-0.2 pkgs.chickenPackages_5.chickenEggs.pbkdf2 Password-Based Key Derivation Function as defined in RFC2898 nixos-25.05 pbkdf2-1.3 nixpkgs-25.05-darwin pbkdf2-1.3 nixos-25.05-small pbkdf2-1.3 nixos-unstable pbkdf2-1.3 nixos-unstable-small pbkdf2-1.3 nixpkgs-unstable pbkdf2-1.3 pkgs.python312Packages.pbkdf2.x86_64-linux nixos-unstable pbkdf2-1.3 pkgs.python312Packages.pbkdf2.aarch64-linux nixos-unstable pbkdf2-1.3 pkgs.python312Packages.pbkdf2.x86_64-darwin nixos-unstable pbkdf2-1.3 pkgs.python312Packages.pbkdf2.aarch64-darwin nixos-unstable pbkdf2-1.3 Package maintainers: 3 @domenkozar Domen Kozar <domen@dev.si> @ledif Adam Fidel <refuse@gmail.com> @jqueiroz Jonathan Queiroz <nixos@johnjq.com>
CVE-2023-4042 5.5 MEDIUM CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): HIGH created 3 months, 3 weeks ago Ghostscript: incomplete fix for cve-2020-16305 A flaw was found in ghostscript. The fix for CVE-2020-16305 in ghostscript was not included in RHSA-2021:1852-06 advisory as it was claimed to be. This issue only affects the ghostscript package as shipped with Red Hat Enterprise Linux 8. ghostscript * gimp:flatpak/ghostscript pkgs.ghostscriptX PostScript interpreter (mainline version) nixos-25.05 10.05.1 nixpkgs-25.05-darwin 10.05.1 nixos-25.05-small 10.05.1 nixos-unstable 10.04.0 nixos-unstable-small 10.05.1 nixpkgs-unstable 10.05.1 pkgs.ghostscript_headless PostScript interpreter (mainline version) nixos-25.05 10.05.1 nixpkgs-25.05-darwin 10.05.1 nixos-25.05-small 10.05.1 nixos-unstable 10.04.0 nixos-unstable-small 10.05.1 nixpkgs-unstable 10.05.1 pkgs.python312Packages.ghostscript Interface to the Ghostscript C-API using ctypes. nixos-25.05 0.7 nixpkgs-25.05-darwin 0.7 nixos-25.05-small 0.7 nixos-unstable 0.7 nixos-unstable-small 0.7 nixpkgs-unstable 0.7 pkgs.python313Packages.ghostscript Interface to the Ghostscript C-API using ctypes. nixos-25.05 0.7 nixpkgs-25.05-darwin 0.7 nixos-25.05-small 0.7 nixos-unstable 0.7 nixos-unstable-small 0.7 nixpkgs-unstable 0.7 pkgs.tests.texlive.dvipng.ghostscript nixos-unstable ??? nixos-unstable-small nixpkgs-unstable pkgs.haskellPackages.ghostscript-parallel Let Ghostscript render pages in parallel nixos-25.05 0.0.1 nixpkgs-25.05-darwin 0.0.1 nixos-25.05-small 0.0.1 nixos-unstable 0.0.1 nixos-unstable-small 0.0.1 nixpkgs-unstable 0.0.1 Package maintainers: 2 @tobim Tobias Mayer <nix@tobim.fastmail.fm> @flokli Florian Klink <flokli@flokli.de>
pkgs.ghostscriptX PostScript interpreter (mainline version) nixos-25.05 10.05.1 nixpkgs-25.05-darwin 10.05.1 nixos-25.05-small 10.05.1 nixos-unstable 10.04.0 nixos-unstable-small 10.05.1 nixpkgs-unstable 10.05.1
pkgs.ghostscript_headless PostScript interpreter (mainline version) nixos-25.05 10.05.1 nixpkgs-25.05-darwin 10.05.1 nixos-25.05-small 10.05.1 nixos-unstable 10.04.0 nixos-unstable-small 10.05.1 nixpkgs-unstable 10.05.1
pkgs.python312Packages.ghostscript Interface to the Ghostscript C-API using ctypes. nixos-25.05 0.7 nixpkgs-25.05-darwin 0.7 nixos-25.05-small 0.7 nixos-unstable 0.7 nixos-unstable-small 0.7 nixpkgs-unstable 0.7
pkgs.python313Packages.ghostscript Interface to the Ghostscript C-API using ctypes. nixos-25.05 0.7 nixpkgs-25.05-darwin 0.7 nixos-25.05-small 0.7 nixos-unstable 0.7 nixos-unstable-small 0.7 nixpkgs-unstable 0.7
pkgs.haskellPackages.ghostscript-parallel Let Ghostscript render pages in parallel nixos-25.05 0.0.1 nixpkgs-25.05-darwin 0.0.1 nixos-25.05-small 0.0.1 nixos-unstable 0.0.1 nixos-unstable-small 0.0.1 nixpkgs-unstable 0.0.1
