Nixpkgs Security Tracker

Login with GitHub

Automatically generated suggestions

to queue a suggestion for refinement.

to remove a suggestion from the queue.

updated 6 seconds ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed
    15 packages
    • fleeting-plugin-aws
    • azure-cli-extensions.fleet
    • python312Packages.tesla-fleet-api
    • python313Packages.tesla-fleet-api
    • haskellPackages.amazonka-iotfleethub
    • haskellPackages.amazonka-iotfleetwise
    • python312Packages.mypy-boto3-iotfleethub
    • python313Packages.mypy-boto3-iotfleethub
    • python312Packages.mypy-boto3-iotfleetwise
    • python313Packages.mypy-boto3-iotfleetwise
    • home-assistant-component-tests.tesla_fleet
    • python312Packages.types-aiobotocore-iotfleethub
    • python313Packages.types-aiobotocore-iotfleethub
    • python312Packages.types-aiobotocore-iotfleetwise
    • python313Packages.types-aiobotocore-iotfleetwise
  • @LeSuisse removed maintainer @AntoineSauzeau
  • @LeSuisse added
    6 maintainers
    • @commiterate
    • @dotlambda
    • @fabaff
    • @mweinelt
    • @mbalatsko
    • @katexochen
Fleet Windows MDM endpoint has a Cross-site Scripting vulnerability

fleetdm/fleet is open source device management software. Prior to versions 4.78.2, 4.77.1, 4.76.2, 4.75.2, and 4.53.3, if Windows MDM is enabled, an unauthenticated attacker can exploit this XSS vulnerability to steal a Fleet administrator's authentication token (FLEET::auth_token) from localStorage. This could allow unauthorized access to Fleet, including administrative access, visibility into device data, and modification of configuration. Versions 4.78.2, 4.77.1, 4.76.2, 4.75.2, and 4.53.3 fix the issue. If an immediate upgrade is not possible, affected Fleet users should temporarily disable Windows MDM.

Affected products

fleet
  • ==>= 4.77.0, < 4.77.1
  • ==>= 4.76.0, < 4.76.2
  • ==< 4.53.3
  • ==>= 4.78.0, < 4.78.2

Matching in nixpkgs

Package maintainers: 7

created 6 hours ago
OpenJPEG allows OOB heap memory write in opj_jp2_read_header

OpenJPEG is an open-source JPEG 2000 codec. In OpenJPEG 2.5.3 and earlier, a call to opj_jp2_read_header may lead to OOB heap memory write when the data stream p_stream is too short and p_image is not initialized.

Affected products

openjpeg
  • ==<= 2.5.3
  • ==>= 2.5.1, <= 2.5.3

Matching in nixpkgs

pkgs.python312Packages.pylibjpeg-openjpeg

A J2K and JP2 plugin for pylibjpeg

pkgs.python313Packages.pylibjpeg-openjpeg

A J2K and JP2 plugin for pylibjpeg

Package maintainers: 2

created 6 hours ago
Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query

Vite is a frontend tooling framework for javascript. Vite exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explicitly exposing the Vite dev server to the network (using --host or server.host config option) are affected. This vulnerability is fixed in 6.2.4, 6.1.3, 6.0.13, 5.4.16, and 4.5.11.

Affected products

vite
  • ==>= 6.0.0, < 6.0.13
  • ==< 4.5.11
  • ==>= 5.0.0, < 5.4.16
  • ==>= 6.2.0, < 6.2.4
  • ==>= 6.1.0, < 6.1.3

Matching in nixpkgs

pkgs.python312Packages.django-vite

Integration of ViteJS in a Django project

pkgs.python313Packages.django-vite

Integration of ViteJS in a Django project

Package maintainers: 3

created 6 hours ago
Incus container environment configuration newline injection

Incus is a system container and virtual machine manager. In versions 6.20.0 and below, a user with the ability to launch a container with a custom YAML configuration (e.g a member of the ‘incus’ group) can create an environment variable containing newlines, which can be used to add additional configuration items in the container’s lxc.conf due to newline injection. This can allow adding arbitrary lifecycle hooks, ultimately resulting in arbitrary command execution on the host. Exploiting this issue on IncusOS requires a slight modification of the payload to change to a different writable directory for the validation step (e.g /tmp). This can be confirmed with a second container with /tmp mounted from the host (A privileged action for validation only). A fix is planned for versions 6.0.6 and 6.21.0, but they have not been released at the time of publication.

