CVE-2026-23518 created 19 hours ago Fleet has a JWT signature bypass vulnerability in Azure AD MDM enrollment Fleet is open source device management software. In versions prior to 4.78.3, 4.77.1, 4.76.2, 4.75.2, and 4.53.3, a vulnerability in Fleet's Windows MDM enrollment flow could allow an attacker to submit forged authentication tokens that are not properly validated. Because JWT signatures were not verified, Fleet could accept attacker-controlled identity claims, enabling enrollment of unauthorized devices under arbitrary Azure AD user identities. Versions 4.78.3, 4.77.1, 4.76.2, 4.75.2, and 4.53.3 fix the issue. If an immediate upgrade is not possible, affected Fleet users should temporarily disable Windows MDM. Affected products fleet ==>= 4.77.0, < 4.77.1 ==>= 4.78.0, < 4.78.3 ==>= 4.75.0, < 4.75.2 ==>= 4.76.0, < 4.76.2 ==< 4.53.3 Matching in nixpkgs pkgs.fleet CLI tool to launch Fleet server nixos-unstable 4.75.1 nixpkgs-unstable 4.75.1 nixos-unstable-small 4.76.1 nixos-25.05 4.67.3 nixos-25.05-small 4.67.3 nixpkgs-25.05-darwin 4.67.3 pkgs.fleetctl CLI tool for managing Fleet nixos-unstable 4.75.1 nixpkgs-unstable 4.75.1 nixos-unstable-small 4.76.1 nixos-25.05 4.67.3 nixos-25.05-small 4.67.3 nixpkgs-25.05-darwin 4.67.3 pkgs.fleeting-plugin-aws GitLab fleeting plugin for AWS nixos-unstable 1.1.0 nixpkgs-unstable 1.1.0 nixos-unstable-small 1.1.0 nixos-25.05 1.0.1 nixos-25.05-small 1.0.1 nixpkgs-25.05-darwin 1.0.1 pkgs.azure-cli-extensions.fleet Microsoft Azure Command-Line Tools Fleet Extension nixos-unstable 1.8.1 nixpkgs-unstable 1.8.1 nixos-unstable-small 1.8.1 nixos-25.05 1.5.2 nixos-25.05-small 1.5.2 nixpkgs-25.05-darwin 1.5.2 pkgs.python312Packages.tesla-fleet-api Python library for Tesla Fleet API and Teslemetry nixos-unstable 1.2.5 nixpkgs-unstable 1.2.5 nixos-unstable-small 1.2.5 nixos-25.05 1.0.17 nixos-25.05-small 1.0.17 nixpkgs-25.05-darwin 1.0.17 pkgs.python313Packages.tesla-fleet-api Python library for Tesla Fleet API and Teslemetry nixos-unstable 1.2.5 nixpkgs-unstable 1.2.5 nixos-unstable-small 1.2.5 nixos-25.05 1.0.17 nixos-25.05-small 1.0.17 nixpkgs-25.05-darwin 1.0.17 pkgs.haskellPackages.amazonka-iotfleethub Amazon IoT Fleet Hub SDK nixos-unstable 2.0-unstable-2025-04-16 nixpkgs-unstable 2.0-unstable-2025-04-16 nixos-unstable-small 2.0-unstable-2025-04-16 nixos-25.05 2.0 nixos-25.05-small 2.0 nixpkgs-25.05-darwin 2.0 pkgs.haskellPackages.amazonka-iotfleetwise Amazon IoT FleetWise SDK nixos-unstable 2.0-unstable-2025-04-16 nixpkgs-unstable 2.0-unstable-2025-04-16 nixos-unstable-small 2.0-unstable-2025-04-16 nixos-25.05 2.0 nixos-25.05-small 2.0 nixpkgs-25.05-darwin 2.0 pkgs.python312Packages.mypy-boto3-iotfleethub Type annotations for boto3 iotfleethub nixos-unstable boto3-iotfleethub-1.40.17 nixpkgs-unstable boto3-iotfleethub-1.40.17 nixos-unstable-small boto3-iotfleethub-1.40.17 nixos-25.05 boto3-iotfleethub-1.38.0 nixos-25.05-small boto3-iotfleethub-1.38.0 nixpkgs-25.05-darwin boto3-iotfleethub-1.38.0 pkgs.python313Packages.mypy-boto3-iotfleethub Type annotations for boto3 iotfleethub nixos-unstable boto3-iotfleethub-1.40.17 nixpkgs-unstable boto3-iotfleethub-1.40.17 nixos-unstable-small boto3-iotfleethub-1.40.17 nixos-25.05 boto3-iotfleethub-1.38.0 nixos-25.05-small boto3-iotfleethub-1.38.0 nixpkgs-25.05-darwin boto3-iotfleethub-1.38.0 pkgs.python312Packages.mypy-boto3-iotfleetwise Type annotations for boto3 iotfleetwise nixos-unstable boto3-iotfleetwise-1.41.0 nixpkgs-unstable boto3-iotfleetwise-1.41.0 nixos-unstable-small boto3-iotfleetwise-1.41.0 nixos-25.05 boto3-iotfleetwise-1.38.0 nixos-25.05-small boto3-iotfleetwise-1.38.0 nixpkgs-25.05-darwin boto3-iotfleetwise-1.38.0 pkgs.python313Packages.mypy-boto3-iotfleetwise Type annotations for boto3 iotfleetwise nixos-unstable boto3-iotfleetwise-1.41.0 nixpkgs-unstable boto3-iotfleetwise-1.41.0 nixos-unstable-small boto3-iotfleetwise-1.41.0 nixos-25.05 boto3-iotfleetwise-1.38.0 nixos-25.05-small boto3-iotfleetwise-1.38.0 nixpkgs-25.05-darwin boto3-iotfleetwise-1.38.0 pkgs.home-assistant-component-tests.tesla_fleet Open source home automation that puts local control and privacy first nixos-unstable 2025.11.3 nixpkgs-unstable 2025.11.3 nixos-unstable-small 2025.11.3 nixos-25.05 2025.5.2 nixos-25.05-small 2025.5.2 nixpkgs-25.05-darwin 2025.5.2 pkgs.python312Packages.types-aiobotocore-iotfleethub Type annotations for aiobotocore iotfleethub nixos-unstable 2.24.2 nixpkgs-unstable 2.24.2 nixos-unstable-small 2.24.2 nixos-25.05 2.21.1 nixos-25.05-small 2.21.1 nixpkgs-25.05-darwin 2.21.1 pkgs.python313Packages.types-aiobotocore-iotfleethub Type annotations for aiobotocore iotfleethub nixos-unstable 2.24.2 nixpkgs-unstable 2.24.2 nixos-unstable-small 2.24.2 nixos-25.05 2.21.1 nixos-25.05-small 2.21.1 nixpkgs-25.05-darwin 2.21.1 pkgs.python312Packages.types-aiobotocore-iotfleetwise Type annotations for aiobotocore iotfleetwise nixos-unstable 2.25.2 nixpkgs-unstable 2.25.2 nixos-unstable-small 2.25.2 nixos-25.05 2.21.1 nixos-25.05-small 2.21.1 nixpkgs-25.05-darwin 2.21.1 pkgs.python313Packages.types-aiobotocore-iotfleetwise Type annotations for aiobotocore iotfleetwise nixos-unstable 2.25.2 nixpkgs-unstable 2.25.2 nixos-unstable-small 2.25.2 nixos-25.05 2.21.1 nixos-25.05-small 2.21.1 nixpkgs-25.05-darwin 2.21.1 Package maintainers: 9 @katexochen Paul Meyer <katexochen0@gmail.com> @ulrikstrid Ulrik Strid <ulrik.strid@outlook.com> @LeSuisse Thomas Gerbet <thomas@gerbet.me> @AntoineSauzeau Antoine Sauzeau <antoine.sauzeau3@gmail.com> @commiterate commiterate @dotlambda Robert Schütz <rschuetz17@gmail.com> @fabaff Fabian Affolter <mail@fabian-affolter.ch> @mweinelt Martin Weinelt <hexa@darmstadt.ccc.de> @mbalatsko Maksym Balatsko <mbalatsko@gmail.com>
fleet ==>= 4.77.0, < 4.77.1 ==>= 4.78.0, < 4.78.3 ==>= 4.75.0, < 4.75.2 ==>= 4.76.0, < 4.76.2 ==< 4.53.3
pkgs.fleet CLI tool to launch Fleet server nixos-unstable 4.75.1 nixpkgs-unstable 4.75.1 nixos-unstable-small 4.76.1 nixos-25.05 4.67.3 nixos-25.05-small 4.67.3 nixpkgs-25.05-darwin 4.67.3