CVE-2025-53331 7.1 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): CHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 3 months, 4 weeks ago WordPress RSS Digest plugin <= 1.5 - Cross Site Request Forgery (CSRF) Vulnerability Cross-Site Request Forgery (CSRF) vulnerability in samcharrington RSS Digest allows Stored XSS. This issue affects RSS Digest: from n/a through 1.5. rss-digest =<1.5 pkgs.matcha-rss-digest Daily digest generator from a list of RSS feeds nixos-25.05 0.7.1 nixpkgs-25.05-darwin 0.7.1 nixos-25.05-small 0.7.1 nixos-unstable 0.6.1 nixos-unstable-small 0.7.1 nixpkgs-unstable 0.7.1 Package maintainers: 1 @foo-dogsquared Gabriel Arazas <foodogsquared@foodogsquared.one>
pkgs.matcha-rss-digest Daily digest generator from a list of RSS feeds nixos-25.05 0.7.1 nixpkgs-25.05-darwin 0.7.1 nixos-25.05-small 0.7.1 nixos-unstable 0.6.1 nixos-unstable-small 0.7.1 nixpkgs-unstable 0.7.1
CVE-2025-53200 4.3 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): LOW Availability impact (A): NONE created 3 months, 4 weeks ago WordPress ChatBot plugin <= 6.7.3 - Broken Access Control Vulnerability Missing Authorization vulnerability in QuantumCloud ChatBot allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ChatBot: from n/a through 6.7.3. chatbot =<6.7.3 pkgs.gnomeExtensions.penguin-ai-chatbot A GNOME Shell extension that provides a chatbot interface using various LLM providers, including Anthropic, OpenAI, Gemini, and OpenRouter. Features include multiple provider support, customizable models, chat history, customizable appearance, a keyboard shortcut, and copy-to-clipboard functionality. nixos-25.05 22 nixpkgs-25.05-darwin 22 nixos-25.05-small 22 nixos-unstable 22 nixos-unstable-small 22 nixpkgs-unstable 22 Package maintainers: 1 @honnip Jung seungwoo <me@honnip.page>
pkgs.gnomeExtensions.penguin-ai-chatbot A GNOME Shell extension that provides a chatbot interface using various LLM providers, including Anthropic, OpenAI, Gemini, and OpenRouter. Features include multiple provider support, customizable models, chat history, customizable appearance, a keyboard shortcut, and copy-to-clipboard functionality. nixos-25.05 22 nixpkgs-25.05-darwin 22 nixos-25.05-small 22 nixos-unstable 22 nixos-unstable-small 22 nixpkgs-unstable 22
CVE-2025-52826 8.8 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 3 months, 4 weeks ago WordPress Sala theme <= 1.1.3 - PHP Object Injection Vulnerability Deserialization of Untrusted Data vulnerability in uxper Sala allows Object Injection. This issue affects Sala: from n/a through 1.1.3. sala =<1.1.3 pkgs.python311Packages.datasalad Pure-Python library with a collection of utilities for working with Git and git-annex nixos-unstable 0.4.0 nixos-unstable-small 0.4.0 nixpkgs-unstable 0.4.0 pkgs.python312Packages.datasalad Pure-Python library with a collection of utilities for working with Git and git-annex nixos-25.05 0.4.0 nixpkgs-25.05-darwin 0.4.0 nixos-25.05-small 0.4.0 nixos-unstable 0.4.0 nixos-unstable-small 0.4.0 nixpkgs-unstable 0.4.0 pkgs.python313Packages.datasalad Pure-Python library with a collection of utilities for working with Git and git-annex nixos-25.05 0.4.0 nixpkgs-25.05-darwin 0.4.0 nixos-25.05-small 0.4.0 nixos-unstable 0.4.0 nixos-unstable-small 0.4.0 nixpkgs-unstable 0.4.0 pkgs.python311Packages.schema-salad Semantic Annotations for Linked Avro Data nixos-unstable 8.7.20241021092521 nixos-unstable-small 8.7.20241021092521 nixpkgs-unstable 8.7.20241021092521 pkgs.python312Packages.schema-salad Semantic Annotations for Linked Avro Data nixos-25.05 8.8.20250205075315 nixpkgs-25.05-darwin 8.8.20250205075315 nixos-25.05-small 8.8.20250205075315 nixos-unstable 8.8.20250205075315 nixos-unstable-small 8.7.20241021092521 nixpkgs-unstable 8.8.20250205075315 pkgs.python313Packages.schema-salad Semantic Annotations for Linked Avro Data nixos-25.05 8.8.20250205075315 nixpkgs-25.05-darwin 8.8.20250205075315 nixos-25.05-small 8.8.20250205075315 nixos-unstable 8.8.20250205075315 nixos-unstable-small 8.8.20250205075315 nixpkgs-unstable 8.8.20250205075315 pkgs.python312Packages.schema-salad.x86_64-linux Semantic Annotations for Linked Avro Data nixos-unstable 8.7.20241021092521 pkgs.python312Packages.schema-salad.aarch64-linux Semantic Annotations for Linked Avro Data nixos-unstable 8.7.20241021092521 pkgs.python312Packages.schema-salad.x86_64-darwin Semantic Annotations for Linked Avro Data nixos-unstable 8.7.20241021092521 pkgs.python312Packages.schema-salad.aarch64-darwin Semantic Annotations for Linked Avro Data nixos-unstable 8.7.20241021092521 Package maintainers: 2 @gador Florian Brandes <florian.brandes@posteo.de> @veprbl Dmitry Kalinkin <veprbl@gmail.com>
