CVE-2025-13742 created 1 month ago Limited HTML injection in emails Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used in an email template, it will be replaced with the buyer's name for the final email. If the name of the attendee contained HTML or Markdown formatting, this was rendered as HTML in the resulting email. This way, a user could inject links or other formatted text through a maliciously formatted name. Since pretix applies a strict allow list approach to allowed HTML tags, this could not be abused for XSS or similarly dangerous attack chains. However, it can be used to manipulate emails in a way that makes user-provided content appear in a trustworthy and credible way, which can be abused for phishing. Affected products pretix <2025.7.0 <2025.8.0 <2025.10.0 <2025.9.0 Matching in nixpkgs pkgs.pretix Ticketing software that cares about your event—all the way nixos-25.05 2025.4.0 nixos-25.05-small 2025.4.0 nixpkgs-25.05-darwin 2025.4.0 nixos-unstable 2025.9.0 nixpkgs-unstable 2025.9.0 nixos-unstable-small 2025.9.0 pkgs.pretix-banktool Automatic bank data upload tool for pretix (with FinTS client) nixos-25.05 1.1.0 nixos-25.05-small 1.1.0 nixpkgs-25.05-darwin 1.1.0 nixos-unstable 1.1.0 nixpkgs-unstable 1.1.0 nixos-unstable-small 1.1.0 Package maintainers: 1 @mweinelt Martin Weinelt <hexa@darmstadt.ccc.de>
pkgs.pretix Ticketing software that cares about your event—all the way nixos-25.05 2025.4.0 nixos-25.05-small 2025.4.0 nixpkgs-25.05-darwin 2025.4.0 nixos-unstable 2025.9.0 nixpkgs-unstable 2025.9.0 nixos-unstable-small 2025.9.0
pkgs.pretix-banktool Automatic bank data upload tool for pretix (with FinTS client) nixos-25.05 1.1.0 nixos-25.05-small 1.1.0 nixpkgs-25.05-darwin 1.1.0 nixos-unstable 1.1.0 nixpkgs-unstable 1.1.0 nixos-unstable-small 1.1.0
CVE-2025-62230 7.3 HIGH CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): LOW Availability impact (A): HIGH created 1 month, 2 weeks ago Xorg: xwayland: use-after-free in xkb client resource removal A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The software frees certain data structures without properly detaching related resources, leading to a use-after-free condition. This can cause memory corruption or a crash when affected clients disconnect. Affected products tigervnc * xwayland <24.1.9 xorg-x11-server * xorg-x11-server-Xwayland * Matching in nixpkgs pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-25.05 1.14.0 nixos-25.05-small 1.14.0 nixpkgs-25.05-darwin 1.14.0 nixos-unstable 1.15.0 nixpkgs-unstable 1.15.0 nixos-unstable-small 1.15.0
pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-25.05 1.14.0 nixos-25.05-small 1.14.0 nixpkgs-25.05-darwin 1.14.0 nixos-unstable 1.15.0 nixpkgs-unstable 1.15.0 nixos-unstable-small 1.15.0
CVE-2025-62402 5.4 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): NONE created 1 month, 2 weeks ago Apache Airflow: Airflow 3 API: /api/v2/dagReports executes DAG Python in API API users via `/api/v2/dagReports` could perform Dag code execution in the context of the api-server if the api-server was deployed in the environment where Dag files were available. Affected products apache-airflow <3.1.1 Matching in nixpkgs pkgs.apache-airflow Programmatically author, schedule and monitor data pipelines nixos-25.05 2.7.3 nixos-25.05-small 2.7.3 nixpkgs-25.05-darwin 2.7.3 nixos-unstable 2.7.3 nixpkgs-unstable 2.7.3 nixos-unstable-small 2.7.3 Package maintainers: 3 @ingenieroariel Ariel Nunez <ariel@nunez.co> @bhipple Benjamin Hipple <bhipple@protonmail.com> @gbpdt Graham Bennett <nix@pdtpartners.com>