pkgs.fleetctl CLI tool for managing Fleet nixos-unstable 4.75.1 nixpkgs-unstable 4.75.1 nixos-unstable-small 4.76.1 nixos-25.05 4.67.3 nixos-25.05-small 4.67.3 nixpkgs-25.05-darwin 4.67.3
pkgs.fleeting-plugin-aws GitLab fleeting plugin for AWS nixos-unstable 1.1.0 nixpkgs-unstable 1.1.0 nixos-unstable-small 1.1.0 nixos-25.05 1.0.1 nixos-25.05-small 1.0.1 nixpkgs-25.05-darwin 1.0.1
pkgs.azure-cli-extensions.fleet Microsoft Azure Command-Line Tools Fleet Extension nixos-unstable 1.8.1 nixpkgs-unstable 1.8.1 nixos-unstable-small 1.8.1 nixos-25.05 1.5.2 nixos-25.05-small 1.5.2 nixpkgs-25.05-darwin 1.5.2
pkgs.python312Packages.tesla-fleet-api Python library for Tesla Fleet API and Teslemetry nixos-unstable 1.2.5 nixpkgs-unstable 1.2.5 nixos-unstable-small 1.2.5 nixos-25.05 1.0.17 nixos-25.05-small 1.0.17 nixpkgs-25.05-darwin 1.0.17
pkgs.python313Packages.tesla-fleet-api Python library for Tesla Fleet API and Teslemetry nixos-unstable 1.2.5 nixpkgs-unstable 1.2.5 nixos-unstable-small 1.2.5 nixos-25.05 1.0.17 nixos-25.05-small 1.0.17 nixpkgs-25.05-darwin 1.0.17
pkgs.haskellPackages.amazonka-iotfleethub Amazon IoT Fleet Hub SDK nixos-unstable 2.0-unstable-2025-04-16 nixpkgs-unstable 2.0-unstable-2025-04-16 nixos-unstable-small 2.0-unstable-2025-04-16 nixos-25.05 2.0 nixos-25.05-small 2.0 nixpkgs-25.05-darwin 2.0
pkgs.haskellPackages.amazonka-iotfleetwise Amazon IoT FleetWise SDK nixos-unstable 2.0-unstable-2025-04-16 nixpkgs-unstable 2.0-unstable-2025-04-16 nixos-unstable-small 2.0-unstable-2025-04-16 nixos-25.05 2.0 nixos-25.05-small 2.0 nixpkgs-25.05-darwin 2.0
pkgs.python312Packages.mypy-boto3-iotfleethub Type annotations for boto3 iotfleethub nixos-unstable boto3-iotfleethub-1.40.17 nixpkgs-unstable boto3-iotfleethub-1.40.17 nixos-unstable-small boto3-iotfleethub-1.40.17 nixos-25.05 boto3-iotfleethub-1.38.0 nixos-25.05-small boto3-iotfleethub-1.38.0 nixpkgs-25.05-darwin boto3-iotfleethub-1.38.0
pkgs.python313Packages.mypy-boto3-iotfleethub Type annotations for boto3 iotfleethub nixos-unstable boto3-iotfleethub-1.40.17 nixpkgs-unstable boto3-iotfleethub-1.40.17 nixos-unstable-small boto3-iotfleethub-1.40.17 nixos-25.05 boto3-iotfleethub-1.38.0 nixos-25.05-small boto3-iotfleethub-1.38.0 nixpkgs-25.05-darwin boto3-iotfleethub-1.38.0
pkgs.python312Packages.mypy-boto3-iotfleetwise Type annotations for boto3 iotfleetwise nixos-unstable boto3-iotfleetwise-1.41.0 nixpkgs-unstable boto3-iotfleetwise-1.41.0 nixos-unstable-small boto3-iotfleetwise-1.41.0 nixos-25.05 boto3-iotfleetwise-1.38.0 nixos-25.05-small boto3-iotfleetwise-1.38.0 nixpkgs-25.05-darwin boto3-iotfleetwise-1.38.0
pkgs.python313Packages.mypy-boto3-iotfleetwise Type annotations for boto3 iotfleetwise nixos-unstable boto3-iotfleetwise-1.41.0 nixpkgs-unstable boto3-iotfleetwise-1.41.0 nixos-unstable-small boto3-iotfleetwise-1.41.0 nixos-25.05 boto3-iotfleetwise-1.38.0 nixos-25.05-small boto3-iotfleetwise-1.38.0 nixpkgs-25.05-darwin boto3-iotfleetwise-1.38.0
pkgs.home-assistant-component-tests.tesla_fleet Open source home automation that puts local control and privacy first nixos-unstable 2025.11.3 nixpkgs-unstable 2025.11.3 nixos-unstable-small 2025.11.3 nixos-25.05 2025.5.2 nixos-25.05-small 2025.5.2 nixpkgs-25.05-darwin 2025.5.2
pkgs.python312Packages.types-aiobotocore-iotfleethub Type annotations for aiobotocore iotfleethub nixos-unstable 2.24.2 nixpkgs-unstable 2.24.2 nixos-unstable-small 2.24.2 nixos-25.05 2.21.1 nixos-25.05-small 2.21.1 nixpkgs-25.05-darwin 2.21.1
pkgs.python313Packages.types-aiobotocore-iotfleethub Type annotations for aiobotocore iotfleethub nixos-unstable 2.24.2 nixpkgs-unstable 2.24.2 nixos-unstable-small 2.24.2 nixos-25.05 2.21.1 nixos-25.05-small 2.21.1 nixpkgs-25.05-darwin 2.21.1
pkgs.python312Packages.types-aiobotocore-iotfleetwise Type annotations for aiobotocore iotfleetwise nixos-unstable 2.25.2 nixpkgs-unstable 2.25.2 nixos-unstable-small 2.25.2 nixos-25.05 2.21.1 nixos-25.05-small 2.21.1 nixpkgs-25.05-darwin 2.21.1
pkgs.python313Packages.types-aiobotocore-iotfleetwise Type annotations for aiobotocore iotfleetwise nixos-unstable 2.25.2 nixpkgs-unstable 2.25.2 nixos-unstable-small 2.25.2 nixos-25.05 2.21.1 nixos-25.05-small 2.21.1 nixpkgs-25.05-darwin 2.21.1
CVE-2026-23524 created 19 hours ago Laravel Redis Horizontal Scaling Insecure Deserialization Laravel Reverb provides a real-time WebSocket communication backend for Laravel applications. In versions 1.6.3 and below, Reverb passes data from the Redis channel directly into PHP’s unserialize() function without restricting which classes can be instantiated, which leaves users vulnerable to Remote Code Execution. The exploitability of this vulnerability is increased because Redis servers are commonly deployed without authentication, but only affects Laravel Reverb when horizontal scaling is enabled (REVERB_SCALING_ENABLED=true). This issue has been fixed in version 1.7.0. As a workaround, require a strong password for Redis access and ensure the service is only accessible via a private network or local loopback, and/or set REVERB_SCALING_ENABLED=false to bypass the vulnerable logic entirely (if the environment uses only one Reverb node). Affected products reverb ==< 1.7.0 Matching in nixpkgs pkgs.hybridreverb2 Reverb effect using hybrid impulse convolution nixos-unstable 2.1.2-unstable-2021-12-19 nixpkgs-unstable 2.1.2-unstable-2021-12-19 nixos-unstable-small 2.1.2-unstable-2021-12-19 nixos-25.05 2.1.2-unstable-2021-12-19 nixos-25.05-small 2.1.2-unstable-2021-12-19 nixpkgs-25.05-darwin 2.1.2-unstable-2021-12-19 pkgs.dragonfly-reverb Hall-style reverb based on freeverb3 algorithms nixos-unstable 3.2.10 nixpkgs-unstable 3.2.10 nixos-unstable-small 3.2.10 nixos-25.05 3.2.10 nixos-25.05-small 3.2.10 nixpkgs-25.05-darwin 3.2.10 Package maintainers: 1 @magnetophon Bart Brouns <bart@magnetophon.nl>
pkgs.hybridreverb2 Reverb effect using hybrid impulse convolution nixos-unstable 2.1.2-unstable-2021-12-19 nixpkgs-unstable 2.1.2-unstable-2021-12-19 nixos-unstable-small 2.1.2-unstable-2021-12-19 nixos-25.05 2.1.2-unstable-2021-12-19 nixos-25.05-small 2.1.2-unstable-2021-12-19 nixpkgs-25.05-darwin 2.1.2-unstable-2021-12-19