pkgs.python311Packages.datasalad Pure-Python library with a collection of utilities for working with Git and git-annex nixos-unstable 0.4.0 nixos-unstable-small 0.4.0 nixpkgs-unstable 0.4.0
pkgs.python312Packages.datasalad Pure-Python library with a collection of utilities for working with Git and git-annex nixos-25.05 0.4.0 nixpkgs-25.05-darwin 0.4.0 nixos-25.05-small 0.4.0 nixos-unstable 0.4.0 nixos-unstable-small 0.4.0 nixpkgs-unstable 0.4.0
pkgs.python313Packages.datasalad Pure-Python library with a collection of utilities for working with Git and git-annex nixos-25.05 0.4.0 nixpkgs-25.05-darwin 0.4.0 nixos-25.05-small 0.4.0 nixos-unstable 0.4.0 nixos-unstable-small 0.4.0 nixpkgs-unstable 0.4.0
pkgs.python311Packages.schema-salad Semantic Annotations for Linked Avro Data nixos-unstable 8.7.20241021092521 nixos-unstable-small 8.7.20241021092521 nixpkgs-unstable 8.7.20241021092521
pkgs.python312Packages.schema-salad Semantic Annotations for Linked Avro Data nixos-25.05 8.8.20250205075315 nixpkgs-25.05-darwin 8.8.20250205075315 nixos-25.05-small 8.8.20250205075315 nixos-unstable 8.8.20250205075315 nixos-unstable-small 8.7.20241021092521 nixpkgs-unstable 8.8.20250205075315
pkgs.python313Packages.schema-salad Semantic Annotations for Linked Avro Data nixos-25.05 8.8.20250205075315 nixpkgs-25.05-darwin 8.8.20250205075315 nixos-25.05-small 8.8.20250205075315 nixos-unstable 8.8.20250205075315 nixos-unstable-small 8.8.20250205075315 nixpkgs-unstable 8.8.20250205075315
pkgs.python312Packages.schema-salad.x86_64-linux Semantic Annotations for Linked Avro Data nixos-unstable 8.7.20241021092521
pkgs.python312Packages.schema-salad.aarch64-linux Semantic Annotations for Linked Avro Data nixos-unstable 8.7.20241021092521
pkgs.python312Packages.schema-salad.x86_64-darwin Semantic Annotations for Linked Avro Data nixos-unstable 8.7.20241021092521
pkgs.python312Packages.schema-salad.aarch64-darwin Semantic Annotations for Linked Avro Data nixos-unstable 8.7.20241021092521
CVE-2025-52816 8.1 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 3 months, 4 weeks ago WordPress Zita theme <= 1.6.5 - Local File Inclusion Vulnerability Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themehunk Zita allows PHP Local File Inclusion. This issue affects Zita: from n/a through 1.6.5. zita =<1.6.5 pkgs.zitadel Identity and access management platform nixos-25.05 2.71.7 nixpkgs-25.05-darwin 2.71.7 nixos-25.05-small 2.71.7 nixos-unstable 2.58.3 nixos-unstable-small 2.58.3 nixpkgs-unstable 2.71.7 pkgs.zita-at1 Autotuner Jack application to correct the pitch of vocal tracks nixos-25.05 at1-0.8.2 nixpkgs-25.05-darwin at1-0.8.2 nixos-25.05-small at1-0.8.2 nixos-unstable at1-0.8.2 nixos-unstable-small at1-0.8.2 nixpkgs-unstable at1-0.8.2 pkgs.zita-ajbridge Connect additional ALSA devices to JACK nixos-25.05 0.8.4 nixpkgs-25.05-darwin 0.8.4 nixos-25.05-small 0.8.4 nixos-unstable 0.8.4 nixos-unstable-small 0.8.4 nixpkgs-unstable 0.8.4 pkgs.zita-njbridge command line Jack clients to transmit full quality multichannel audio over a local IP network nixos-25.05 0.4.8 nixpkgs-25.05-darwin 0.4.8 nixos-25.05-small 0.4.8 nixos-unstable 0.4.8 nixos-unstable-small 0.4.8 nixpkgs-unstable 0.4.8 pkgs.zitadel-tools Helper tools for zitadel nixos-25.05 