CVE-2025-67847 updated 3 hours ago by @LeSuisse Activity log Created automatic suggestion 10 hours ago @LeSuisse removed package moodle-dl 3 hours ago Moodle: moodle: remote code execution via insufficient restore input validation A flaw was found in Moodle. An attacker with access to the restore interface could trigger server-side execution of arbitrary code. This is due to insufficient validation of restore input, which leads to unintended interpretation by core restore routines. Successful exploitation could result in a full compromise of the Moodle application. Affected products moodle <4.4.12 <4.1.22 <5.1.1 <4.1.0 <4.5.8 <5.0.4 Matching in nixpkgs pkgs.moodle Free and open-source learning management system (LMS) written in PHP nixos-unstable 5.0.2 nixpkgs-unstable 5.0.2 nixos-unstable-small 5.0.2 nixos-25.05 5.0 nixos-25.05-small 5.0 nixpkgs-25.05-darwin 5.0 Package maintainers: 2 @freezeboy freezeboy @kmein Kierán Meinhardt <kmein@posteo.de>
pkgs.moodle Free and open-source learning management system (LMS) written in PHP nixos-unstable 5.0.2 nixpkgs-unstable 5.0.2 nixos-unstable-small 5.0.2 nixos-25.05 5.0 nixos-25.05-small 5.0 nixpkgs-25.05-darwin 5.0
CVE-2026-21441 created 10 hours ago urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API) urllib3 is an HTTP client library for Python. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. urllib3 can perform decoding or decompression based on the HTTP `Content-Encoding` header (e.g., `gzip`, `deflate`, `br`, or `zstd`). When using the streaming API, the library decompresses only the necessary bytes, enabling partial content consumption. Starting in version 1.22 and prior to version 2.6.3, for HTTP redirect responses, the library would read the entire response body to drain the connection and decompress the content unnecessarily. This decompression occurred even before any read methods were called, and configured read limits did not restrict the amount of decompressed data. As a result, there was no safeguard against decompression bombs. A malicious server could exploit this to trigger excessive resource consumption on the client. Applications and libraries are affected when they stream content from untrusted sources by setting `preload_content=False` when they do not disable redirects. Users should upgrade to at least urllib3 v2.6.3, in which the library does not decode content of redirect responses when `preload_content=False`. If upgrading is not immediately possible, disable redirects by setting `redirect=False` for requests to untrusted source. Affected products urllib3 ==>= 1.22, < 2.6.3 Matching in nixpkgs pkgs.kodiPackages.urllib3 HTTP library with thread-safe connection pooling, file post, and more nixos-unstable urllib3-2.2.3 nixpkgs-unstable urllib3-2.2.3 nixos-unstable-small urllib3-2.2.3 nixos-25.05 urllib3-2.2.3 nixos-25.05-small urllib3-2.2.3 nixpkgs-25.05-darwin urllib3-2.2.3 pkgs.python312Packages.urllib3 Powerful, user-friendly HTTP client for Python nixos-unstable urllib3-2.5.0 nixpkgs-unstable urllib3-2.5.0 nixos-unstable-small urllib3-2.5.0 nixos-25.05 urllib3-2.3.0 nixos-25.05-small urllib3-2.3.0 nixpkgs-25.05-darwin urllib3-2.3.0 pkgs.python313Packages.urllib3 Powerful, user-friendly HTTP client for Python nixos-unstable urllib3-2.5.0 nixpkgs-unstable urllib3-2.5.0 nixos-unstable-small urllib3-2.5.0 nixos-25.05 