pkgs.dragonfly-reverb Hall-style reverb based on freeverb3 algorithms nixos-unstable 3.2.10 nixpkgs-unstable 3.2.10 nixos-unstable-small 3.2.10 nixos-25.05 3.2.10 nixos-25.05-small 3.2.10 nixpkgs-25.05-darwin 3.2.10
CVE-2026-0988 created 19 hours ago Glib: glib: denial of service via integer overflow in g_buffered_input_stream_peek() A flaw was found in glib. Missing validation of offset and count parameters in the g_buffered_input_stream_peek() function can lead to an integer overflow during length calculation. When specially crafted values are provided, this overflow results in an incorrect size being passed to memcpy(), triggering a buffer overflow. This can cause application crashes, leading to a Denial of Service (DoS). Affected products bootc glib2 loupe papers librsvg2 rpm-ostree mingw-glib2 glycin-loaders Matching in nixpkgs pkgs.bootc Boot and upgrade via container images nixos-unstable 1.6.0 nixpkgs-unstable 1.6.0 nixos-unstable-small 1.6.0 nixos-25.05 1.1.2 nixos-25.05-small 1.1.2 nixpkgs-25.05-darwin 1.1.2 pkgs.loupe Simple image viewer application written with GTK4 and Rust nixos-unstable 49.1 nixpkgs-unstable 49.1 nixos-unstable-small 49.1 nixos-25.05 48.1 nixos-25.05-small 48.1 nixpkgs-25.05-darwin 48.1 pkgs.papers GNOME's document viewer nixos-unstable 49.1 nixpkgs-unstable 49.1 nixos-unstable-small 49.1 nixos-25.05 48.2 nixos-25.05-small 48.2 nixpkgs-25.05-darwin 48.2 pkgs.qbootctl Qualcomm bootctl HAL for Linux nixos-unstable 0.2.2 nixpkgs-unstable 0.2.2 nixos-unstable-small 0.2.2 pkgs.rpm-ostree Hybrid image/package system. It uses OSTree as an image format, and uses RPM as a component model nixos-unstable 2024.8 nixpkgs-unstable 2024.8 nixos-unstable-small 2024.8 nixos-25.05 2024.8 nixos-25.05-small 2024.8 nixpkgs-25.05-darwin 2024.8 pkgs.podman-bootc Streamlining podman+bootc interactions nixos-unstable 0.1.2 nixpkgs-unstable 0.1.2 nixos-unstable-small 0.1.2 nixos-25.05 0.1.2 nixos-25.05-small 0.1.2 nixpkgs-25.05-darwin 0.1.2 pkgs.mlxbf-bootctl Control BlueField boot partitions nixos-unstable 2025-01-16 nixpkgs-unstable 2025-01-16 nixos-unstable-small 2025-01-16 nixos-25.05 1.1-6 nixos-25.05-small 1.1-6 nixpkgs-25.05-darwin 1.1-6 pkgs.glycin-loaders Glycin loaders for several formats nixos-unstable 2.0.5 nixpkgs-unstable 2.0.5 nixos-unstable-small 2.0.5 nixos-25.05 1.2.1 nixos-25.05-small 1.2.1 nixpkgs-25.05-darwin 1.2.1 pkgs.pop-wallpapers Wallpapers for Pop!_OS nixos-unstable 1.0.5-unstable-2025-06-24 nixpkgs-unstable 1.0.5-unstable-2025-06-24 nixos-unstable-small 1.0.5-unstable-2025-06-24 nixos-25.05 1.0.5-unstable-2025-06-24 nixos-25.05-small 1.0.5-unstable-2025-06-24 nixpkgs-25.05-darwin 1.0.5-unstable-2025-06-24 pkgs.cosmic-wallpapers Wallpapers for the COSMIC Desktop Environment nixos-unstable 1.0.0-beta.7 nixpkgs-unstable 1.0.0-beta.7 nixos-unstable-small 1.0.0-beta.7 nixos-25.05 1.0.0-alpha.7 nixos-25.05-small 1.0.0-alpha.7 nixpkgs-25.05-darwin 1.0.0-alpha.7 pkgs.pop-hp-wallpapers Wallpapers for High-Performance System76 products nixos-unstable 0-unstable-2025-10-28 nixpkgs-unstable 0-unstable-2025-10-28 nixos-unstable-small 0-unstable-2025-10-28 nixos-25.05 0-unstable-2022-04-01 nixos-25.05-small 0-unstable-2022-04-01 nixpkgs-25.05-darwin 0-unstable-2022-04-01 pkgs.systemd-bootchart Boot performance graphing tool from systemd nixos-unstable 235 nixpkgs-unstable 235 nixos-unstable-small 235 pkgs.rubyPackages.glib2 None nixos-unstable glib2-4.3.3 nixpkgs-unstable glib2-4.3.3 nixos-unstable-small glib2-4.3.3 nixos-25.05 glib2-4.2.9 nixos-25.05-small glib2-4.2.9 nixpkgs-25.05-darwin glib2-4.2.9 pkgs.system76-wallpapers Wallpapers for System76 products nixos-unstable 0-unstable-2024-04-26 nixpkgs-unstable 0-unstable-2024-04-26 nixos-unstable-small 0-unstable-2024-04-26 nixos-25.05 0-unstable-2024-04-26 nixos-25.05-small 0-unstable-2024-04-26 nixpkgs-25.05-darwin 0-unstable-2024-04-26 pkgs.rubyPackages_3_1.glib2 None nixos-25.05 glib2-4.2.9 nixos-25.05-small glib2-4.2.9 nixpkgs-25.05-darwin glib2-4.2.9 pkgs.rubyPackages_3_2.glib2 None nixos-25.05 glib2-4.2.9 nixos-25.05-small glib2-4.2.9 nixpkgs-25.05-darwin glib2-4.2.9 pkgs.rubyPackages_3_3.glib2 None nixos-unstable glib2-4.3.3 nixpkgs-unstable glib2-4.3.3 nixos-unstable-small glib2-4.3.3 nixos-25.05 glib2-4.2.9 nixos-25.05-small glib2-4.2.9 nixpkgs-25.05-darwin glib2-4.2.9 pkgs.rubyPackages_3_4.glib2 None nixos-unstable glib2-4.3.3 nixpkgs-unstable glib2-4.3.3 nixos-unstable-small glib2-4.3.3 nixos-25.05 glib2-4.2.9 nixos-25.05-small glib2-4.2.9 nixpkgs-25.05-darwin glib2-4.2.9 pkgs.rubyPackages_3_5.glib2 None nixos-unstable glib2-4.3.3 nixpkgs-unstable glib2-4.3.3 nixos-unstable-small glib2-4.3.3 pkgs.deepin.deepin-wallpapers deepin-wallpapers provides wallpapers of dde nixos-25.05 1.7.16 nixos-25.05-small 1.7.16 nixpkgs-25.05-darwin 1.7.16 pkgs.lomiri.lomiri-wallpapers Wallpapers for the Lomiri Operating Environment, gathered from people of the Ubuntu Touch / UBports community nixos-unstable 20.04.0 nixpkgs-unstable 20.04.0 nixos-unstable-small 20.04.0 nixos-25.05 20.04.0 nixos-25.05-small 20.04.0 nixpkgs-25.05-darwin 20.04.0 pkgs.perlPackages.Apppapersway PaperWM-like scrollable tiling window management for Sway/i3wm nixos-unstable 2.001 nixpkgs-unstable 2.001 nixos-unstable-small 2.001 nixos-25.05 1.004 nixos-25.05-small 1.004 nixpkgs-25.05-darwin 1.004 pkgs.gnomeExtensions.2-wallpapers Changes the wallpaper based on whether there are open windows or not. nixos-unstable 2-wallpapers-6 nixpkgs-unstable 2-wallpapers-6 nixos-unstable-small 2-wallpapers-6 pkgs.perl538Packages.Apppapersway PaperWM-like scrollable tiling window management for Sway/i3wm nixos-unstable 2.001 nixpkgs-unstable 2.001 nixos-unstable-small 2.001 nixos-25.05 1.004 nixos-25.05-small 1.004 nixpkgs-25.05-darwin 1.004 pkgs.perl540Packages.Apppapersway PaperWM-like scrollable tiling window management for Sway/i3wm nixos-unstable 2.001 nixpkgs-unstable 2.001 nixos-unstable-small 2.001 pkgs.pantheon.elementary-wallpapers Collection of wallpapers for elementary nixos-unstable 