0.5.0 nixpkgs-25.05-darwin 0.5.0 nixos-25.05-small 0.5.0 nixos-unstable 0.5.0 nixos-unstable-small 0.5.0 nixpkgs-unstable 0.5.0 pkgs.zita-alsa-pcmi Successor of clalsadrv, provides easy access to ALSA PCM devices nixos-25.05 0.6.1 nixpkgs-25.05-darwin 0.6.1 nixos-25.05-small 0.6.1 nixos-unstable 0.6.1 nixos-unstable-small 0.6.1 nixpkgs-unstable 0.6.1 pkgs.zita-convolver Convolution library by Fons Adriaensen nixos-25.05 4.0.3 nixpkgs-25.05-darwin 4.0.3 nixos-25.05-small 4.0.3 nixos-unstable 4.0.3 nixos-unstable-small 4.0.3 nixpkgs-unstable 4.0.3 pkgs.zita-resampler Resample library by Fons Adriaensen nixos-25.05 1.8.0 nixpkgs-25.05-darwin 1.8.0 nixos-25.05-small 1.8.0 nixos-unstable 1.8.0 nixos-unstable-small 1.8.0 nixpkgs-unstable 1.8.0 Package maintainers: 3 @orivej Orivej Desh <orivej@gmx.fr> @magnetophon Bart Brouns <bart@magnetophon.nl> @nrabulinski Nikodem Rabuliński <1337-nix@nrab.lol>
pkgs.zitadel Identity and access management platform nixos-25.05 2.71.7 nixpkgs-25.05-darwin 2.71.7 nixos-25.05-small 2.71.7 nixos-unstable 2.58.3 nixos-unstable-small 2.58.3 nixpkgs-unstable 2.71.7
pkgs.zita-at1 Autotuner Jack application to correct the pitch of vocal tracks nixos-25.05 at1-0.8.2 nixpkgs-25.05-darwin at1-0.8.2 nixos-25.05-small at1-0.8.2 nixos-unstable at1-0.8.2 nixos-unstable-small at1-0.8.2 nixpkgs-unstable at1-0.8.2
pkgs.zita-ajbridge Connect additional ALSA devices to JACK nixos-25.05 0.8.4 nixpkgs-25.05-darwin 0.8.4 nixos-25.05-small 0.8.4 nixos-unstable 0.8.4 nixos-unstable-small 0.8.4 nixpkgs-unstable 0.8.4
pkgs.zita-njbridge command line Jack clients to transmit full quality multichannel audio over a local IP network nixos-25.05 0.4.8 nixpkgs-25.05-darwin 0.4.8 nixos-25.05-small 0.4.8 nixos-unstable 0.4.8 nixos-unstable-small 0.4.8 nixpkgs-unstable 0.4.8
pkgs.zitadel-tools Helper tools for zitadel nixos-25.05 0.5.0 nixpkgs-25.05-darwin 0.5.0 nixos-25.05-small 0.5.0 nixos-unstable 0.5.0 nixos-unstable-small 0.5.0 nixpkgs-unstable 0.5.0
pkgs.zita-alsa-pcmi Successor of clalsadrv, provides easy access to ALSA PCM devices nixos-25.05 0.6.1 nixpkgs-25.05-darwin 0.6.1 nixos-25.05-small 0.6.1 nixos-unstable 0.6.1 nixos-unstable-small 0.6.1 nixpkgs-unstable 0.6.1
pkgs.zita-convolver Convolution library by Fons Adriaensen nixos-25.05 4.0.3 nixpkgs-25.05-darwin 4.0.3 nixos-25.05-small 4.0.3 nixos-unstable 4.0.3 nixos-unstable-small 4.0.3 nixpkgs-unstable 4.0.3
pkgs.zita-resampler Resample library by Fons Adriaensen nixos-25.05 1.8.0 nixpkgs-25.05-darwin 1.8.0 nixos-25.05-small 1.8.0 nixos-unstable 1.8.0 nixos-unstable-small 1.8.0 nixpkgs-unstable 1.8.0
CVE-2024-6174 8.8 HIGH CVSS version: 3.1 Attack vector (AV): ADJACENT_NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 3 months, 4 weeks ago When a non-x86 platform is detected, cloud-init grants root access … When a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP address. To prevent this, cloud-init default configurations disable platform enumeration. cloud-init <25.1.3 pkgs.cloud-init Provides configuration and customization of cloud instance nixos-unstable 24.2 nixpkgs-unstable 24.2 Package maintainers: 2 @jfroche Jean-François Roche <jfroche@pyxel.be> @illustris Harikrishnan R <me@illustris.tech>
pkgs.cloud-init Provides configuration and customization of cloud instance nixos-unstable 24.2 nixpkgs-unstable 24.2
CVE-2024-11584 5.9 MEDIUM CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 3 months, 4 weeks ago cloud-init through 25.1.2 includes the systemd socket unit cloud-init-hotplugd.socket with … cloud-init through 25.1.2 includes the systemd socket unit cloud-init-hotplugd.socket with default SocketMode that grants 0666 permissions, making it world-writable. This is used for the "/run/cloud-init/hook-hotplug-cmd" FIFO. An unprivileged user could trigger hotplug-hook commands. cloud-init <25.1.3 pkgs.cloud-init Provides configuration and customization of cloud instance nixos-25.05 24.2 nixpkgs-25.05-darwin 24.2 nixos-25.05-small 24.2 nixos-unstable 24.2 nixos-unstable-small 24.2 nixpkgs-unstable 24.2 Package maintainers: 2 @jfroche Jean-François Roche <jfroche@pyxel.be> @illustris Harikrishnan R <me@illustris.tech>