urllib3-2.3.0 nixos-25.05-small urllib3-2.3.0 nixpkgs-25.05-darwin urllib3-2.3.0 pkgs.python312Packages.types-urllib3 Typing stubs for urllib3 nixos-unstable urllib3-1.26.25.14 nixpkgs-unstable urllib3-1.26.25.14 nixos-unstable-small urllib3-1.26.25.14 nixos-25.05 urllib3-1.26.25.14 nixos-25.05-small urllib3-1.26.25.14 nixpkgs-25.05-darwin urllib3-1.26.25.14 pkgs.python313Packages.types-urllib3 Typing stubs for urllib3 nixos-unstable urllib3-1.26.25.14 nixpkgs-unstable urllib3-1.26.25.14 nixos-unstable-small urllib3-1.26.25.14 nixos-25.05 urllib3-1.26.25.14 nixos-25.05-small urllib3-1.26.25.14 nixpkgs-25.05-darwin urllib3-1.26.25.14 pkgs.python312Packages.urllib3-future Powerful HTTP 1.1, 2, and 3 client with both sync and async interfaces nixos-unstable urllib3-future-2.14.907 nixpkgs-unstable urllib3-future-2.14.907 nixos-unstable-small urllib3-future-2.14.907 pkgs.python313Packages.urllib3-future Powerful HTTP 1.1, 2, and 3 client with both sync and async interfaces nixos-unstable urllib3-future-2.14.907 nixpkgs-unstable urllib3-future-2.14.907 nixos-unstable-small urllib3-future-2.14.907 pkgs.python312Packages.opentelemetry-instrumentation-urllib3 OpenTelemetry urllib3 instrumentation nixos-unstable urllib3-0.55b0 nixpkgs-unstable urllib3-0.55b0 nixos-unstable-small urllib3-0.55b0 pkgs.python313Packages.opentelemetry-instrumentation-urllib3 OpenTelemetry urllib3 instrumentation nixos-unstable urllib3-0.55b0 nixpkgs-unstable urllib3-0.55b0 nixos-unstable-small urllib3-0.55b0 Package maintainers: 14 @minijackson Rémi Nicole <minijackson@riseup.net> @edwtjo Edward Tjörnhammar <ed@cflags.cc> @peterhoeg Peter Hoeg <peter@hoeg.com> @nvmd Sergey Kazenyuk <kazenyuk@pm.me> @cpages Carles Pagès <page@ruiec.cat> @sephalon Stefan Wiehler <me@sephalon.net> @dschrempf Dominik Schrempf <dominik.schrempf@gmail.com> @aanderse Aaron Andersen <aaron@fosslib.net> @fabaff Fabian Affolter <mail@fabian-affolter.ch> @de11n Elliot Cameron <nixpkgs-commits@deshaw.com> @despsyched Priyanshu Tripathi <priyanshu.tripathi@deshaw.com> @natsukium Tomoya Otabi <nixpkgs@natsukium.com> @invokes-su Souvik Sen <nixpkgs-commits@deshaw.com> @dotlambda Robert Schütz <rschuetz17@gmail.com>
pkgs.kodiPackages.urllib3 HTTP library with thread-safe connection pooling, file post, and more nixos-unstable urllib3-2.2.3 nixpkgs-unstable urllib3-2.2.3 nixos-unstable-small urllib3-2.2.3 nixos-25.05 urllib3-2.2.3 nixos-25.05-small urllib3-2.2.3 nixpkgs-25.05-darwin urllib3-2.2.3
pkgs.python312Packages.urllib3 Powerful, user-friendly HTTP client for Python nixos-unstable urllib3-2.5.0 nixpkgs-unstable urllib3-2.5.0 nixos-unstable-small urllib3-2.5.0 nixos-25.05 urllib3-2.3.0 nixos-25.05-small urllib3-2.3.0 nixpkgs-25.05-darwin urllib3-2.3.0
pkgs.python313Packages.urllib3 Powerful, user-friendly HTTP client for Python nixos-unstable urllib3-2.5.0 nixpkgs-unstable urllib3-2.5.0 nixos-unstable-small urllib3-2.5.0 nixos-25.05 urllib3-2.3.0 nixos-25.05-small urllib3-2.3.0 nixpkgs-25.05-darwin urllib3-2.3.0
pkgs.python312Packages.types-urllib3 Typing stubs for urllib3 nixos-unstable urllib3-1.26.25.14 nixpkgs-unstable urllib3-1.26.25.14 nixos-unstable-small urllib3-1.26.25.14 nixos-25.05 urllib3-1.26.25.14 nixos-25.05-small urllib3-1.26.25.14 nixpkgs-25.05-darwin urllib3-1.26.25.14