8.0.0 nixpkgs-unstable 8.0.0 nixos-unstable-small 8.0.0 nixos-25.05 8.0.0 nixos-25.05-small 8.0.0 nixpkgs-25.05-darwin 8.0.0 pkgs.libsForQt5.plasma-workspace-wallpapers None nixos-25.05 5.27.11 nixos-25.05-small 5.27.11 nixpkgs-25.05-darwin 5.27.11 pkgs.kdePackages.plasma-workspace-wallpapers Wallpapers for Plasma Workspaces nixos-unstable 6.5.3 nixpkgs-unstable 6.5.3 nixos-unstable-small 6.5.3 nixos-25.05 6.3.6 nixos-25.05-small 6.3.6 nixpkgs-25.05-darwin 6.3.6 pkgs.plasma5Packages.plasma-workspace-wallpapers None nixos-25.05 5.27.11 nixos-25.05-small 5.27.11 nixpkgs-25.05-darwin 5.27.11 Package maintainers: 37 @Thesola10 Karim Vergnes <me@thesola.io> @michaelBelsanti Mike Belsanti <mbels03@protonmail.com> @thefossguy Pratham Patel <prathampatel@thefossguy.com> @alyssais Alyssa Ross <hi@alyssa.is> @HeitorAugustoLN Heitor Augusto <nixpkgs.woven713@passmail.net> @drakon64 Evelyn Chance <nixpkgs@drakon.cloud> @a-kenji Alexander Kenji Berthold <aks.kenji@protonmail.com> @nyabinary Niko Cantero <nyanbinary@keemail.me> @Pandapip1 Gavin John <gavinnjohn@gmail.com> @ahoneybun Aaron Honeycutt <aaronhoneycutt@proton.me> @wineee Lu Hongxu <lhongxu@outlook.com> @jtojnar Jan Tojnar <jtojnar@gmail.com> @bobby285271 Bobby Rong <rjl931189261@126.com> @hedning Tor Hedin Brønner <torhedinbronner@gmail.com> @dasj19 Daniel Șerbănescu <daniel@serbanescu.dk> @NickCao Nick Cao <nickcao@nichi.co> @FRidh Frederik Rietdijk <fridh@fridh.nl> @mjm Matt Moriarity <matt@mattmoriarity.com> @nyanloutre Paul Trehiou <paul@nyanlout.re> @ttuegel Thomas Tuegel <ttuegel@mailbox.org> @SCOTT-HAMILTON Scott Hamilton <sgn.hamilton@protonmail.com> @K900 Ilya K. <me@0upti.me> @ilya-fedin Ilya Fedin <fedin-ilja2010@ya.ru> @peterhoeg Peter Hoeg <peter@hoeg.com> @SuperSandro2000 Sandro Jäckel <sandro.jaeckel@gmail.com> @LunNova Luna Nova <nixpkgs-maintainer@lunnova.dev> @bkchr Bastian Köcher <nixos@kchr.de> @OPNA2608 Cosima Neidahl <opna2608@protonmail.com> @06kellyjac Jack <hello+nixpkgs@j-k.io> @nikstur nikstur <nikstur@outlook.com> @davidak David Kleuker <post@davidak.de> @fgaz Francesco Gazzetta <fgaz@fgaz.me> @evan-goode Evan Goode <mail@evangoo.de> @normalcea normalcea <normalc@posteo.net> @honnip Jung seungwoo <me@honnip.page> @numinit Morgan Jones <me+nixpkgs@numin.it> @brianmcgillion Brian McGillion <bmg.avoin@gmail.com>
pkgs.bootc Boot and upgrade via container images nixos-unstable 1.6.0 nixpkgs-unstable 1.6.0 nixos-unstable-small 1.6.0 nixos-25.05 1.1.2 nixos-25.05-small 1.1.2 nixpkgs-25.05-darwin 1.1.2
pkgs.loupe Simple image viewer application written with GTK4 and Rust nixos-unstable 49.1 nixpkgs-unstable 49.1 nixos-unstable-small 49.1 nixos-25.05 48.1 nixos-25.05-small 48.1 nixpkgs-25.05-darwin 48.1
pkgs.papers GNOME's document viewer nixos-unstable 49.1 nixpkgs-unstable 49.1 nixos-unstable-small 49.1 nixos-25.05 48.2 nixos-25.05-small 48.2 nixpkgs-25.05-darwin 48.2
pkgs.qbootctl Qualcomm bootctl HAL for Linux nixos-unstable 0.2.2 nixpkgs-unstable 0.2.2 nixos-unstable-small 0.2.2
pkgs.rpm-ostree Hybrid image/package system. It uses OSTree as an image format, and uses RPM as a component model nixos-unstable 2024.8 nixpkgs-unstable 2024.8 nixos-unstable-small 2024.8 nixos-25.05 2024.8 nixos-25.05-small 2024.8 nixpkgs-25.05-darwin 2024.8
pkgs.podman-bootc Streamlining podman+bootc interactions nixos-unstable 0.1.2 nixpkgs-unstable 0.1.2 nixos-unstable-small 0.1.2 nixos-25.05 0.1.2 nixos-25.05-small 0.1.2 nixpkgs-25.05-darwin 0.1.2
pkgs.mlxbf-bootctl Control BlueField boot partitions nixos-unstable 2025-01-16 nixpkgs-unstable 2025-01-16 nixos-unstable-small 2025-01-16 nixos-25.05 1.1-6 nixos-25.05-small 1.1-6 nixpkgs-25.05-darwin 1.1-6
pkgs.glycin-loaders Glycin loaders for several formats nixos-unstable 2.0.5 nixpkgs-unstable 2.0.5 nixos-unstable-small 2.0.5 nixos-25.05 1.2.1 nixos-25.05-small 1.2.1 nixpkgs-25.05-darwin 1.2.1
pkgs.pop-wallpapers Wallpapers for Pop!_OS nixos-unstable 1.0.5-unstable-2025-06-24 nixpkgs-unstable 1.0.5-unstable-2025-06-24 nixos-unstable-small 1.0.5-unstable-2025-06-24 nixos-25.05 1.0.5-unstable-2025-06-24 nixos-25.05-small 1.0.5-unstable-2025-06-24 nixpkgs-25.05-darwin 1.0.5-unstable-2025-06-24
pkgs.cosmic-wallpapers Wallpapers for the COSMIC Desktop Environment nixos-unstable 1.0.0-beta.7 nixpkgs-unstable 1.0.0-beta.7 nixos-unstable-small 1.0.0-beta.7 nixos-25.05 1.0.0-alpha.7 nixos-25.05-small 1.0.0-alpha.7 nixpkgs-25.05-darwin 1.0.0-alpha.7
pkgs.pop-hp-wallpapers Wallpapers for High-Performance System76 products nixos-unstable 0-unstable-2025-10-28 nixpkgs-unstable 0-unstable-2025-10-28 nixos-unstable-small 0-unstable-2025-10-28 nixos-25.05 0-unstable-2022-04-01 nixos-25.05-small 0-unstable-2022-04-01 nixpkgs-25.05-darwin 0-unstable-2022-04-01
pkgs.systemd-bootchart Boot performance graphing tool from systemd nixos-unstable 235 nixpkgs-unstable 235 nixos-unstable-small 235
pkgs.rubyPackages.glib2 None nixos-unstable glib2-4.3.3 nixpkgs-unstable glib2-4.3.3 nixos-unstable-small glib2-4.3.3 nixos-25.05 glib2-4.2.9 nixos-25.05-small glib2-4.2.9 nixpkgs-25.05-darwin glib2-4.2.9
pkgs.system76-wallpapers Wallpapers for System76 products nixos-unstable 0-unstable-2024-04-26 nixpkgs-unstable 0-unstable-2024-04-26 nixos-unstable-small 0-unstable-2024-04-26 nixos-25.05 0-unstable-2024-04-26 nixos-25.05-small 0-unstable-2024-04-26 nixpkgs-25.05-darwin 0-unstable-2024-04-26
pkgs.rubyPackages_3_1.glib2 None nixos-25.05 glib2-4.2.9 nixos-25.05-small glib2-4.2.9 nixpkgs-25.05-darwin glib2-4.2.9
pkgs.rubyPackages_3_2.glib2 None nixos-25.05 glib2-4.2.9 nixos-25.05-small glib2-4.2.9 nixpkgs-25.05-darwin glib2-4.2.9
pkgs.rubyPackages_3_3.glib2 None nixos-unstable glib2-4.3.3 nixpkgs-unstable glib2-4.3.3 nixos-unstable-small glib2-4.3.3 nixos-25.05 glib2-4.2.9 nixos-25.05-small glib2-4.2.9 nixpkgs-25.05-darwin glib2-4.2.9
pkgs.rubyPackages_3_4.glib2 None nixos-unstable glib2-4.3.3 nixpkgs-unstable glib2-4.3.3 nixos-unstable-small glib2-4.3.3 nixos-25.05 glib2-4.2.9 nixos-25.05-small glib2-4.2.9 nixpkgs-25.05-darwin glib2-4.2.9