pkgs.cloud-init Provides configuration and customization of cloud instance nixos-25.05 24.2 nixpkgs-25.05-darwin 24.2 nixos-25.05-small 24.2 nixos-unstable 24.2 nixos-unstable-small 24.2 nixpkgs-unstable 24.2
CVE-2024-6126 3.2 LOW CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): REQUIRED Scope (S): CHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): LOW created 3 months, 4 weeks ago Cockpit: authenticated user can kill any process when enabling pam_env's user_readenv option A flaw was found in the cockpit package. This flaw allows an authenticated user to kill any process when enabling the pam_env's user_readenv option, which leads to a denial of service (DoS) attack. cockpit * pkgs.cockpit Web-based graphical interface for servers nixos-25.05 338 nixpkgs-25.05-darwin 338 nixos-25.05-small 338 nixos-unstable 329.1 nixos-unstable-small 340 nixpkgs-unstable 338 pkgs.emacsPackages.test-cockpit nixos-unstable 20240604.1943 nixos-unstable-small 20240604.1943 nixpkgs-unstable 20240604.1943 Package maintainers: 1 @lucasew Lucas Eduardo Wendt <lucas59356@gmail.com>
pkgs.cockpit Web-based graphical interface for servers nixos-25.05 338 nixpkgs-25.05-darwin 338 nixos-25.05-small 338 nixos-unstable 329.1 nixos-unstable-small 340 nixpkgs-unstable 338
pkgs.emacsPackages.test-cockpit nixos-unstable 20240604.1943 nixos-unstable-small 20240604.1943 nixpkgs-unstable 20240604.1943
CVE-2025-5318 5.4 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): NONE created 4 months ago Libssh: out-of-bounds read in sftp_handle() A flaw was found in the libssh library. An out-of-bounds read can be triggered in the sftp_handle function due to an incorrect comparison check that permits the function to access memory beyond the valid handle list and to return an invalid pointer, which is used in further processing. This vulnerability allows an authenticated remote attacker to potentially read unintended memory regions, exposing sensitive information or affect service behavior. rhcos libssh pkgs.libssh SSH client library nixos-25.05 0.11.1 nixpkgs-25.05-darwin 0.11.1 nixos-25.05-small 0.11.1 nixos-unstable 0.11.1 nixos-unstable-small 0.11.1 nixpkgs-unstable 0.11.1 pkgs.libssh2 Client-side C library implementing the SSH2 protocol nixos-25.05 1.11.1 nixpkgs-25.05-darwin 1.11.1 nixos-25.05-small 1.11.1 nixos-unstable 1.11.1 nixos-unstable-small 1.11.1 nixpkgs-unstable 1.11.1 pkgs.libssh.x86_64-linux SSH client library nixos-unstable ??? nixos-unstable-small 0.11.1 pkgs.libssh.aarch64-linux SSH client library nixos-unstable ??? nixos-unstable-small 0.11.1 pkgs.libssh.x86_64-darwin SSH client library nixos-unstable ??? nixos-unstable-small 0.11.1 pkgs.libssh2.x86_64-linux Client-side C library implementing the SSH2 protocol nixos-unstable ??? nixos-unstable-small 1.11.1 pkgs.libssh.aarch64-darwin SSH client library nixos-unstable ??? nixos-unstable-small 0.11.1 pkgs.libssh2.aarch64-linux Client-side C library implementing the SSH2 protocol nixos-unstable ??? nixos-unstable-small 1.11.1 pkgs.libssh2.x86_64-darwin Client-side C library implementing the SSH2 protocol nixos-unstable ??? nixos-unstable-small 1.11.1 pkgs.haskellPackages.libssh libssh bindings nixos-25.05 0.1.0.0 nixpkgs-25.05-darwin 0.1.0.0 nixos-25.05-small 0.1.0.0 nixos-unstable 0.1.0.0 nixos-unstable-small 0.1.0.0 nixpkgs-unstable 0.1.0.0 pkgs.libssh2.aarch64-darwin Client-side C library implementing the SSH2 protocol nixos-unstable ??? nixos-unstable-small 1.11.1 