pkgs.python313Packages.types-urllib3 Typing stubs for urllib3 nixos-unstable urllib3-1.26.25.14 nixpkgs-unstable urllib3-1.26.25.14 nixos-unstable-small urllib3-1.26.25.14 nixos-25.05 urllib3-1.26.25.14 nixos-25.05-small urllib3-1.26.25.14 nixpkgs-25.05-darwin urllib3-1.26.25.14
pkgs.python312Packages.urllib3-future Powerful HTTP 1.1, 2, and 3 client with both sync and async interfaces nixos-unstable urllib3-future-2.14.907 nixpkgs-unstable urllib3-future-2.14.907 nixos-unstable-small urllib3-future-2.14.907
pkgs.python313Packages.urllib3-future Powerful HTTP 1.1, 2, and 3 client with both sync and async interfaces nixos-unstable urllib3-future-2.14.907 nixpkgs-unstable urllib3-future-2.14.907 nixos-unstable-small urllib3-future-2.14.907
pkgs.python312Packages.opentelemetry-instrumentation-urllib3 OpenTelemetry urllib3 instrumentation nixos-unstable urllib3-0.55b0 nixpkgs-unstable urllib3-0.55b0 nixos-unstable-small urllib3-0.55b0
pkgs.python313Packages.opentelemetry-instrumentation-urllib3 OpenTelemetry urllib3 instrumentation nixos-unstable urllib3-0.55b0 nixpkgs-unstable urllib3-0.55b0 nixos-unstable-small urllib3-0.55b0
CVE-2024-51791 created 10 hours ago WordPress Forms plugin <= 2.8.0 - Arbitrary File Upload vulnerability Unrestricted Upload of File with Dangerous Type vulnerability in Made I.T. Forms allows Upload a Web Shell to a Web Server.This issue affects Forms: from n/a through 2.8.0. Affected products forms =<2.8.0 forms-by-made-it =<2.8.0 Matching in nixpkgs pkgs.platformsh Unified tool for managing your Platform.sh services from the command line nixos-unstable 5.7.2 nixpkgs-unstable 5.7.2 nixos-unstable-small 5.7.2 nixos-25.05 5.3.0 nixos-25.05-small 5.3.0 nixpkgs-25.05-darwin 5.3.0 pkgs.python312Packages.wtforms Flexible forms validation and rendering library for Python nixos-unstable 3.2.1 nixpkgs-unstable 3.2.1 nixos-unstable-small 3.2.1 nixos-25.05 3.2.1 nixos-25.05-small 3.2.1 nixpkgs-25.05-darwin 3.2.1 pkgs.python313Packages.wtforms Flexible forms validation and rendering library for Python nixos-unstable 3.2.1 nixpkgs-unstable 3.2.1 nixos-unstable-small 3.2.1 nixos-25.05 3.2.1 nixos-25.05-small 3.2.1 nixpkgs-25.05-darwin 3.2.1 pkgs.python312Packages.nitransforms Geometric transformations for images and surfaces nixos-unstable 25.1.0 nixpkgs-unstable 25.1.0 nixos-unstable-small 25.1.0 nixos-25.05 24.1.1 nixos-25.05-small 24.1.1 nixpkgs-25.05-darwin 24.1.1 pkgs.python312Packages.transforms3d Convert between various geometric transformations nixos-unstable transforms3d-0.4.2 nixpkgs-unstable transforms3d-0.4.2 nixos-unstable-small transforms3d-0.4.2 nixos-25.05 transforms3d-0.4.2 nixos-25.05-small transforms3d-0.4.2 nixpkgs-25.05-darwin transforms3d-0.4.2 pkgs.python313Packages.nitransforms Geometric transformations for images and surfaces nixos-unstable 25.1.0 nixpkgs-unstable 25.1.0 nixos-unstable-small 25.1.0 nixos-25.05 24.1.1 nixos-25.05-small 24.1.1 nixpkgs-25.05-darwin 24.1.1 pkgs.python313Packages.transforms3d Convert between various geometric transformations nixos-unstable transforms3d-0.4.2 nixpkgs-unstable transforms3d-0.4.2 nixos-unstable-small transforms3d-0.4.2 nixos-25.05 transforms3d-0.4.2 nixos-25.05-small transforms3d-0.4.2 nixpkgs-25.05-darwin transforms3d-0.4.2 pkgs.haskellPackages.unsafeperformst Like unsafeperformIO, but for the ST monad nixos-unstable 0.9.2 nixpkgs-unstable 0.9.2 nixos-unstable-small 0.9.2 nixos-25.05 0.9.2 nixos-25.05-small 0.9.2 nixpkgs-25.05-darwin 0.9.2 pkgs.nodePackages.