pkgs.rubyPackages_3_5.glib2 None nixos-unstable glib2-4.3.3 nixpkgs-unstable glib2-4.3.3 nixos-unstable-small glib2-4.3.3
pkgs.deepin.deepin-wallpapers deepin-wallpapers provides wallpapers of dde nixos-25.05 1.7.16 nixos-25.05-small 1.7.16 nixpkgs-25.05-darwin 1.7.16
pkgs.lomiri.lomiri-wallpapers Wallpapers for the Lomiri Operating Environment, gathered from people of the Ubuntu Touch / UBports community nixos-unstable 20.04.0 nixpkgs-unstable 20.04.0 nixos-unstable-small 20.04.0 nixos-25.05 20.04.0 nixos-25.05-small 20.04.0 nixpkgs-25.05-darwin 20.04.0
pkgs.perlPackages.Apppapersway PaperWM-like scrollable tiling window management for Sway/i3wm nixos-unstable 2.001 nixpkgs-unstable 2.001 nixos-unstable-small 2.001 nixos-25.05 1.004 nixos-25.05-small 1.004 nixpkgs-25.05-darwin 1.004
pkgs.gnomeExtensions.2-wallpapers Changes the wallpaper based on whether there are open windows or not. nixos-unstable 2-wallpapers-6 nixpkgs-unstable 2-wallpapers-6 nixos-unstable-small 2-wallpapers-6
pkgs.perl538Packages.Apppapersway PaperWM-like scrollable tiling window management for Sway/i3wm nixos-unstable 2.001 nixpkgs-unstable 2.001 nixos-unstable-small 2.001 nixos-25.05 1.004 nixos-25.05-small 1.004 nixpkgs-25.05-darwin 1.004
pkgs.perl540Packages.Apppapersway PaperWM-like scrollable tiling window management for Sway/i3wm nixos-unstable 2.001 nixpkgs-unstable 2.001 nixos-unstable-small 2.001
pkgs.pantheon.elementary-wallpapers Collection of wallpapers for elementary nixos-unstable 8.0.0 nixpkgs-unstable 8.0.0 nixos-unstable-small 8.0.0 nixos-25.05 8.0.0 nixos-25.05-small 8.0.0 nixpkgs-25.05-darwin 8.0.0
pkgs.libsForQt5.plasma-workspace-wallpapers None nixos-25.05 5.27.11 nixos-25.05-small 5.27.11 nixpkgs-25.05-darwin 5.27.11
pkgs.kdePackages.plasma-workspace-wallpapers Wallpapers for Plasma Workspaces nixos-unstable 6.5.3 nixpkgs-unstable 6.5.3 nixos-unstable-small 6.5.3 nixos-25.05 6.3.6 nixos-25.05-small 6.3.6 nixpkgs-25.05-darwin 6.3.6
pkgs.plasma5Packages.plasma-workspace-wallpapers None nixos-25.05 5.27.11 nixos-25.05-small 5.27.11 nixpkgs-25.05-darwin 5.27.11
CVE-2026-22807 created 19 hours ago vLLM affected by RCE via auto_map dynamic module loading during model initialization vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to version 0.14.0, vLLM loads Hugging Face `auto_map` dynamic modules during model resolution without gating on `trust_remote_code`, allowing attacker-controlled Python code in a model repo/path to execute at server startup. An attacker who can influence the model repo/path (local directory or remote Hugging Face repo) can achieve arbitrary code execution on the vLLM host during model load. This happens before any request handling and does not require API access. Version 0.14.0 fixes the issue. Affected products vllm ==>= 0.10.1, < 0.14.0 Matching in nixpkgs pkgs.vllm High-throughput and memory-efficient inference and serving engine for LLMs nixos-unstable 0.11.2 nixpkgs-unstable 0.11.2 nixos-unstable-small 0.11.2 nixos-25.05 0.8.3 nixos-25.05-small 0.8.3 nixpkgs-25.05-darwin 0.8.3 pkgs.pkgsRocm.vllm High-throughput and memory-efficient inference and serving engine for LLMs nixos-unstable 0.11.2 nixpkgs-unstable 0.11.2 nixos-unstable-small 0.11.2 pkgs.python312Packages.vllm High-throughput and memory-efficient inference and serving engine for LLMs nixos-unstable 0.11.2 nixpkgs-unstable 0.11.2 nixos-unstable-small 0.11.2 nixos-25.05 0.8.3 nixos-25.05-small 0.8.3 nixpkgs-25.05-darwin 0.8.3 pkgs.python313Packages.vllm High-throughput and memory-efficient inference and serving engine for LLMs nixos-unstable 0.11.2 nixpkgs-unstable 0.11.2 nixos-unstable-small 0.11.2 nixos-25.05 0.8.3 nixos-25.05-small 0.8.3 nixpkgs-25.05-darwin 0.8.3 pkgs.pkgsRocm.python3Packages.vllm High-throughput and memory-efficient inference and serving engine for LLMs nixos-unstable 0.11.2 nixpkgs-unstable 0.11.2 nixos-unstable-small 0.11.2 Package maintainers: 3 @CertainLach Yaroslav Bolyukin <iam@lach.pw> @happysalada Raphael Megzari <raphael@megzari.com> @daniel-fahey Daniel Fahey <daniel.fahey+nixpkgs@pm.me>
pkgs.vllm High-throughput and memory-efficient inference and serving engine for LLMs nixos-unstable 0.11.2 nixpkgs-unstable 0.11.2 nixos-unstable-small 0.11.2 nixos-25.05 0.8.3 nixos-25.05-small 0.8.3 nixpkgs-25.05-darwin 0.8.3
pkgs.pkgsRocm.vllm High-throughput and memory-efficient inference and serving engine for LLMs nixos-unstable 0.11.2 nixpkgs-unstable 0.11.2 nixos-unstable-small 0.11.2
pkgs.python312Packages.vllm High-throughput and memory-efficient inference and serving engine for LLMs nixos-unstable 0.11.2 nixpkgs-unstable 0.11.2 nixos-unstable-small 0.11.2 nixos-25.05 0.8.3 nixos-25.05-small 0.8.3 nixpkgs-25.05-darwin 0.8.3
pkgs.python313Packages.vllm High-throughput and memory-efficient inference and serving engine for LLMs nixos-unstable 0.11.2 nixpkgs-unstable 0.11.2 nixos-unstable-small 0.11.2 nixos-25.05 0.8.3 nixos-25.05-small 0.8.3 nixpkgs-25.05-darwin 0.8.3
pkgs.pkgsRocm.python3Packages.vllm High-throughput and memory-efficient inference and serving engine for LLMs nixos-unstable 0.11.2 nixpkgs-unstable 0.11.2 nixos-unstable-small 0.11.2
CVE-2021-47865 created 19 hours ago ProFTPD 1.3.7a - Remote Denial of Service ProFTPD 1.3.7a contains a denial of service vulnerability that allows attackers to overwhelm the server by creating multiple simultaneous FTP connections. Attackers can repeatedly establish connections using threading to exhaust server connection limits and block legitimate user access. Affected products ProFTPD ==1.3.7a Matching in nixpkgs pkgs.proftpd Highly configurable GPL-licensed FTP server software nixos-unstable 1.3.9 nixpkgs-unstable 1.3.9 nixos-unstable-small 1.3.9 nixos-25.05 1.3.9 nixos-25.05-small 1.3.9 nixpkgs-25.05-darwin 1.3.9 Package maintainers: 5 @dpausp Tobias Stenzel <dpausp@posteo.de> @osnyx Oliver Schmidt <os@flyingcircus.io> @leona-ya Leona Maroni <nix@leona.is> @frlan Frank Lanitz <frank@frank.uvena.de> @ctheune Christian Theune <ct@flyingcircus.io>
pkgs.proftpd Highly configurable GPL-licensed FTP server software nixos-unstable 1.3.9 nixpkgs-unstable 1.3.9 nixos-unstable-small 1.3.9 nixos-25.05 1.3.9 nixos-25.05-small 1.3.9 nixpkgs-25.05-darwin 1.3.9