pkgs.haskellPackages.libssh2 FFI bindings to libssh2 SSH2 client library (http://libssh2.org/) nixos-unstable 0.2.0.9 nixos-unstable-small 0.2.0.9 nixpkgs-unstable 0.2.0.9 pkgs.haskellPackages.libssh2-conduit Conduit wrappers for libssh2 FFI bindings (see libssh2 package) nixos-unstable 0.2.1 nixos-unstable-small 0.2.1 nixpkgs-unstable 0.2.1 pkgs.python311Packages.ansible-pylibssh Python bindings to client functionality of libssh specific to Ansible use case nixos-unstable 1.2.2 nixos-unstable-small 1.2.2 nixpkgs-unstable 1.2.2 pkgs.python312Packages.ansible-pylibssh Python bindings to client functionality of libssh specific to Ansible use case nixos-25.05 1.2.2 nixpkgs-25.05-darwin 1.2.2 nixos-25.05-small 1.2.2 nixos-unstable 1.2.2 nixos-unstable-small 1.2.2 nixpkgs-unstable 1.2.2 pkgs.python313Packages.ansible-pylibssh Python bindings to client functionality of libssh specific to Ansible use case nixos-25.05 1.2.2 nixpkgs-25.05-darwin 1.2.2 nixos-25.05-small 1.2.2 nixos-unstable 1.2.2 nixos-unstable-small 1.2.2 nixpkgs-unstable 1.2.2 pkgs.haskellPackages.libssh.x86_64-linux libssh bindings nixos-unstable ??? nixpkgs-unstable 0.1.0.0 pkgs.haskellPackages.libssh.aarch64-linux libssh bindings nixos-unstable ??? nixpkgs-unstable 0.1.0.0 pkgs.haskellPackages.libssh.x86_64-darwin libssh bindings nixos-unstable ??? nixpkgs-unstable 0.1.0.0 pkgs.haskellPackages.libssh2.x86_64-linux FFI bindings to libssh2 SSH2 client library (http://libssh2.org/) nixos-unstable ??? nixpkgs-unstable 0.2.0.9 pkgs.haskellPackages.libssh.aarch64-darwin libssh bindings nixos-unstable ??? nixpkgs-unstable 0.1.0.0 pkgs.haskellPackages.libssh2.aarch64-linux FFI bindings to libssh2 SSH2 client library (http://libssh2.org/) nixos-unstable ??? nixpkgs-unstable 0.2.0.9 pkgs.haskellPackages.libssh2.x86_64-darwin FFI bindings to libssh2 SSH2 client library (http://libssh2.org/) nixos-unstable ??? nixpkgs-unstable 0.2.0.9 pkgs.haskellPackages.libssh2.aarch64-darwin FFI bindings to libssh2 SSH2 client library (http://libssh2.org/) nixos-unstable ??? nixpkgs-unstable 0.2.0.9 pkgs.haskellPackages.libssh2-conduit.x86_64-linux Conduit wrappers for libssh2 FFI bindings (see libssh2 package) nixos-unstable ??? nixpkgs-unstable 0.2.1 pkgs.haskellPackages.libssh2-conduit.aarch64-linux Conduit wrappers for libssh2 FFI bindings (see libssh2 package) nixos-unstable ??? nixpkgs-unstable 0.2.1 pkgs.haskellPackages.libssh2-conduit.x86_64-darwin Conduit wrappers for libssh2 FFI bindings (see libssh2 package) nixos-unstable ??? nixpkgs-unstable 0.2.1 pkgs.haskellPackages.libssh2-conduit.aarch64-darwin Conduit wrappers for libssh2 FFI bindings (see libssh2 package) nixos-unstable ??? nixpkgs-unstable 0.2.1 pkgs.tests.pkg-config.defaultPkgConfigPackages.libssh2 Test whether libssh2-1.11.1 exposes pkg-config modules libssh2 nixos-25.05 libssh2 nixpkgs-25.05-darwin libssh2 nixos-25.05-small libssh2 nixos-unstable libssh2 nixos-unstable-small libssh2 nixpkgs-unstable libssh2 Package maintainers: 3 @geluk Johan Geluk <johan+nix@geluk.io> @svanderburg Sander van der Burg <s.vanderburg@tudelft.nl> @SuperSandro2000 Sandro Jäckel <sandro.jaeckel@gmail.com>
pkgs.libssh SSH client library nixos-25.05 0.11.1 nixpkgs-25.05-darwin 0.11.1 nixos-25.05-small 0.11.1 nixos-unstable 0.11.1 nixos-unstable-small 0.11.1 nixpkgs-unstable 0.11.1
pkgs.libssh2 Client-side C library implementing the SSH2 protocol nixos-25.05 1.11.1 nixpkgs-25.05-darwin 1.11.1 nixos-25.05-small 1.11.1 nixos-unstable 1.11.1 nixos-unstable-small 1.11.1 nixpkgs-unstable 1.11.1
pkgs.libssh2.x86_64-linux Client-side C library implementing the SSH2 protocol nixos-unstable ??? nixos-unstable-small 1.11.1
pkgs.libssh2.aarch64-linux Client-side C library implementing the SSH2 protocol nixos-unstable ??? nixos-unstable-small 1.11.1
