CVE-2025-14338 created 15 hours ago Polkit authentication dis isabled by default in inputplumber Polkit authentication dis isabled by default and a race condition in the Polkit authorization check in versions before v0.69.0 can lead to the same issues as in CVE-2025-66005. Affected products inputplumber <0.63.0 Matching in nixpkgs pkgs.inputplumber Open source input router and remapper daemon for Linux nixos-unstable 0.67.1 nixpkgs-unstable 0.67.1 nixos-unstable-small 0.68.0 nixos-25.05 0.56.1 nixos-25.05-small 0.56.1 nixpkgs-25.05-darwin 0.56.1 Package maintainers: 1 @ShadowApex William Edwards <shadowapex@gmail.com>
pkgs.inputplumber Open source input router and remapper daemon for Linux nixos-unstable 0.67.1 nixpkgs-unstable 0.67.1 nixos-unstable-small 0.68.0 nixos-25.05 0.56.1 nixos-25.05-small 0.56.1 nixpkgs-25.05-darwin 0.56.1
CVE-2025-66005 created 15 hours ago Lack of Authentication in the InputManager D-Bus interface Lack of authorization of the InputManager D-Bus interface in InputPlumber versions before v0.63.0 can lead to local Denial-of-Service, information leak or even privilege escalation in the context of the currently active user session. Affected products inputplumber <0.63.0 Matching in nixpkgs pkgs.inputplumber Open source input router and remapper daemon for Linux nixos-unstable 0.67.1 nixpkgs-unstable 0.67.1 nixos-unstable-small 0.68.0 nixos-25.05 0.56.1 nixos-25.05-small 0.56.1 nixpkgs-25.05-darwin 0.56.1 Package maintainers: 1 @ShadowApex William Edwards <shadowapex@gmail.com>
pkgs.inputplumber Open source input router and remapper daemon for Linux nixos-unstable 0.67.1 nixpkgs-unstable 0.67.1 nixos-unstable-small 0.68.0 nixos-25.05 0.56.1 nixos-25.05-small 0.56.1 nixpkgs-25.05-darwin 0.56.1
CVE-2025-14242 6.5 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): HIGH created 15 hours ago Vsftpd: vsftpd: denial of service via integer overflow in ls command parameter parsing A flaw was found in vsftpd. This vulnerability allows a denial of service (DoS) via an integer overflow in the ls command parameter parsing, triggered by a remote, authenticated attacker sending a crafted STAT command with a specific byte sequence. Affected products vsftpd * Matching in nixpkgs pkgs.vsftpd Very secure FTP daemon nixos-unstable 3.0.5 nixpkgs-unstable 3.0.5 nixos-unstable-small 3.0.5 nixos-25.05 3.0.5 nixos-25.05-small 3.0.5 nixpkgs-25.05-darwin 3.0.5 Package maintainers: 1 @peterhoeg Peter Hoeg <peter@hoeg.com>
pkgs.vsftpd Very secure FTP daemon nixos-unstable 3.0.5 nixpkgs-unstable 3.0.5 nixos-unstable-small 3.0.5 nixos-25.05 3.0.5 nixos-25.05-small 3.0.5 nixpkgs-25.05-darwin 3.0.5
CVE-2026-0716 4.8 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): NONE Availability impact (A): LOW created 15 hours ago Libsoup: out-of-bounds read in libsoup websocket frame processing A flaw was found in libsoup’s WebSocket frame processing when handling incoming messages. If a non-default configuration is used where the maximum incoming payload size is unset, the library may read memory outside the intended bounds. This can cause unintended memory exposure or a