@tailwindcss/forms A plugin that provides a basic reset for form styles that makes form elements easy to override with utilities. nixos-unstable 0.5.10 nixpkgs-unstable 0.5.10 nixos-unstable-small 0.5.10 nixos-25.05 0.5.10 nixos-25.05-small 0.5.10 nixpkgs-25.05-darwin 0.5.10 pkgs.python312Packages.beanhub-forms Library for generating and processing BeanHub's custom forms nixos-unstable 0.1.3 nixpkgs-unstable 0.1.3 nixos-unstable-small 0.1.3 nixos-25.05 0.1.3 nixos-25.05-small 0.1.3 nixpkgs-25.05-darwin 0.1.3 pkgs.python313Packages.beanhub-forms Library for generating and processing BeanHub's custom forms nixos-unstable 0.1.3 nixpkgs-unstable 0.1.3 nixos-unstable-small 0.1.3 nixos-25.05 0.1.3 nixos-25.05-small 0.1.3 nixpkgs-25.05-darwin 0.1.3 pkgs.python312Packages.aiomodernforms Asynchronous Python client for Modern Forms fans nixos-unstable 0.1.8 nixpkgs-unstable 0.1.8 nixos-unstable-small 0.1.8 nixos-25.05 0.1.8 nixos-25.05-small 0.1.8 nixpkgs-25.05-darwin 0.1.8 pkgs.python313Packages.aiomodernforms Asynchronous Python client for Modern Forms fans nixos-unstable 0.1.8 nixpkgs-unstable 0.1.8 nixos-unstable-small 0.1.8 nixos-25.05 0.1.8 nixos-25.05-small 0.1.8 nixpkgs-25.05-darwin 0.1.8 pkgs.python312Packages.craft-platforms Manage platforms and architectures for charm applications nixos-25.05 0.8.0 nixos-25.05-small 0.8.0 nixpkgs-25.05-darwin 0.8.0 pkgs.python313Packages.craft-platforms Manage platforms and architectures for charm applications nixos-25.05 0.8.0 nixos-25.05-small 0.8.0 nixpkgs-25.05-darwin 0.8.0 pkgs.haskellPackages.unicode-transforms Unicode normalization nixos-unstable 0.4.0.1 nixpkgs-unstable 0.4.0.1 nixos-unstable-small 0.4.0.1 nixos-25.05 0.4.0.1 nixos-25.05-small 0.4.0.1 nixpkgs-25.05-darwin 0.4.0.1 pkgs.inkscape-extensions.applytransforms Inkscape extension which removes all matrix transforms by applying them recursively to shapes nixos-unstable 0.pre+unstable=2021-05-11 nixpkgs-unstable 0.pre+unstable=2021-05-11 nixos-unstable-small 0.pre+unstable=2021-05-11 nixos-25.05 0.pre+unstable=2021-05-11 nixos-25.05-small 0.pre+unstable=2021-05-11 nixpkgs-25.05-darwin 0.pre+unstable=2021-05-11 pkgs.python312Packages.permissionedforms Django extension for creating forms that vary according to user permissions nixos-unstable 0.1 nixpkgs-unstable 0.1 nixos-unstable-small 0.1 nixos-25.05 0.1 nixos-25.05-small 0.1 nixpkgs-25.05-darwin 0.1 pkgs.python313Packages.permissionedforms Django extension for creating forms that vary according to user permissions nixos-unstable 0.1 nixpkgs-unstable 0.1 nixos-unstable-small 0.1 nixos-25.05 0.1 nixos-25.05-small 0.1 nixpkgs-25.05-darwin 0.1 pkgs.python312Packages.wtforms-bootstrap5 Simple library for rendering WTForms in HTML as Bootstrap 5 form controls nixos-unstable bootstrap5-0.3.0 nixpkgs-unstable bootstrap5-0.3.0 nixos-unstable-small bootstrap5-0.3.0 nixos-25.05 bootstrap5-0.3.0 nixos-25.05-small bootstrap5-0.3.0 nixpkgs-25.05-darwin bootstrap5-0.3.0 pkgs.python312Packages.wtforms-sqlalchemy WTForms integration for SQLAlchemy nixos-unstable 0.4.2 nixpkgs-unstable 0.4.2 nixos-unstable-small 0.4.2 nixos-25.05 0.4.2 nixos-25.05-small 0.4.2 nixpkgs-25.05-darwin 0.4.2 pkgs.python313Packages.wtforms-bootstrap5 Simple library for rendering WTForms in HTML