pkgs.libssh2.x86_64-darwin Client-side C library implementing the SSH2 protocol nixos-unstable ??? nixos-unstable-small 1.11.1
pkgs.haskellPackages.libssh libssh bindings nixos-25.05 0.1.0.0 nixpkgs-25.05-darwin 0.1.0.0 nixos-25.05-small 0.1.0.0 nixos-unstable 0.1.0.0 nixos-unstable-small 0.1.0.0 nixpkgs-unstable 0.1.0.0
pkgs.libssh2.aarch64-darwin Client-side C library implementing the SSH2 protocol nixos-unstable ??? nixos-unstable-small 1.11.1
pkgs.haskellPackages.libssh2 FFI bindings to libssh2 SSH2 client library (http://libssh2.org/) nixos-unstable 0.2.0.9 nixos-unstable-small 0.2.0.9 nixpkgs-unstable 0.2.0.9
pkgs.haskellPackages.libssh2-conduit Conduit wrappers for libssh2 FFI bindings (see libssh2 package) nixos-unstable 0.2.1 nixos-unstable-small 0.2.1 nixpkgs-unstable 0.2.1
pkgs.python311Packages.ansible-pylibssh Python bindings to client functionality of libssh specific to Ansible use case nixos-unstable 1.2.2 nixos-unstable-small 1.2.2 nixpkgs-unstable 1.2.2
pkgs.python312Packages.ansible-pylibssh Python bindings to client functionality of libssh specific to Ansible use case nixos-25.05 1.2.2 nixpkgs-25.05-darwin 1.2.2 nixos-25.05-small 1.2.2 nixos-unstable 1.2.2 nixos-unstable-small 1.2.2 nixpkgs-unstable 1.2.2
pkgs.python313Packages.ansible-pylibssh Python bindings to client functionality of libssh specific to Ansible use case nixos-25.05 1.2.2 nixpkgs-25.05-darwin 1.2.2 nixos-25.05-small 1.2.2 nixos-unstable 1.2.2 nixos-unstable-small 1.2.2 nixpkgs-unstable 1.2.2
pkgs.haskellPackages.libssh.aarch64-linux libssh bindings nixos-unstable ??? nixpkgs-unstable 0.1.0.0
pkgs.haskellPackages.libssh.x86_64-darwin libssh bindings nixos-unstable ??? nixpkgs-unstable 0.1.0.0
pkgs.haskellPackages.libssh2.x86_64-linux FFI bindings to libssh2 SSH2 client library (http://libssh2.org/) nixos-unstable ??? nixpkgs-unstable 0.2.0.9
pkgs.haskellPackages.libssh.aarch64-darwin libssh bindings nixos-unstable ??? nixpkgs-unstable 0.1.0.0
pkgs.haskellPackages.libssh2.aarch64-linux FFI bindings to libssh2 SSH2 client library (http://libssh2.org/) nixos-unstable ??? nixpkgs-unstable 0.2.0.9
pkgs.haskellPackages.libssh2.x86_64-darwin FFI bindings to libssh2 SSH2 client library (http://libssh2.org/) nixos-unstable ??? nixpkgs-unstable 0.2.0.9
pkgs.haskellPackages.libssh2.aarch64-darwin FFI bindings to libssh2 SSH2 client library (http://libssh2.org/) nixos-unstable ??? nixpkgs-unstable 0.2.0.9
pkgs.haskellPackages.libssh2-conduit.x86_64-linux Conduit wrappers for libssh2 FFI bindings (see libssh2 package) nixos-unstable ??? nixpkgs-unstable 0.2.1
pkgs.haskellPackages.libssh2-conduit.aarch64-linux Conduit wrappers for libssh2 FFI bindings (see libssh2 package) nixos-unstable ??? nixpkgs-unstable 0.2.1
pkgs.haskellPackages.libssh2-conduit.x86_64-darwin Conduit wrappers for libssh2 FFI bindings (see libssh2 package) nixos-unstable ??? nixpkgs-unstable 0.2.1
pkgs.haskellPackages.libssh2-conduit.aarch64-darwin Conduit wrappers for libssh2 FFI bindings (see libssh2 package) nixos-unstable ??? nixpkgs-unstable 0.2.1
pkgs.tests.pkg-config.defaultPkgConfigPackages.libssh2 Test whether libssh2-1.11.1 exposes pkg-config modules libssh2 nixos-25.05 libssh2 nixpkgs-25.05-darwin libssh2 nixos-25.05-small libssh2 nixos-unstable libssh2 nixos-unstable-small libssh2 nixpkgs-unstable libssh2