crash. Applications using libsoup’s WebSocket support with this configuration may be impacted. Affected products libsoup libsoup3 Matching in nixpkgs pkgs.libsoup_3 HTTP client/server library for GNOME nixos-unstable 3.6.5 nixpkgs-unstable 3.6.5 nixos-unstable-small 3.6.5 nixos-25.05 3.6.5 nixos-25.05-small 3.6.5 nixpkgs-25.05-darwin 3.6.5 pkgs.libsoup_2_4 HTTP client/server library for GNOME nixos-unstable 2.74.3 nixpkgs-unstable 2.74.3 nixos-unstable-small 2.74.3 nixos-25.05 2.74.3 nixos-25.05-small 2.74.3 nixpkgs-25.05-darwin 2.74.3 pkgs.tests.pkg-config.defaultPkgConfigPackages."libsoup-gnome-2.4" Test whether libsoup-2.74.3 exposes pkg-config modules libsoup-gnome-2.4 nixos-unstable - nixpkgs-unstable nixos-unstable-small nixos-25.05 - nixos-25.05-small nixpkgs-25.05-darwin Package maintainers: 6 @bobby285271 Bobby Rong <rjl931189261@126.com> @lovek323 Jason O'Conal <jason@oconal.id.au> @dasj19 Daniel Șerbănescu <daniel@serbanescu.dk> @7c6f434c Michael Raskin <7c6f434c@mail.ru> @jtojnar Jan Tojnar <jtojnar@gmail.com> @hedning Tor Hedin Brønner <torhedinbronner@gmail.com>
pkgs.libsoup_3 HTTP client/server library for GNOME nixos-unstable 3.6.5 nixpkgs-unstable 3.6.5 nixos-unstable-small 3.6.5 nixos-25.05 3.6.5 nixos-25.05-small 3.6.5 nixpkgs-25.05-darwin 3.6.5
pkgs.libsoup_2_4 HTTP client/server library for GNOME nixos-unstable 2.74.3 nixpkgs-unstable 2.74.3 nixos-unstable-small 2.74.3 nixos-25.05 2.74.3 nixos-25.05-small 2.74.3 nixpkgs-25.05-darwin 2.74.3
pkgs.tests.pkg-config.defaultPkgConfigPackages."libsoup-gnome-2.4" Test whether libsoup-2.74.3 exposes pkg-config modules libsoup-gnome-2.4 nixos-unstable - nixpkgs-unstable nixos-unstable-small nixos-25.05 - nixos-25.05-small nixpkgs-25.05-darwin
CVE-2025-66388 4.3 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): NONE Availability impact (A): NONE created 5 days, 20 hours ago Apache Airflow: Secrets in rendered templates not redacted properly and exposed in the UI A vulnerability in Apache Airflow allowed authenticated UI users to view secret values in rendered templates due to secrets not being properly redacted, potentially exposing secrets to users without the appropriate authorization. Users are recommended to upgrade to version 3.1.4, which fixes this issue. Affected products apache-airflow <3.1.4 Matching in nixpkgs pkgs.apache-airflow Programmatically author, schedule and monitor data pipelines nixos-unstable 2.7.3 nixpkgs-unstable 2.7.3 nixos-unstable-small 2.7.3 nixos-25.11 2.7.3 nixos-25.11-small 2.7.3 nixpkgs-25.11-darwin 2.7.3 nixos-25.05 2.7.3 nixos-25.05-small 2.7.3 nixpkgs-25.05-darwin 2.7.3 Package maintainers: 3 @ingenieroariel Ariel Nunez <ariel@nunez.co> @bhipple Benjamin Hipple <bhipple@protonmail.com> @gbpdt Graham Bennett <nix@pdtpartners.com>
pkgs.apache-airflow Programmatically author, schedule and monitor data pipelines nixos-unstable 2.7.3 nixpkgs-unstable 2.7.3 nixos-unstable-small 2.7.3 nixos-25.11 2.7.3 nixos-25.11-small 2.7.3 nixpkgs-25.11-darwin 2.7.3 nixos-25.05 2.7.3 nixos-25.05-small 2.7.3 nixpkgs-25.05-darwin 2.7.3