as Bootstrap 5 form controls nixos-unstable bootstrap5-0.3.0 nixpkgs-unstable bootstrap5-0.3.0 nixos-unstable-small bootstrap5-0.3.0 nixos-25.05 bootstrap5-0.3.0 nixos-25.05-small bootstrap5-0.3.0 nixpkgs-25.05-darwin bootstrap5-0.3.0 pkgs.python313Packages.wtforms-sqlalchemy WTForms integration for SQLAlchemy nixos-unstable 0.4.2 nixpkgs-unstable 0.4.2 nixos-unstable-small 0.4.2 nixos-25.05 0.4.2 nixos-25.05-small 0.4.2 nixpkgs-25.05-darwin 0.4.2 pkgs.python312Packages.django-crispy-forms Best way to have DRY Django forms nixos-unstable 2.5 nixpkgs-unstable 2.5 nixos-unstable-small 2.5 nixos-25.05 2.4 nixos-25.05-small 2.4 nixpkgs-25.05-darwin 2.4 pkgs.python313Packages.django-crispy-forms Best way to have DRY Django forms nixos-unstable 2.5 nixpkgs-unstable 2.5 nixos-unstable-small 2.5 nixos-25.05 2.4 nixos-25.05-small 2.4 nixpkgs-25.05-darwin 2.4 pkgs.nodePackages_latest.@tailwindcss/forms A plugin that provides a basic reset for form styles that makes form elements easy to override with utilities. nixos-unstable 0.5.10 nixpkgs-unstable 0.5.10 nixos-unstable-small 0.5.10 nixos-25.05 0.5.10 nixos-25.05-small 0.5.10 nixpkgs-25.05-darwin 0.5.10 pkgs.wordpressPackages.plugins.wpforms-lite None nixos-unstable 1.9.4.2 nixpkgs-unstable 1.9.4.2 nixos-unstable-small 1.9.4.2 nixos-25.05 1.9.4.2 nixos-25.05-small 1.9.4.2 nixpkgs-25.05-darwin 1.9.4.2 pkgs.home-assistant-component-tests.modern_forms Open source home automation that puts local control and privacy first nixos-unstable 2025.11.3 nixpkgs-unstable 2025.11.3 nixos-unstable-small 2025.11.3 nixos-25.05 2025.5.2 nixos-25.05-small 2025.5.2 nixpkgs-25.05-darwin 2025.5.2 pkgs.python312Packages.django-formset-js-improved Wrapper for a JavaScript formset helper nixos-unstable 0.5.0.3 nixpkgs-unstable 0.5.0.3 nixos-unstable-small 0.5.0.3 nixos-25.05 0.5.0.3 nixos-25.05-small 0.5.0.3 nixpkgs-25.05-darwin 0.5.0.3 pkgs.python313Packages.django-formset-js-improved Wrapper for a JavaScript formset helper nixos-unstable 0.5.0.3 nixpkgs-unstable 0.5.0.3 nixos-unstable-small 0.5.0.3 nixos-25.05 0.5.0.3 nixos-25.05-small 0.5.0.3 nixpkgs-25.05-darwin 0.5.0.3 pkgs.chickenPackages_5.chickenEggs.sxml-transforms The SXML transformations (to XML, SXML, and HTML) from the SSAX project at Sourceforge nixos-unstable 1.4.3 nixpkgs-unstable 1.4.3 nixos-unstable-small 1.4.3 nixos-25.05 1.4.3 nixos-25.05-small 1.4.3 nixpkgs-25.05-darwin 1.4.3 pkgs.wordpressPackages.plugins.hcaptcha-for-forms-and-more None nixos-unstable 4.12.0 nixpkgs-unstable 4.12.0 nixos-unstable-small 4.12.0 nixos-25.05 4.12.0 nixos-25.05-small 4.12.0 nixpkgs-25.05-darwin 4.12.0 Package maintainers: 17 @fabaff Fabian Affolter <mail@fabian-affolter.ch> @dotlambda Robert Schütz <rschuetz17@gmail.com> @mweinelt Martin Weinelt <hexa@darmstadt.ccc.de> @jtojnar Jan Tojnar <jtojnar@gmail.com> @shyim Soner Sayakci <s.sayakci@gmail.com> @spk Laurent Arnoud <laurent@spkdev.net> @fangpenlin Fang-Pen Lin <hello@fangpenlin.com> @jnsgruk Jon Seager <jon@sgrs.uk> @ambroisie Bruno BELANYI <bruno.nixpkgs@belanyi.fr> @bcdarwin Ben Darwin <bcdarwin@gmail.com> @sephii Sylvain Fankhauser <sephi@fhtagn.top> @bhipple Benjamin Hipple <bhipple@protonmail.com> @vidister Fiona Weber <v@vidister.de> @johannwagner Johann Wagner <nix@wagner.digital> @n0emis Ember Keske <nixpkgs@n0emis.network> @yuyuyureka Yureka <yuka@yuka.dev> @SuperSandro2000 Sandro Jäckel <sandro.jaeckel@gmail.com>