CVE-2026-23517 created 19 hours ago Fleet has an Access Control vulnerability in debug/pprof endpoints Fleet is open source device management software. A broken access control issue in versions prior to 4.78.3, 4.77.1, 4.76.2, 4.75.2, and 4.53.3 allowed authenticated users to access debug and profiling endpoints regardless of role. As a result, low-privilege users could view internal server diagnostics and trigger resource-intensive profiling operations. Fleet’s debug/pprof endpoints are accessible to any authenticated user regardless of role, including the lowest-privilege “Observer” role. This allows low-privilege users to access sensitive server internals, including runtime profiling data and in-memory application state, and to trigger CPU-intensive profiling operations that could lead to denial of service. Versions 4.78.3, 4.77.1, 4.76.2, 4.75.2, and 4.53.3 fix the issue. If an immediate upgrade is not possible, users should put the debug/pprof endpoints behind an IP allowlist as a workaround. Affected products fleet ==>= 4.77.0, < 4.77.1 ==>= 4.78.0, < 4.78.3 ==>= 4.75.0, < 4.75.2 ==>= 4.76.0, < 4.76.2 ==< 4.53.3 Matching in nixpkgs pkgs.fleet CLI tool to launch Fleet server nixos-unstable 4.75.1 nixpkgs-unstable 4.75.1 nixos-unstable-small 4.76.1 nixos-25.05 4.67.3 nixos-25.05-small 4.67.3 nixpkgs-25.05-darwin 4.67.3 pkgs.fleetctl CLI tool for managing Fleet nixos-unstable 4.75.1 nixpkgs-unstable 4.75.1 nixos-unstable-small 4.76.1 nixos-25.05 4.67.3 nixos-25.05-small 4.67.3 nixpkgs-25.05-darwin 4.67.3 pkgs.fleeting-plugin-aws GitLab fleeting plugin for AWS nixos-unstable 1.1.0 nixpkgs-unstable 1.1.0 nixos-unstable-small 1.1.0 nixos-25.05 1.0.1 nixos-25.05-small 1.0.1 nixpkgs-25.05-darwin 1.0.1 pkgs.azure-cli-extensions.fleet Microsoft Azure Command-Line Tools Fleet Extension nixos-unstable 1.8.1 nixpkgs-unstable 1.8.1 nixos-unstable-small 1.8.1 nixos-25.05 1.5.2 nixos-25.05-small 1.5.2 nixpkgs-25.05-darwin 1.5.2 pkgs.python312Packages.tesla-fleet-api Python library for Tesla Fleet API and Teslemetry nixos-unstable 1.2.5 nixpkgs-unstable 1.2.5 nixos-unstable-small 1.2.5 nixos-25.05 1.0.17 nixos-25.05-small 1.0.17 nixpkgs-25.05-darwin 1.0.17 pkgs.python313Packages.tesla-fleet-api Python library for Tesla Fleet API and Teslemetry nixos-unstable 1.2.5 nixpkgs-unstable 1.2.5 nixos-unstable-small 1.2.5 nixos-25.05 1.0.17 nixos-25.05-small 1.0.17 nixpkgs-25.05-darwin 1.0.17 pkgs.haskellPackages.amazonka-iotfleethub Amazon IoT Fleet Hub SDK nixos-unstable 2.0-unstable-2025-04-16 nixpkgs-unstable 2.0-unstable-2025-04-16 nixos-unstable-small 2.0-unstable-2025-04-16 nixos-25.05 2.0 nixos-25.05-small 2.0 nixpkgs-25.05-darwin 2.0 pkgs.haskellPackages.amazonka-iotfleetwise Amazon IoT FleetWise SDK nixos-unstable 2.0-unstable-2025-04-16 nixpkgs-unstable 2.0-unstable-2025-04-16 nixos-unstable-small 2.0-unstable-2025-04-16 nixos-25.05 2.0 nixos-25.05-small 2.0 nixpkgs-25.05-darwin 2.0 pkgs.python312Packages.mypy-boto3-iotfleethub Type annotations for boto3 iotfleethub nixos-unstable boto3-iotfleethub-1.40.17 nixpkgs-unstable boto3-iotfleethub-1.40.17 nixos-unstable-small boto3-iotfleethub-1.40.17 nixos-25.05 boto3-iotfleethub-1.38.0 nixos-25.05-small boto3-iotfleethub-1.38.0 nixpkgs-25.05-darwin boto3-iotfleethub-1.38.0 pkgs.python313Packages.mypy-boto3-iotfleethub Type annotations for boto3 iotfleethub nixos-unstable boto3-iotfleethub-1.40.17 nixpkgs-unstable boto3-iotfleethub-1.40.17 nixos-unstable-small boto3-iotfleethub-1.40.17 nixos-25.05 boto3-iotfleethub-1.38.0 nixos-25.05-small boto3-iotfleethub-1.38.0 nixpkgs-25.05-darwin boto3-iotfleethub-1.38.0 pkgs.python312Packages.mypy-boto3-iotfleetwise Type annotations for boto3 iotfleetwise nixos-unstable boto3-iotfleetwise-1.41.0 nixpkgs-unstable boto3-iotfleetwise-1.41.0 nixos-unstable-small boto3-iotfleetwise-1.41.0 nixos-25.05 boto3-iotfleetwise-1.38.0 nixos-25.05-small boto3-iotfleetwise-1.38.0 nixpkgs-25.05-darwin boto3-iotfleetwise-1.38.0 pkgs.python313Packages.mypy-boto3-iotfleetwise Type annotations for boto3 iotfleetwise nixos-unstable boto3-iotfleetwise-1.41.0 nixpkgs-unstable boto3-iotfleetwise-1.41.0 nixos-unstable-small boto3-iotfleetwise-1.41.0 nixos-25.05 boto3-iotfleetwise-1.38.0 nixos-25.05-small boto3-iotfleetwise-1.38.0 nixpkgs-25.05-darwin boto3-iotfleetwise-1.38.0 pkgs.home-assistant-component-tests.tesla_fleet Open source home automation that puts local control and privacy first nixos-unstable 2025.11.3 nixpkgs-unstable 2025.11.3 nixos-unstable-small 2025.11.3 nixos-25.05 2025.5.2 nixos-25.05-small 2025.5.2 nixpkgs-25.05-darwin 2025.5.2 pkgs.python312Packages.types-aiobotocore-iotfleethub Type annotations for aiobotocore iotfleethub nixos-unstable 2.24.2 nixpkgs-unstable 2.24.2 nixos-unstable-small 2.24.2 nixos-25.05 2.21.1 nixos-25.05-small 2.21.1 nixpkgs-25.05-darwin 2.21.1 pkgs.python313Packages.types-aiobotocore-iotfleethub Type annotations for aiobotocore iotfleethub nixos-unstable 2.24.2 nixpkgs-unstable 2.24.2 nixos-unstable-small 2.24.2 nixos-25.05 2.21.1 nixos-25.05-small 2.21.1 nixpkgs-25.05-darwin 2.21.1 pkgs.python312Packages.types-aiobotocore-iotfleetwise Type annotations for aiobotocore iotfleetwise nixos-unstable 2.25.2 nixpkgs-unstable 2.25.2 nixos-unstable-small 2.25.2 nixos-25.05 2.21.1 nixos-25.05-small 2.21.1 nixpkgs-25.05-darwin 2.21.1 pkgs.python313Packages.types-aiobotocore-iotfleetwise Type annotations for aiobotocore iotfleetwise nixos-unstable 2.25.2 nixpkgs-unstable 2.25.2 nixos-unstable-small 2.25.2 nixos-25.05 2.21.1 nixos-25.05-small 2.21.1 nixpkgs-25.05-darwin 2.21.1 Package maintainers: 9 @katexochen Paul Meyer <katexochen0@gmail.com> @ulrikstrid Ulrik Strid <ulrik.strid@outlook.com> @LeSuisse Thomas Gerbet <thomas@gerbet.me> @AntoineSauzeau Antoine Sauzeau <antoine.sauzeau3@gmail.com> @commiterate commiterate @dotlambda Robert Schütz <rschuetz17@gmail.com> @fabaff Fabian Affolter <mail@fabian-affolter.ch> @mweinelt Martin Weinelt <hexa@darmstadt.ccc.de> @mbalatsko Maksym Balatsko <mbalatsko@gmail.com>