CVE-2025-13053 created 6 days, 1 hour ago A missing encryption of sensitive data vulnerability was found in the UPS settings of ADM When a user configures the NAS to retrieve UPS status or control the UPS, a non-enforced TLS certificate verification can allow an attacker able to intercept network traffic between the client and server can perform a man-in-the-middle (MITM) attack, which may obtain the sensitive information of the UPS server configuation. This issue affects ADM: from 4.1.0 through 4.3.3.RKD2, from 5.0.0 through 5.1.0.RN42. Affected products UPS =<4.3.3.RKD2 =<5.1.0.RN42 Matching in nixpkgs pkgs.perlPackages.NetCUPS Common Unix Printing System Interface nixos-unstable 0.64 nixpkgs-unstable 0.64 nixos-unstable-small 0.64 nixos-25.11 0.64 nixos-25.11-small 0.64 nixpkgs-25.11-darwin 0.64 nixos-25.05 0.64 nixos-25.05-small 0.64 nixpkgs-25.05-darwin 0.64 pkgs.perl538Packages.NetCUPS Common Unix Printing System Interface nixos-unstable 0.64 nixpkgs-unstable 0.64 nixos-unstable-small 0.64 nixos-25.11 0.64 nixos-25.11-small 0.64 nixpkgs-25.11-darwin 0.64 nixos-25.05 0.64 nixos-25.05-small 0.64 nixpkgs-25.05-darwin 0.64 pkgs.perl540Packages.NetCUPS Common Unix Printing System Interface nixos-unstable 0.64 nixpkgs-unstable 0.64 nixos-unstable-small 0.64 nixos-25.11 - nixos-25.11-small 0.64 nixpkgs-25.11-darwin 0.64 nixos-25.05 0.64 nixos-25.05-small 0.64 nixpkgs-25.05-darwin 0.64
pkgs.perlPackages.NetCUPS Common Unix Printing System Interface nixos-unstable 0.64 nixpkgs-unstable 0.64 nixos-unstable-small 0.64 nixos-25.11 0.64 nixos-25.11-small 0.64 nixpkgs-25.11-darwin 0.64 nixos-25.05 0.64 nixos-25.05-small 0.64 nixpkgs-25.05-darwin 0.64
pkgs.perl538Packages.NetCUPS Common Unix Printing System Interface nixos-unstable 0.64 nixpkgs-unstable 0.64 nixos-unstable-small 0.64 nixos-25.11 0.64 nixos-25.11-small 0.64 nixpkgs-25.11-darwin 0.64 nixos-25.05 0.64 nixos-25.05-small 0.64 nixpkgs-25.05-darwin 0.64
pkgs.perl540Packages.NetCUPS Common Unix Printing System Interface nixos-unstable 0.64 nixpkgs-unstable 0.64 nixos-unstable-small 0.64 nixos-25.11 - nixos-25.11-small 0.64 nixpkgs-25.11-darwin 0.64 nixos-25.05 0.64 nixos-25.05-small 0.64 nixpkgs-25.05-darwin 0.64
CVE-2023-0835 8.2 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): CHANGED Confidentiality impact (C): HIGH Integrity impact (I): LOW Availability impact (A): NONE created 6 days, 3 hours ago markdown-pdf 11.0.0 - Local File Read via Server Side XSS markdown-pdf version 11.0.0 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the Markdown content entered by the user. Affected products markdown-pdf ==11.0.0 Matching in nixpkgs pkgs.vscode-extensions.yzane.markdown-pdf Converts Markdown files to pdf, html, png or jpeg files nixos-unstable 1.5.0 nixpkgs-unstable 1.5.0 nixos-unstable-small 1.5.0 nixos-25.11 1.5.0 nixos-25.11-small 1.5.0 nixpkgs-25.11-darwin 1.5.0 nixos-25.05 1.5.0 nixos-25.05-small 1.5.0 nixpkgs-25.05-darwin 1.5.0 Package maintainers: 1 @Pandapip1 Gavin John <gavinnjohn@gmail.com>
pkgs.vscode-extensions.yzane.markdown-pdf Converts Markdown files to pdf, html, png or jpeg files nixos-unstable 1.5.0 nixpkgs-unstable 1.5.0 nixos-unstable-small 1.5.0 nixos-25.11 1.5.0 nixos-25.11-small 1.5.0 nixpkgs-25.11-darwin 1.5.0 nixos-25.05 1.5.0 nixos-25.05-small 1.5.0 nixpkgs-25.05-darwin 1.5.0