pkgs.platformsh Unified tool for managing your Platform.sh services from the command line nixos-unstable 5.7.2 nixpkgs-unstable 5.7.2 nixos-unstable-small 5.7.2 nixos-25.05 5.3.0 nixos-25.05-small 5.3.0 nixpkgs-25.05-darwin 5.3.0
pkgs.python312Packages.wtforms Flexible forms validation and rendering library for Python nixos-unstable 3.2.1 nixpkgs-unstable 3.2.1 nixos-unstable-small 3.2.1 nixos-25.05 3.2.1 nixos-25.05-small 3.2.1 nixpkgs-25.05-darwin 3.2.1
pkgs.python313Packages.wtforms Flexible forms validation and rendering library for Python nixos-unstable 3.2.1 nixpkgs-unstable 3.2.1 nixos-unstable-small 3.2.1 nixos-25.05 3.2.1 nixos-25.05-small 3.2.1 nixpkgs-25.05-darwin 3.2.1
pkgs.python312Packages.nitransforms Geometric transformations for images and surfaces nixos-unstable 25.1.0 nixpkgs-unstable 25.1.0 nixos-unstable-small 25.1.0 nixos-25.05 24.1.1 nixos-25.05-small 24.1.1 nixpkgs-25.05-darwin 24.1.1
pkgs.python312Packages.transforms3d Convert between various geometric transformations nixos-unstable transforms3d-0.4.2 nixpkgs-unstable transforms3d-0.4.2 nixos-unstable-small transforms3d-0.4.2 nixos-25.05 transforms3d-0.4.2 nixos-25.05-small transforms3d-0.4.2 nixpkgs-25.05-darwin transforms3d-0.4.2
pkgs.python313Packages.nitransforms Geometric transformations for images and surfaces nixos-unstable 25.1.0 nixpkgs-unstable 25.1.0 nixos-unstable-small 25.1.0 nixos-25.05 24.1.1 nixos-25.05-small 24.1.1 nixpkgs-25.05-darwin 24.1.1
pkgs.python313Packages.transforms3d Convert between various geometric transformations nixos-unstable transforms3d-0.4.2 nixpkgs-unstable transforms3d-0.4.2 nixos-unstable-small transforms3d-0.4.2 nixos-25.05 transforms3d-0.4.2 nixos-25.05-small transforms3d-0.4.2 nixpkgs-25.05-darwin transforms3d-0.4.2
pkgs.haskellPackages.unsafeperformst Like unsafeperformIO, but for the ST monad nixos-unstable 0.9.2 nixpkgs-unstable 0.9.2 nixos-unstable-small 0.9.2 nixos-25.05 0.9.2 nixos-25.05-small 0.9.2 nixpkgs-25.05-darwin 0.9.2
pkgs.nodePackages.@tailwindcss/forms A plugin that provides a basic reset for form styles that makes form elements easy to override with utilities. nixos-unstable 0.5.10 nixpkgs-unstable 0.5.10 nixos-unstable-small 0.5.10 nixos-25.05 0.5.10 nixos-25.05-small 0.5.10 nixpkgs-25.05-darwin 0.5.10
pkgs.python312Packages.beanhub-forms Library for generating and processing BeanHub's custom forms nixos-unstable 0.1.3 nixpkgs-unstable 0.1.3 nixos-unstable-small 0.1.3 nixos-25.05 0.1.3 nixos-25.05-small 0.1.3 nixpkgs-25.05-darwin 0.1.3
pkgs.python313Packages.beanhub-forms Library for generating and processing BeanHub's custom forms nixos-unstable 0.1.3 nixpkgs-unstable 0.1.3 nixos-unstable-small 0.1.3 nixos-25.05 0.1.3 nixos-25.05-small 0.1.3 nixpkgs-25.05-darwin 0.1.3
pkgs.python312Packages.aiomodernforms Asynchronous Python client for Modern Forms fans nixos-unstable 0.1.8 nixpkgs-unstable 0.1.8 nixos-unstable-small 0.1.8 nixos-25.05 0.1.8 nixos-25.05-small 0.1.8 nixpkgs-25.05-darwin 0.1.8
pkgs.python313Packages.aiomodernforms Asynchronous Python client for Modern Forms fans nixos-unstable 0.1.8 nixpkgs-unstable 0.1.8 nixos-unstable-small 0.1.8 nixos-25.05 0.1.8 nixos-25.05-small 0.1.8 nixpkgs-25.05-darwin 0.1.8
pkgs.python312Packages.craft-platforms Manage platforms and architectures for charm applications nixos-25.05 0.8.0 nixos-25.05-small 0.8.0 nixpkgs-25.05-darwin 0.8.0