CVE-2025-6547 created 4 months ago On Node.js < 3, pbkdf2 silently disregards Uint8Array input, returning static keys Improper Input Validation vulnerability in pbkdf2 allows Signature Spoofing by Improper Validation.This issue affects pbkdf2: <=3.1.2. pbkdf2 ==<=3.1.2 pkgs.fastpbkdf2 Fast PBKDF2-HMAC-{SHA1,SHA256,SHA512} implementation in C nixos-25.05 1.0.0 nixpkgs-25.05-darwin 1.0.0 nixos-25.05-small 1.0.0 nixos-unstable 1.0.0 nixos-unstable-small 1.0.0 nixpkgs-unstable 1.0.0 pkgs.python311Packages.pbkdf2 nixos-unstable pbkdf2-1.3 nixos-unstable-small pbkdf2-1.3 nixpkgs-unstable pbkdf2-1.3 pkgs.python312Packages.pbkdf2 nixos-25.05 pbkdf2-1.3 nixpkgs-25.05-darwin pbkdf2-1.3 nixos-25.05-small pbkdf2-1.3 nixos-unstable pbkdf2-1.3 nixos-unstable-small pbkdf2-1.3 nixpkgs-unstable pbkdf2-1.3 pkgs.python313Packages.pbkdf2 nixos-25.05 pbkdf2-1.3 nixpkgs-25.05-darwin pbkdf2-1.3 nixos-25.05-small pbkdf2-1.3 nixos-unstable pbkdf2-1.3 nixos-unstable-small pbkdf2-1.3 nixpkgs-unstable pbkdf2-1.3 pkgs.emacsPackages.kaesar-pbkdf2 nixos-unstable pbkdf2-20230626.2314 nixos-unstable-small pbkdf2-20230626.2314 nixpkgs-unstable pbkdf2-20230626.2314 pkgs.python311Packages.fastpbkdf2 Python bindings for fastpbkdf2 nixos-unstable fastpbkdf2-0.2 nixos-unstable-small fastpbkdf2-0.2 nixpkgs-unstable fastpbkdf2-0.2 pkgs.python312Packages.fastpbkdf2 Python bindings for fastpbkdf2 nixos-25.05 fastpbkdf2-0.2 nixpkgs-25.05-darwin fastpbkdf2-0.2 nixos-25.05-small fastpbkdf2-0.2 nixos-unstable fastpbkdf2-0.2 nixos-unstable-small fastpbkdf2-0.2 nixpkgs-unstable fastpbkdf2-0.2 pkgs.python313Packages.fastpbkdf2 Python bindings for fastpbkdf2 nixos-25.05 fastpbkdf2-0.2 nixpkgs-25.05-darwin fastpbkdf2-0.2 nixos-25.05-small fastpbkdf2-0.2 nixos-unstable fastpbkdf2-0.2 nixos-unstable-small fastpbkdf2-0.2 nixpkgs-unstable fastpbkdf2-0.2 pkgs.chickenPackages_5.chickenEggs.pbkdf2 Password-Based Key Derivation Function as defined in RFC2898 nixos-25.05 pbkdf2-1.3 nixpkgs-25.05-darwin pbkdf2-1.3 nixos-25.05-small pbkdf2-1.3 nixos-unstable pbkdf2-1.3 nixos-unstable-small pbkdf2-1.3 nixpkgs-unstable pbkdf2-1.3 pkgs.python312Packages.pbkdf2.x86_64-linux nixos-unstable pbkdf2-1.3 pkgs.python312Packages.pbkdf2.aarch64-linux nixos-unstable pbkdf2-1.3 pkgs.python312Packages.pbkdf2.x86_64-darwin nixos-unstable pbkdf2-1.3 pkgs.python312Packages.pbkdf2.aarch64-darwin nixos-unstable pbkdf2-1.3 Package maintainers: 3 @domenkozar Domen Kozar <domen@dev.si> @ledif Adam Fidel <refuse@gmail.com> @jqueiroz Jonathan Queiroz <nixos@johnjq.com>
pkgs.fastpbkdf2 Fast PBKDF2-HMAC-{SHA1,SHA256,SHA512} implementation in C nixos-25.05 1.0.0 nixpkgs-25.05-darwin 1.0.0 nixos-25.05-small 1.0.0 nixos-unstable 1.0.0 nixos-unstable-small 1.0.0 nixpkgs-unstable 1.0.0
pkgs.python311Packages.pbkdf2 nixos-unstable pbkdf2-1.3 nixos-unstable-small pbkdf2-1.3 nixpkgs-unstable pbkdf2-1.3
pkgs.python312Packages.pbkdf2 nixos-25.05 pbkdf2-1.3 nixpkgs-25.05-darwin pbkdf2-1.3 nixos-25.05-small pbkdf2-1.3 nixos-unstable pbkdf2-1.3 nixos-unstable-small pbkdf2-1.3 nixpkgs-unstable pbkdf2-1.3
pkgs.python313Packages.pbkdf2 nixos-25.05 pbkdf2-1.3 nixpkgs-25.05-darwin pbkdf2-1.3 nixos-25.05-small pbkdf2-1.3 nixos-unstable pbkdf2-1.3 nixos-unstable-small pbkdf2-1.3 nixpkgs-unstable pbkdf2-1.3
pkgs.emacsPackages.kaesar-pbkdf2 nixos-unstable pbkdf2-20230626.2314 nixos-unstable-small pbkdf2-20230626.2314 nixpkgs-unstable pbkdf2-20230626.2314
pkgs.python311Packages.fastpbkdf2 Python bindings for fastpbkdf2 nixos-unstable fastpbkdf2-0.2 nixos-unstable-small fastpbkdf2-0.2 nixpkgs-unstable fastpbkdf2-0.2
pkgs.python312Packages.fastpbkdf2 Python bindings for fastpbkdf2 nixos-25.05 fastpbkdf2-0.2 nixpkgs-25.05-darwin fastpbkdf2-0.2 nixos-25.05-small fastpbkdf2-0.2 nixos-unstable fastpbkdf2-0.2 nixos-unstable-small fastpbkdf2-0.2 nixpkgs-unstable fastpbkdf2-0.2
pkgs.python313Packages.fastpbkdf2 Python bindings for fastpbkdf2 nixos-25.05 fastpbkdf2-0.2 nixpkgs-25.05-darwin fastpbkdf2-0.2 nixos-25.05-small fastpbkdf2-0.2 nixos-unstable fastpbkdf2-0.2 nixos-unstable-small fastpbkdf2-0.2 nixpkgs-unstable fastpbkdf2-0.2
pkgs.chickenPackages_5.chickenEggs.pbkdf2 Password-Based Key Derivation Function as defined in RFC2898 nixos-25.05 pbkdf2-1.3 nixpkgs-25.05-darwin pbkdf2-1.3 nixos-25.05-small pbkdf2-1.3 nixos-unstable pbkdf2-1.3 nixos-unstable-small pbkdf2-1.3 nixpkgs-unstable pbkdf2-1.3