pkgs.apache-airflow Programmatically author, schedule and monitor data pipelines nixos-25.05 2.7.3 nixos-25.05-small 2.7.3 nixpkgs-25.05-darwin 2.7.3 nixos-unstable 2.7.3 nixpkgs-unstable 2.7.3 nixos-unstable-small 2.7.3
CVE-2025-62231 7.3 HIGH CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): LOW Availability impact (A): HIGH created 1 month, 2 weeks ago Xorg: xmayland: value overflow in xkbsetcompatmap() A flaw was identified in the X.Org X server’s X Keyboard (Xkb) extension where improper bounds checking in the XkbSetCompatMap() function can cause an unsigned short overflow. If an attacker sends specially crafted input data, the value calculation may overflow, leading to memory corruption or a crash. Affected products tigervnc * xwayland <24.1.9 xorg-x11-server * xorg-x11-server-Xwayland * Matching in nixpkgs pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-25.05 1.14.0 nixos-25.05-small 1.14.0 nixpkgs-25.05-darwin 1.14.0 nixos-unstable 1.15.0 nixpkgs-unstable 1.15.0 nixos-unstable-small 1.15.0
pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-25.05 1.14.0 nixos-25.05-small 1.14.0 nixpkgs-25.05-darwin 1.14.0 nixos-unstable 1.15.0 nixpkgs-unstable 1.15.0 nixos-unstable-small 1.15.0
CVE-2025-54941 4.6 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): NONE created 1 month, 2 weeks ago Apache Airflow: Command injection in "example_dag_decorator" An example dag `example_dag_decorator` had non-validated parameter that allowed the UI user to redirect the example to a malicious server and execute code on worker. This however required that the example dags are enabled in production (not default) or the example dag code copied to build your own similar dag. If you used the `example_dag_decorator` please review it and apply the changes implemented in Airflow 3.0.5 accordingly. Affected products apache-airflow << 3.0.5 Matching in nixpkgs pkgs.apache-airflow Programmatically author, schedule and monitor data pipelines nixos-25.05 2.7.3 nixos-25.05-small 2.7.3 nixpkgs-25.05-darwin 2.7.3 nixos-unstable 2.7.3 nixpkgs-unstable 2.7.3 nixos-unstable-small 2.7.3 Package maintainers: 3 @ingenieroariel Ariel Nunez <ariel@nunez.co> @bhipple Benjamin Hipple <bhipple@protonmail.com> @gbpdt Graham Bennett <nix@pdtpartners.com>
pkgs.apache-airflow Programmatically author, schedule and monitor data pipelines nixos-25.05 2.7.3 nixos-25.05-small 2.7.3 nixpkgs-25.05-darwin 2.7.3 nixos-unstable 2.7.3 nixpkgs-unstable 2.7.3 nixos-unstable-small 2.7.3
CVE-2025-62395 4.3 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): NONE Availability impact (A): NONE created 1 month, 2 weeks ago Moodle: external cohort search service leaks system cohort data A flaw in the cohort search web service allowed users with permissions in lower contexts to access cohort information from the system context, revealing restricted administrative data. Affected products moodle <4.4.11 <4.5.7 <5.0.3 <4.1.21 Matching in nixpkgs pkgs.moodle Free and open-source learning management system (LMS) written in PHP nixos-25.05 5.0 nixos-25.05-small 5.0 nixpkgs-25.05-darwin 5.0 nixos-unstable 5.0.2 nixpkgs-unstable 5.0.2 nixos-unstable-small 5.0.2 pkgs.moodle-dl Moodle downloader that downloads course content fast from Moodle nixos-25.05 2.3.13 nixos-25.05-small 2.3.13 nixpkgs-25.05-darwin 2.3.13 nixos-unstable 2.3.13 nixpkgs-unstable 2.3.13 nixos-unstable-small 2.3.13 Package maintainers: 2 @freezeboy freezeboy @kmein Kierán Meinhardt <kmein@posteo.de>