pkgs.python313Packages.craft-platforms Manage platforms and architectures for charm applications nixos-25.05 0.8.0 nixos-25.05-small 0.8.0 nixpkgs-25.05-darwin 0.8.0
pkgs.haskellPackages.unicode-transforms Unicode normalization nixos-unstable 0.4.0.1 nixpkgs-unstable 0.4.0.1 nixos-unstable-small 0.4.0.1 nixos-25.05 0.4.0.1 nixos-25.05-small 0.4.0.1 nixpkgs-25.05-darwin 0.4.0.1
pkgs.inkscape-extensions.applytransforms Inkscape extension which removes all matrix transforms by applying them recursively to shapes nixos-unstable 0.pre+unstable=2021-05-11 nixpkgs-unstable 0.pre+unstable=2021-05-11 nixos-unstable-small 0.pre+unstable=2021-05-11 nixos-25.05 0.pre+unstable=2021-05-11 nixos-25.05-small 0.pre+unstable=2021-05-11 nixpkgs-25.05-darwin 0.pre+unstable=2021-05-11
pkgs.python312Packages.permissionedforms Django extension for creating forms that vary according to user permissions nixos-unstable 0.1 nixpkgs-unstable 0.1 nixos-unstable-small 0.1 nixos-25.05 0.1 nixos-25.05-small 0.1 nixpkgs-25.05-darwin 0.1
pkgs.python313Packages.permissionedforms Django extension for creating forms that vary according to user permissions nixos-unstable 0.1 nixpkgs-unstable 0.1 nixos-unstable-small 0.1 nixos-25.05 0.1 nixos-25.05-small 0.1 nixpkgs-25.05-darwin 0.1
pkgs.python312Packages.wtforms-bootstrap5 Simple library for rendering WTForms in HTML as Bootstrap 5 form controls nixos-unstable bootstrap5-0.3.0 nixpkgs-unstable bootstrap5-0.3.0 nixos-unstable-small bootstrap5-0.3.0 nixos-25.05 bootstrap5-0.3.0 nixos-25.05-small bootstrap5-0.3.0 nixpkgs-25.05-darwin bootstrap5-0.3.0
pkgs.python312Packages.wtforms-sqlalchemy WTForms integration for SQLAlchemy nixos-unstable 0.4.2 nixpkgs-unstable 0.4.2 nixos-unstable-small 0.4.2 nixos-25.05 0.4.2 nixos-25.05-small 0.4.2 nixpkgs-25.05-darwin 0.4.2
pkgs.python313Packages.wtforms-bootstrap5 Simple library for rendering WTForms in HTML as Bootstrap 5 form controls nixos-unstable bootstrap5-0.3.0 nixpkgs-unstable bootstrap5-0.3.0 nixos-unstable-small bootstrap5-0.3.0 nixos-25.05 bootstrap5-0.3.0 nixos-25.05-small bootstrap5-0.3.0 nixpkgs-25.05-darwin bootstrap5-0.3.0
pkgs.python313Packages.wtforms-sqlalchemy WTForms integration for SQLAlchemy nixos-unstable 0.4.2 nixpkgs-unstable 0.4.2 nixos-unstable-small 0.4.2 nixos-25.05 0.4.2 nixos-25.05-small 0.4.2 nixpkgs-25.05-darwin 0.4.2
pkgs.python312Packages.django-crispy-forms Best way to have DRY Django forms nixos-unstable 2.5 nixpkgs-unstable 2.5 nixos-unstable-small 2.5 nixos-25.05 2.4 nixos-25.05-small 2.4 nixpkgs-25.05-darwin 2.4
pkgs.python313Packages.django-crispy-forms Best way to have DRY Django forms nixos-unstable 2.5 nixpkgs-unstable 2.5 nixos-unstable-small 2.5 nixos-25.05 2.4 nixos-25.05-small 2.4 nixpkgs-25.05-darwin 2.4
pkgs.nodePackages_latest.@tailwindcss/forms A plugin that provides a basic reset for form styles that makes form elements easy to override with utilities. nixos-unstable 0.5.10 nixpkgs-unstable 0.5.10 nixos-unstable-small 0.5.10 nixos-25.05 0.5.10 nixos-25.05-small 0.5.10 nixpkgs-25.05-darwin 0.5.10
pkgs.wordpressPackages.plugins.wpforms-lite None nixos-unstable 1.9.4.2 nixpkgs-unstable 1.9.4.2 nixos-unstable-small 1.9.4.2 nixos-25.05 1.9.4.2 nixos-25.05-small 1.9.4.2 nixpkgs-25.05-darwin 1.9.4.2