fleet ==>= 4.77.0, < 4.77.1 ==>= 4.78.0, < 4.78.3 ==>= 4.75.0, < 4.75.2 ==>= 4.76.0, < 4.76.2 ==< 4.53.3
pkgs.fleet CLI tool to launch Fleet server nixos-unstable 4.75.1 nixpkgs-unstable 4.75.1 nixos-unstable-small 4.76.1 nixos-25.05 4.67.3 nixos-25.05-small 4.67.3 nixpkgs-25.05-darwin 4.67.3
pkgs.fleetctl CLI tool for managing Fleet nixos-unstable 4.75.1 nixpkgs-unstable 4.75.1 nixos-unstable-small 4.76.1 nixos-25.05 4.67.3 nixos-25.05-small 4.67.3 nixpkgs-25.05-darwin 4.67.3
pkgs.fleeting-plugin-aws GitLab fleeting plugin for AWS nixos-unstable 1.1.0 nixpkgs-unstable 1.1.0 nixos-unstable-small 1.1.0 nixos-25.05 1.0.1 nixos-25.05-small 1.0.1 nixpkgs-25.05-darwin 1.0.1
pkgs.azure-cli-extensions.fleet Microsoft Azure Command-Line Tools Fleet Extension nixos-unstable 1.8.1 nixpkgs-unstable 1.8.1 nixos-unstable-small 1.8.1 nixos-25.05 1.5.2 nixos-25.05-small 1.5.2 nixpkgs-25.05-darwin 1.5.2
pkgs.python312Packages.tesla-fleet-api Python library for Tesla Fleet API and Teslemetry nixos-unstable 1.2.5 nixpkgs-unstable 1.2.5 nixos-unstable-small 1.2.5 nixos-25.05 1.0.17 nixos-25.05-small 1.0.17 nixpkgs-25.05-darwin 1.0.17
pkgs.python313Packages.tesla-fleet-api Python library for Tesla Fleet API and Teslemetry nixos-unstable 1.2.5 nixpkgs-unstable 1.2.5 nixos-unstable-small 1.2.5 nixos-25.05 1.0.17 nixos-25.05-small 1.0.17 nixpkgs-25.05-darwin 1.0.17
pkgs.haskellPackages.amazonka-iotfleethub Amazon IoT Fleet Hub SDK nixos-unstable 2.0-unstable-2025-04-16 nixpkgs-unstable 2.0-unstable-2025-04-16 nixos-unstable-small 2.0-unstable-2025-04-16 nixos-25.05 2.0 nixos-25.05-small 2.0 nixpkgs-25.05-darwin 2.0
pkgs.haskellPackages.amazonka-iotfleetwise Amazon IoT FleetWise SDK nixos-unstable 2.0-unstable-2025-04-16 nixpkgs-unstable 2.0-unstable-2025-04-16 nixos-unstable-small 2.0-unstable-2025-04-16 nixos-25.05 2.0 nixos-25.05-small 2.0 nixpkgs-25.05-darwin 2.0
pkgs.python312Packages.mypy-boto3-iotfleethub Type annotations for boto3 iotfleethub nixos-unstable boto3-iotfleethub-1.40.17 nixpkgs-unstable boto3-iotfleethub-1.40.17 nixos-unstable-small boto3-iotfleethub-1.40.17 nixos-25.05 boto3-iotfleethub-1.38.0 nixos-25.05-small boto3-iotfleethub-1.38.0 nixpkgs-25.05-darwin boto3-iotfleethub-1.38.0
pkgs.python313Packages.mypy-boto3-iotfleethub Type annotations for boto3 iotfleethub nixos-unstable boto3-iotfleethub-1.40.17 nixpkgs-unstable boto3-iotfleethub-1.40.17 nixos-unstable-small boto3-iotfleethub-1.40.17 nixos-25.05 boto3-iotfleethub-1.38.0 nixos-25.05-small boto3-iotfleethub-1.38.0 nixpkgs-25.05-darwin boto3-iotfleethub-1.38.0
pkgs.python312Packages.mypy-boto3-iotfleetwise Type annotations for boto3 iotfleetwise nixos-unstable boto3-iotfleetwise-1.41.0 nixpkgs-unstable boto3-iotfleetwise-1.41.0 nixos-unstable-small boto3-iotfleetwise-1.41.0 nixos-25.05 boto3-iotfleetwise-1.38.0 nixos-25.05-small boto3-iotfleetwise-1.38.0 nixpkgs-25.05-darwin boto3-iotfleetwise-1.38.0
pkgs.python313Packages.mypy-boto3-iotfleetwise Type annotations for boto3 iotfleetwise nixos-unstable boto3-iotfleetwise-1.41.0 nixpkgs-unstable boto3-iotfleetwise-1.41.0 nixos-unstable-small boto3-iotfleetwise-1.41.0 nixos-25.05 boto3-iotfleetwise-1.38.0 nixos-25.05-small boto3-iotfleetwise-1.38.0 nixpkgs-25.05-darwin boto3-iotfleetwise-1.38.0
pkgs.home-assistant-component-tests.tesla_fleet Open source home automation that puts local control and privacy first nixos-unstable 2025.11.3 nixpkgs-unstable 2025.11.3 nixos-unstable-small 2025.11.3 nixos-25.05 2025.5.2 nixos-25.05-small 2025.5.2 nixpkgs-25.05-darwin 2025.5.2
pkgs.python312Packages.types-aiobotocore-iotfleethub Type annotations for aiobotocore iotfleethub nixos-unstable 2.24.2 nixpkgs-unstable 2.24.2 nixos-unstable-small 2.24.2 nixos-25.05 2.21.1 nixos-25.05-small 2.21.1 nixpkgs-25.05-darwin 2.21.1
pkgs.python313Packages.types-aiobotocore-iotfleethub Type annotations for aiobotocore iotfleethub nixos-unstable 2.24.2 nixpkgs-unstable 2.24.2 nixos-unstable-small 2.24.2 nixos-25.05 2.21.1 nixos-25.05-small 2.21.1 nixpkgs-25.05-darwin 2.21.1
pkgs.python312Packages.types-aiobotocore-iotfleetwise Type annotations for aiobotocore iotfleetwise nixos-unstable 2.25.2 nixpkgs-unstable 2.25.2 nixos-unstable-small 2.25.2 nixos-25.05 2.21.1 nixos-25.05-small 2.21.1 nixpkgs-25.05-darwin 2.21.1
pkgs.python313Packages.types-aiobotocore-iotfleetwise Type annotations for aiobotocore iotfleetwise nixos-unstable 2.25.2 nixpkgs-unstable 2.25.2 nixos-unstable-small 2.25.2 nixos-25.05 2.21.1 nixos-25.05-small 2.21.1 nixpkgs-25.05-darwin 2.21.1
CVE-2026-24061 created 19 hours ago telnetd in GNU Inetutils through 2.7 allows remote authentication bypass … telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable. Affected products Inetutils =<2.7 Matching in nixpkgs pkgs.inetutils Collection of common network programs nixos-unstable 2.6 nixpkgs-unstable 2.6 nixos-unstable-small 2.6 nixos-25.05 2.6 nixos-25.05-small 2.6 nixpkgs-25.05-darwin 2.6 Package maintainers: 1 @matthewbauer Matthew Bauer <mjbauer95@gmail.com>
pkgs.inetutils Collection of common network programs nixos-unstable 2.6 nixpkgs-unstable 2.6 nixos-unstable-small 2.6 nixos-25.05 2.6 nixos-25.05-small 2.6 nixpkgs-25.05-darwin 2.6