CVE-2025-62230 7.3 HIGH CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): LOW Availability impact (A): HIGH created 1 month, 3 weeks ago Xorg: xwayland: use-after-free in xkb client resource removal A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The software frees certain data structures without properly detaching related resources, leading to a use-after-free condition. This can cause memory corruption or a crash when affected clients disconnect. Affected products tigervnc * xwayland <24.1.9 xorg-x11-server * xorg-x11-server-Xwayland * Matching in nixpkgs pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-unstable 1.15.0 nixpkgs-unstable 1.15.0 nixos-unstable-small 1.15.0 nixos-25.05 1.14.0 nixos-25.05-small 1.14.0 nixpkgs-25.05-darwin 1.14.0
pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-unstable 1.15.0 nixpkgs-unstable 1.15.0 nixos-unstable-small 1.15.0 nixos-25.05 1.14.0 nixos-25.05-small 1.14.0 nixpkgs-25.05-darwin 1.14.0
CVE-2025-62402 5.4 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): NONE created 1 month, 3 weeks ago Apache Airflow: Airflow 3 API: /api/v2/dagReports executes DAG Python in API API users via `/api/v2/dagReports` could perform Dag code execution in the context of the api-server if the api-server was deployed in the environment where Dag files were available. Affected products apache-airflow <3.1.1 Matching in nixpkgs pkgs.apache-airflow Programmatically author, schedule and monitor data pipelines nixos-unstable 2.7.3 nixpkgs-unstable 2.7.3 nixos-unstable-small 2.7.3 nixos-25.05 2.7.3 nixos-25.05-small 2.7.3 nixpkgs-25.05-darwin 2.7.3 Package maintainers: 3 @ingenieroariel Ariel Nunez <ariel@nunez.co> @bhipple Benjamin Hipple <bhipple@protonmail.com> @gbpdt Graham Bennett <nix@pdtpartners.com>
pkgs.apache-airflow Programmatically author, schedule and monitor data pipelines nixos-unstable 2.7.3 nixpkgs-unstable 2.7.3 nixos-unstable-small 2.7.3 nixos-25.05 2.7.3 nixos-25.05-small 2.7.3 nixpkgs-25.05-darwin 2.7.3
CVE-2025-62231 7.3 HIGH CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): LOW Availability impact (A): HIGH created 1 month, 3 weeks ago Xorg: xmayland: value overflow in xkbsetcompatmap() A flaw was identified in the X.Org X server’s X Keyboard (Xkb) extension where improper bounds checking in the XkbSetCompatMap() function can cause an unsigned short overflow. If an attacker sends specially crafted input data, the value calculation may overflow, leading to memory corruption or a crash. Affected products tigervnc * xwayland <24.1.9 xorg-x11-server * xorg-x11-server-Xwayland * Matching in nixpkgs pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-unstable 1.15.0 nixpkgs-unstable 1.15.0 nixos-unstable-small 1.15.0 nixos-25.05 1.14.0 nixos-25.05-small 1.14.0 nixpkgs-25.05-darwin 1.14.0
pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-unstable 1.15.0 nixpkgs-unstable 1.15.0 nixos-unstable-small 1.15.0 nixos-25.05 1.14.0 nixos-25.05-small 1.14.0 nixpkgs-25.05-darwin 1.14.0