Affected products

incus
  • ==<= 6.0.5
  • ==>= 6.1.0, <= 6.20.0

Matching in nixpkgs

pkgs.incus-lts

Powerful system container and virtual machine manager

pkgs.terraform-providers.incus

None

pkgs.terraform-providers.lxc_incus

None

Package maintainers: 5

created 6 hours ago
Use After Free vulnerability in Samsung Open Source rLottie allows …

Use After Free vulnerability in Samsung Open Source rLottie allows Remote Code Inclusion.This issue affects rLottie: V0.2.

Affected products

rLottie
  • ==V0.2

Matching in nixpkgs

Package maintainers: 2

created 6 hours ago
WordPress Anon theme <= 2.2.10 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CleverSoft Anon anon2x allows Reflected XSS.This issue affects Anon: from n/a through <= 2.2.10.

Affected products

anon2x
  • =<<= 2.2.10

Matching in nixpkgs

pkgs.myanon

Myanon is a mysqldump anonymizer, reading a dump from stdin, and producing on the fly an anonymized version to stdout

pkgs.pg-dump-anon

Export databases with data being anonymized with the anonymizer extension

pkgs.raft-canonical

Fully asynchronous C implementation of the Raft consensus protocol

pkgs.python312Packages.anonip

Tool to anonymize IP addresses in log files

pkgs.python313Packages.anonip

Tool to anonymize IP addresses in log files

pkgs.graylogPlugins.ipanonymizer

Graylog-server plugin that replaces the last octet of IP addresses in messages with xxx

pkgs.postgresqlPackages.anonymizer

Extension to mask or replace personally identifiable information (PII) or commercially sensitive data from a PostgreSQL database

pkgs.python312Packages.anonymizeip

Python library for anonymizing IP addresses

pkgs.python313Packages.anonymizeip

Python library for anonymizing IP addresses

pkgs.perlPackages.XMLCanonicalizeXML

Perl extension for inclusive (1.0 and 1.1) and exclusive canonicalization of XML using libxml2

pkgs.postgresql13Packages.anonymizer

Extension to mask or replace personally identifiable information (PII) or commercially sensitive data from a PostgreSQL database

pkgs.postgresql14Packages.anonymizer

Extension to mask or replace personally identifiable information (PII) or commercially sensitive data from a PostgreSQL database

pkgs.postgresql15Packages.anonymizer

Extension to mask or replace personally identifiable information (PII) or commercially sensitive data from a PostgreSQL database

pkgs.postgresql16Packages.anonymizer

Extension to mask or replace personally identifiable information (PII) or commercially sensitive data from a PostgreSQL database

pkgs.postgresql18Packages.anonymizer

Extension to mask or replace personally identifiable information (PII) or commercially sensitive data from a PostgreSQL database

pkgs.python312Packages.canonicaljson

Encodes objects and arrays as RFC 7159 JSON

pkgs.python313Packages.canonicaljson

Encodes objects and arrays as RFC 7159 JSON

pkgs.perl538Packages.XMLCanonicalizeXML

Perl extension for inclusive (1.0 and 1.1) and exclusive canonicalization of XML using libxml2

pkgs.perl540Packages.XMLCanonicalizeXML

Perl extension for inclusive (1.0 and 1.1) and exclusive canonicalization of XML using libxml2

pkgs.typstPackages.canonical-nthu-thesis_0_1_0

A template for master theses and doctoral dissertations for NTHU (National Tsing Hua University

pkgs.typstPackages.canonical-nthu-thesis_0_2_0

A template for master theses and doctoral dissertations for NTHU (National Tsing Hua University

pkgs.python312Packages.canonical-sphinx-extensions

A collection of Sphinx extensions used by Canonical documentation

pkgs.python313Packages.canonical-sphinx-extensions

A collection of Sphinx extensions used by Canonical documentation

Package maintainers: 26

created 6 hours ago
Loop with Unreachable Exit Condition ('Infinite Loop') in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that under certain circumstances could have allowed an authenticated user to create a denial of service condition by configuring malformed Wiki documents that bypass cycle detection.

Affected products

GitLab
  • <18.8.2
  • <18.6.4
  • <18.7.2

Matching in nixpkgs

pkgs.danger-gitlab

Gem that exists to ensure all dependencies are set up for Danger with GitLab

pkgs.gitlab-clippy

Convert clippy warnings into GitLab Code Quality report

pkgs.gitlab-timelogs

CLI utility to support you with your time logs in GitLab

pkgs.gitlab-ci-linter

.gitlab-ci.yml lint helper tool

pkgs.ocamlPackages.gitlab

Native OCaml bindings to Gitlab REST API v4

pkgs.gitlab-container-registry

GitLab Docker toolset to pack, ship, store, and deliver content

pkgs.ocamlPackages.gitlab-jsoo

Gitlab APIv4 JavaScript library

pkgs.ocamlPackages.gitlab-unix

Gitlab APIv4 Unix library

pkgs.rubyPackages_3_1.gitlab-markup

None

pkgs.rubyPackages_3_2.gitlab-markup

None

pkgs.rubyPackages_3_5.gitlab-markup

None

pkgs.python312Packages.mkdocs-gitlab

MkDocs plugin to transform strings such as #1234, %56, or !789 into links to a Gitlab repository