pkgs.moodle Free and open-source learning management system (LMS) written in PHP nixos-25.05 5.0 nixos-25.05-small 5.0 nixpkgs-25.05-darwin 5.0 nixos-unstable 5.0.2 nixpkgs-unstable 5.0.2 nixos-unstable-small 5.0.2
pkgs.moodle-dl Moodle downloader that downloads course content fast from Moodle nixos-25.05 2.3.13 nixos-25.05-small 2.3.13 nixpkgs-25.05-darwin 2.3.13 nixos-unstable 2.3.13 nixpkgs-unstable 2.3.13 nixos-unstable-small 2.3.13
CVE-2025-62398 5.3 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): NONE Availability impact (A): NONE created 1 month, 2 weeks ago Moodle: possible to bypass mfa A serious authentication flaw allowed attackers with valid credentials to bypass multi-factor authentication under certain conditions, potentially compromising user accounts. Affected products moodle <4.4.11 <4.5.7 <5.0.3 Matching in nixpkgs pkgs.moodle Free and open-source learning management system (LMS) written in PHP nixos-25.05 5.0 nixos-25.05-small 5.0 nixpkgs-25.05-darwin 5.0 nixos-unstable 5.0.2 nixpkgs-unstable 5.0.2 nixos-unstable-small 5.0.2 pkgs.moodle-dl Moodle downloader that downloads course content fast from Moodle nixos-25.05 2.3.13 nixos-25.05-small 2.3.13 nixpkgs-25.05-darwin 2.3.13 nixos-unstable 2.3.13 nixpkgs-unstable 2.3.13 nixos-unstable-small 2.3.13 Package maintainers: 2 @freezeboy freezeboy @kmein Kierán Meinhardt <kmein@posteo.de>
pkgs.moodle Free and open-source learning management system (LMS) written in PHP nixos-25.05 5.0 nixos-25.05-small 5.0 nixpkgs-25.05-darwin 5.0 nixos-unstable 5.0.2 nixpkgs-unstable 5.0.2 nixos-unstable-small 5.0.2
pkgs.moodle-dl Moodle downloader that downloads course content fast from Moodle nixos-25.05 2.3.13 nixos-25.05-small 2.3.13 nixpkgs-25.05-darwin 2.3.13 nixos-unstable 2.3.13 nixpkgs-unstable 2.3.13 nixos-unstable-small 2.3.13
CVE-2025-12105 7.5 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): HIGH created 1 month, 2 weeks ago Libsoup: heap use-after-free in libsoup message queue handling during http/2 read completion A flaw was found in the asynchronous message queue handling of the libsoup library, widely used by GNOME and WebKit-based applications to manage HTTP/2 communications. When network operations are aborted at specific timing intervals, an internal message queue item may be freed twice due to missing state synchronization. This leads to a use-after-free memory access, potentially crashing the affected application. Attackers could exploit this behavior remotely by triggering specific HTTP/2 read and cancel sequences, resulting in a denial-of-service condition. Affected products libsoup =<3.6.5 libsoup3 * Matching in nixpkgs pkgs.libsoup_3 HTTP client/server library for GNOME nixos-25.05 3.6.5 nixos-25.05-small 3.6.5 nixpkgs-25.05-darwin 3.6.5 nixos-unstable 3.6.5 nixpkgs-unstable 3.6.5 nixos-unstable-small 3.6.5 pkgs.libsoup_2_4 HTTP client/server library for GNOME nixos-25.05 2.74.3 nixos-25.05-small 2.74.3 nixpkgs-25.05-darwin 2.74.3 nixos-unstable 2.74.3 nixpkgs-unstable 2.74.3 nixos-unstable-small 2.74.3 pkgs.tests.pkg-config.defaultPkgConfigPackages."libsoup-gnome-2.4" Test whether libsoup-2.74.3 exposes pkg-config modules libsoup-gnome-2.4 nixos-25.05 - nixos-25.05-small nixpkgs-25.05-darwin nixos-unstable - nixpkgs-unstable nixos-unstable-small Package maintainers: 6 @bobby285271 Bobby Rong <rjl931189261@126.com> @7c6f434c Michael Raskin <7c6f434c@mail.ru> @jtojnar Jan Tojnar <jtojnar@gmail.com> @lovek323 Jason O'Conal <jason@oconal.id.au> @dasj19 Daniel Șerbănescu <daniel@serbanescu.dk> @hedning Tor Hedin Brønner <torhedinbronner@gmail.com>