CVE-2026-23986 created 19 hours ago Copier safe template has arbitrary filesystem write access via directory symlinks when _preserve_symlinks: true Copier is a library and CLI app for rendering project templates. Prior to version 9.11.2, Copier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the `--UNSAFE,--trust` flag. As it turns out, a safe template can currently write to arbitrary directories outside the destination path by using directory a symlink along with `_preserve_symlinks: true` and a generated directory structure whose rendered path is inside the symlinked directory. This way, a malicious template author can create a template that overwrites arbitrary files (according to the user's write permissions), e.g., to cause havoc. Version 9.11.2 patches the issue. Affected products copier ==< 9.11.2 Matching in nixpkgs pkgs.copier Library and command-line utility for rendering projects templates nixos-unstable 9.11.0 nixpkgs-unstable 9.11.0 nixos-unstable-small 9.11.0 nixos-25.05 9.6.0 nixos-25.05-small 9.6.0 nixpkgs-25.05-darwin 9.6.0 pkgs.apksigcopier Copy/extract/patch android apk signatures & compare APKs nixos-unstable 1.1.1 nixpkgs-unstable 1.1.1 nixos-unstable-small 1.1.1 nixos-25.05 1.1.1 nixos-25.05-small 1.1.1 nixpkgs-25.05-darwin 1.1.1 pkgs.gnomeExtensions.copier Copy text notes to clipboard via a panel indicator nixos-unstable 8 nixpkgs-unstable 8 nixos-unstable-small 8 nixos-25.05 8 nixos-25.05-small 8 nixpkgs-25.05-darwin 8 pkgs.python312Packages.copier Library and command-line utility for rendering projects templates nixos-unstable 9.11.0 nixpkgs-unstable 9.11.0 nixos-unstable-small 9.11.0 nixos-25.05 9.6.0 nixos-25.05-small 9.6.0 nixpkgs-25.05-darwin 9.6.0 pkgs.python313Packages.copier Library and command-line utility for rendering projects templates nixos-unstable 9.11.0 nixpkgs-unstable 9.11.0 nixos-unstable-small 9.11.0 nixos-25.05 9.6.0 nixos-25.05-small 9.6.0 nixpkgs-25.05-darwin 9.6.0 pkgs.python312Packages.copier-template-tester ctt: CLI and pre-commit tool for testing copier nixos-unstable 2.2.0 nixpkgs-unstable 2.2.0 nixos-unstable-small 2.2.0 nixos-25.05 2.1.1 nixos-25.05-small 2.1.1 nixpkgs-25.05-darwin 2.1.1 pkgs.python313Packages.copier-template-tester ctt: CLI and pre-commit tool for testing copier nixos-unstable 2.2.0 nixpkgs-unstable 2.2.0 nixos-unstable-small 2.2.0 nixos-25.05 2.1.1 nixos-25.05-small 2.1.1 nixpkgs-25.05-darwin 2.1.1 Package maintainers: 4 @obfusk FC Stegerman <flx@obfusk.net> @greg-hellings greg <greg.hellings@gmail.com> @honnip Jung seungwoo <me@honnip.page> @yajo Jairo Llopis <yajo.sk8@gmail.com>
pkgs.copier Library and command-line utility for rendering projects templates nixos-unstable 9.11.0 nixpkgs-unstable 9.11.0 nixos-unstable-small 9.11.0 nixos-25.05 9.6.0 nixos-25.05-small 9.6.0 nixpkgs-25.05-darwin 9.6.0
pkgs.apksigcopier Copy/extract/patch android apk signatures & compare APKs nixos-unstable 1.1.1 nixpkgs-unstable 1.1.1 nixos-unstable-small 1.1.1 nixos-25.05 1.1.1 nixos-25.05-small 1.1.1 nixpkgs-25.05-darwin 1.1.1
pkgs.gnomeExtensions.copier Copy text notes to clipboard via a panel indicator nixos-unstable 8 nixpkgs-unstable 8 nixos-unstable-small 8 nixos-25.05 8 nixos-25.05-small 8 nixpkgs-25.05-darwin 8
pkgs.python312Packages.copier Library and command-line utility for rendering projects templates nixos-unstable 9.11.0 nixpkgs-unstable 9.11.0 nixos-unstable-small 9.11.0 nixos-25.05 9.6.0 nixos-25.05-small 9.6.0 nixpkgs-25.05-darwin 9.6.0
pkgs.python313Packages.copier Library and command-line utility for rendering projects templates nixos-unstable 9.11.0 nixpkgs-unstable 9.11.0 nixos-unstable-small 9.11.0 nixos-25.05 9.6.0 nixos-25.05-small 9.6.0 nixpkgs-25.05-darwin 9.6.0
pkgs.python312Packages.copier-template-tester ctt: CLI and pre-commit tool for testing copier nixos-unstable 2.2.0 nixpkgs-unstable 2.2.0 nixos-unstable-small 2.2.0 nixos-25.05 2.1.1 nixos-25.05-small 2.1.1 nixpkgs-25.05-darwin 2.1.1
pkgs.python313Packages.copier-template-tester ctt: CLI and pre-commit tool for testing copier nixos-unstable 2.2.0 nixpkgs-unstable 2.2.0 nixos-unstable-small 2.2.0 nixos-25.05 2.1.1 nixos-25.05-small 2.1.1 nixpkgs-25.05-darwin 2.1.1
CVE-2021-47857 created 19 hours ago Moodle 3.10.3 - 'label' Persistent Cross Site Scripting Moodle 3.10.3 contains a persistent cross-site scripting vulnerability in the calendar event subtitle field that allows attackers to inject malicious scripts. Attackers can craft a calendar event with malicious JavaScript in the subtitle track label to execute arbitrary code when users view the event. Affected products Moodle ==3.10.3 Matching in nixpkgs pkgs.moodle Free and open-source learning management system (LMS) written in PHP nixos-unstable 5.0.2 nixpkgs-unstable 5.0.2 nixos-unstable-small 5.0.2 nixos-25.05 5.0 nixos-25.05-small 5.0 nixpkgs-25.05-darwin 5.0 pkgs.moodle-dl Moodle downloader that downloads course content fast from Moodle nixos-unstable 2.3.13 nixpkgs-unstable 2.3.13 nixos-unstable-small 2.3.13 nixos-25.05 2.3.13 nixos-25.05-small 2.3.13 nixpkgs-25.05-darwin 2.3.13 Package maintainers: 2 @freezeboy freezeboy @kmein Kierán Meinhardt <kmein@posteo.de>
pkgs.moodle Free and open-source learning management system (LMS) written in PHP nixos-unstable 5.0.2 nixpkgs-unstable 5.0.2 nixos-unstable-small 5.0.2 nixos-25.05 5.0 nixos-25.05-small 5.0 nixpkgs-25.05-darwin 5.0
pkgs.moodle-dl Moodle downloader that downloads course content fast from Moodle nixos-unstable 2.3.13 nixpkgs-unstable 2.3.13 nixos-unstable-small 2.3.13 nixos-25.05 2.3.13 nixos-25.05-small 2.3.13 nixpkgs-25.05-darwin 2.3.13
CVE-2025-12781 created 19 hours ago base64.b64decode() always accepts "+/" characters, despite setting altchars When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the characters "+/" will always be accepted, regardless of the value of "altchars" parameter, typically used to establish an "alternative base64 alphabet" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues. This behavior can only be insecure if your application uses an alternate base64 alphabet (without "+/"). If your application does not use the "altchars" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet. The attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64 alphabet they are expecting or verify that their application would not be affected if the b64decode() functions accepted "+" or "/" outside of altchars. Affected products CPython <3.15.0 Matching in nixpkgs pkgs.haskellPackages.cpython Bindings for libpython nixos-unstable 3.9.0 nixpkgs-unstable 3.9.0 nixos-unstable-small 3.9.0 nixos-25.05 3.9.0 nixos-25.05-small 3.9.0 nixpkgs-25.05-darwin 3.9.0 Package maintainers: 1 @sheepforce Phillip Seeber <phillip.seeber@googlemail.com>
pkgs.haskellPackages.cpython Bindings for libpython nixos-unstable 3.9.0 nixpkgs-unstable 3.9.0 nixos-unstable-small 3.9.0 nixos-25.05 3.9.0 nixos-25.05-small 3.9.0 nixpkgs-25.05-darwin 3.9.0