pkgs.python313Packages.mkdocs-gitlab

MkDocs plugin to transform strings such as #1234, %56, or !789 into links to a Gitlab repository

pkgs.terraform-providers.gitlabhq_gitlab

None

pkgs.prometheus-gitlab-ci-pipelines-exporter

Prometheus / OpenMetrics exporter for GitLab CI pipelines insights

pkgs.perlPackages.AlienBuildPluginDownloadGitLab

Alien::Build plugin to download from GitLab

pkgs.perl538Packages.AlienBuildPluginDownloadGitLab

Alien::Build plugin to download from GitLab

pkgs.perl540Packages.AlienBuildPluginDownloadGitLab

Alien::Build plugin to download from GitLab

Package maintainers: 21

created 6 hours ago
Allocation of Resources Without Limits or Throttling in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.3 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that could have allowed an unauthenticated user to create a denial of service condition by sending repeated malformed SSH authentication requests.

Affected products

GitLab
  • <18.8.2
  • <18.6.4
  • <18.7.2

Matching in nixpkgs

pkgs.danger-gitlab

Gem that exists to ensure all dependencies are set up for Danger with GitLab

pkgs.gitlab-clippy

Convert clippy warnings into GitLab Code Quality report

pkgs.gitlab-timelogs

CLI utility to support you with your time logs in GitLab

pkgs.gitlab-ci-linter

.gitlab-ci.yml lint helper tool

pkgs.ocamlPackages.gitlab

Native OCaml bindings to Gitlab REST API v4

pkgs.gitlab-container-registry

GitLab Docker toolset to pack, ship, store, and deliver content

pkgs.ocamlPackages.gitlab-jsoo

Gitlab APIv4 JavaScript library

pkgs.ocamlPackages.gitlab-unix

Gitlab APIv4 Unix library

pkgs.rubyPackages_3_1.gitlab-markup

None

pkgs.rubyPackages_3_2.gitlab-markup

None

pkgs.rubyPackages_3_5.gitlab-markup

None

pkgs.python312Packages.mkdocs-gitlab

MkDocs plugin to transform strings such as #1234, %56, or !789 into links to a Gitlab repository

pkgs.python313Packages.mkdocs-gitlab

MkDocs plugin to transform strings such as #1234, %56, or !789 into links to a Gitlab repository

pkgs.terraform-providers.gitlabhq_gitlab

None

pkgs.prometheus-gitlab-ci-pipelines-exporter

Prometheus / OpenMetrics exporter for GitLab CI pipelines insights

pkgs.perlPackages.AlienBuildPluginDownloadGitLab

Alien::Build plugin to download from GitLab

pkgs.perl538Packages.AlienBuildPluginDownloadGitLab

Alien::Build plugin to download from GitLab

pkgs.perl540Packages.AlienBuildPluginDownloadGitLab

Alien::Build plugin to download from GitLab

Package maintainers: 21

created 6 hours ago
Apache Xerces C++: Use-after-free on external DTD scan

The Apache Xerces C++ XML parser on versions 3.0.0 before 3.2.5 contains a use-after-free error triggered during the scanning of external DTDs. Users are recommended to upgrade to version 3.2.5 which fixes the issue, or mitigate the issue by disabling DTD processing. This can be accomplished via the DOM using a standard parser feature, or via SAX using the XERCES_DISABLE_DTD environment variable. This issue has been disclosed before as CVE-2018-1311, but unfortunately that advisory incorrectly stated the issue would be fixed in version 3.2.3 or 3.2.4.

Affected products

xerces-c
  • <3.2.5
Apache Xerces C++
  • <3.2.5

Matching in nixpkgs

pkgs.xercesc

Validating XML parser written in a portable subset of C++

pkgs.tests.pkg-config.defaultPkgConfigPackages.xerces-c

Test whether xerces-c-3.3.0 exposes pkg-config modules xerces-c

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small
  • nixos-25.05 -
    • nixos-25.05-small
    • nixpkgs-25.05-darwin
created 6 hours ago
WordPress Rashy theme <= 1.1.3 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in goalthemes Rashy rashy allows PHP Local File Inclusion.This issue affects Rashy: from n/a through <= 1.1.3.

Affected products

rashy
  • =<<= 1.1.3

Matching in nixpkgs

pkgs.trashy

Simple, fast, and featureful alternative to rm and trash-cli

Package maintainers: 1