pkgs.libsoup_3 HTTP client/server library for GNOME nixos-25.05 3.6.5 nixos-25.05-small 3.6.5 nixpkgs-25.05-darwin 3.6.5 nixos-unstable 3.6.5 nixpkgs-unstable 3.6.5 nixos-unstable-small 3.6.5
pkgs.libsoup_2_4 HTTP client/server library for GNOME nixos-25.05 2.74.3 nixos-25.05-small 2.74.3 nixpkgs-25.05-darwin 2.74.3 nixos-unstable 2.74.3 nixpkgs-unstable 2.74.3 nixos-unstable-small 2.74.3
pkgs.tests.pkg-config.defaultPkgConfigPackages."libsoup-gnome-2.4" Test whether libsoup-2.74.3 exposes pkg-config modules libsoup-gnome-2.4 nixos-25.05 - nixos-25.05-small nixpkgs-25.05-darwin nixos-unstable - nixpkgs-unstable nixos-unstable-small
CVE-2025-62401 5.4 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): LOW Availability impact (A): LOW created 1 month, 2 weeks ago Moodle: possible to bypass timer in timed assignments An issue in Moodle’s timed assignment feature allowed students to bypass the time restriction, potentially giving them more time than allowed to complete an assessment. Affected products moodle <4.4.11 <4.5.7 <5.0.3 <4.1.21 Matching in nixpkgs pkgs.moodle Free and open-source learning management system (LMS) written in PHP nixos-25.05 5.0 nixos-25.05-small 5.0 nixpkgs-25.05-darwin 5.0 nixos-unstable 5.0.2 nixpkgs-unstable 5.0.2 nixos-unstable-small 5.0.2 pkgs.moodle-dl Moodle downloader that downloads course content fast from Moodle nixos-25.05 2.3.13 nixos-25.05-small 2.3.13 nixpkgs-25.05-darwin 2.3.13 nixos-unstable 2.3.13 nixpkgs-unstable 2.3.13 nixos-unstable-small 2.3.13 Package maintainers: 2 @freezeboy freezeboy @kmein Kierán Meinhardt <kmein@posteo.de>
pkgs.moodle Free and open-source learning management system (LMS) written in PHP nixos-25.05 5.0 nixos-25.05-small 5.0 nixpkgs-25.05-darwin 5.0 nixos-unstable 5.0.2 nixpkgs-unstable 5.0.2 nixos-unstable-small 5.0.2
pkgs.moodle-dl Moodle downloader that downloads course content fast from Moodle nixos-25.05 2.3.13 nixos-25.05-small 2.3.13 nixpkgs-25.05-darwin 2.3.13 nixos-unstable 2.3.13 nixpkgs-unstable 2.3.13 nixos-unstable-small 2.3.13
CVE-2025-62397 5.3 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): NONE Availability impact (A): NONE created 1 month, 2 weeks ago Moodle: router produces json instead of 404 error for invalid course id The router’s inconsistent response to invalid course IDs allowed attackers to infer which course IDs exist, potentially aiding reconnaissance. Affected products moodle <5.0.3 Matching in nixpkgs pkgs.moodle Free and open-source learning management system (LMS) written in PHP nixos-25.05 5.0 nixos-25.05-small 5.0 nixpkgs-25.05-darwin 5.0 nixos-unstable 5.0.2 nixpkgs-unstable 5.0.2 nixos-unstable-small 5.0.2 pkgs.moodle-dl Moodle downloader that downloads course content fast from Moodle nixos-25.05 2.3.13 nixos-25.05-small 2.3.13 nixpkgs-25.05-darwin 2.3.13 nixos-unstable 2.3.13 nixpkgs-unstable 2.3.13 nixos-unstable-small 2.3.13 Package maintainers: 2 @freezeboy freezeboy @kmein Kierán Meinhardt <kmein@posteo.de>
pkgs.moodle Free and open-source learning management system (LMS) written in PHP nixos-25.05 5.0 nixos-25.05-small 5.0 nixpkgs-25.05-darwin 5.0 nixos-unstable 5.0.2 nixpkgs-unstable 5.0.2 nixos-unstable-small 5.0.2
pkgs.moodle-dl Moodle downloader that downloads course content fast from Moodle nixos-25.05 2.3.13 nixos-25.05-small 2.3.13 nixpkgs-25.05-darwin 2.3.13 nixos-unstable 2.3.13 nixpkgs-unstable 2.3.13 nixos-unstable-small 2.3.13