pkgs.home-assistant-component-tests.modern_forms Open source home automation that puts local control and privacy first nixos-unstable 2025.11.3 nixpkgs-unstable 2025.11.3 nixos-unstable-small 2025.11.3 nixos-25.05 2025.5.2 nixos-25.05-small 2025.5.2 nixpkgs-25.05-darwin 2025.5.2
pkgs.python312Packages.django-formset-js-improved Wrapper for a JavaScript formset helper nixos-unstable 0.5.0.3 nixpkgs-unstable 0.5.0.3 nixos-unstable-small 0.5.0.3 nixos-25.05 0.5.0.3 nixos-25.05-small 0.5.0.3 nixpkgs-25.05-darwin 0.5.0.3
pkgs.python313Packages.django-formset-js-improved Wrapper for a JavaScript formset helper nixos-unstable 0.5.0.3 nixpkgs-unstable 0.5.0.3 nixos-unstable-small 0.5.0.3 nixos-25.05 0.5.0.3 nixos-25.05-small 0.5.0.3 nixpkgs-25.05-darwin 0.5.0.3
pkgs.chickenPackages_5.chickenEggs.sxml-transforms The SXML transformations (to XML, SXML, and HTML) from the SSAX project at Sourceforge nixos-unstable 1.4.3 nixpkgs-unstable 1.4.3 nixos-unstable-small 1.4.3 nixos-25.05 1.4.3 nixos-25.05-small 1.4.3 nixpkgs-25.05-darwin 1.4.3
pkgs.wordpressPackages.plugins.hcaptcha-for-forms-and-more None nixos-unstable 4.12.0 nixpkgs-unstable 4.12.0 nixos-unstable-small 4.12.0 nixos-25.05 4.12.0 nixos-25.05-small 4.12.0 nixpkgs-25.05-darwin 4.12.0
CVE-2026-24137 created 10 hours ago sigstore legacy TUF client allows for arbitrary file writes with target cache path traversal sigstore framework is a common go library shared across sigstore services and clients. In versions 1.10.3 and below, the legacy TUF client (pkg/tuf/client.go) supports caching target files to disk. It constructs a filesystem path by joining a cache base directory with a target name sourced from signed target metadata; however, it does not validate that the resulting path stays within the cache base directory. A malicious TUF repository can trigger arbitrary file overwriting, limited to the permissions that the calling process has. Note that this should only affect clients that are directly using the TUF client in sigstore/sigstore or are using an older version of Cosign. Public Sigstore deployment users are unaffected, as TUF metadata is validated by a quorum of trusted collaborators. This issue has been fixed in version 1.10.4. As a workaround, users can disable disk caching for the legacy client by setting SIGSTORE_NO_CACHE=true in the environment, migrate to https://github.com/sigstore/sigstore-go/tree/main/pkg/tuf, or upgrade to the latest sigstore/sigstore release. Affected products sigstore ==< 1.10.4 Matching in nixpkgs pkgs.k8s-manifest-sigstore Kubectl plugin for signing Kubernetes manifest YAML files with sigstore nixos-unstable 0.5.4 nixpkgs-unstable 0.5.4 nixos-unstable-small 0.5.4 nixos-25.05 0.5.4 nixos-25.05-small 0.5.4 nixpkgs-25.05-darwin 0.5.4 pkgs.python312Packages.sigstore Codesigning tool for Python packages nixos-unstable 4.0.0 nixpkgs-unstable 4.0.0 nixos-unstable-small 4.0.0 nixos-25.05 3.6.2 nixos-25.05-small 3.6.2 nixpkgs-25.05-darwin 3.6.2 pkgs.python313Packages.sigstore Codesigning tool for Python packages nixos-unstable 4.0.0 nixpkgs-unstable 4.0.0 nixos-unstable-small 4.0.0 nixos-25.05 3.6.2 nixos-25.05-small 3.6.2 nixpkgs-25.05-darwin 3.6.2 pkgs.python312Packages.sigstore-models Pydantic-based, protobuf-free data models for Sigstore nixos-unstable 0.0.5 nixpkgs-unstable 0.0.5 nixos-unstable-small 0.0.5 pkgs.python313Packages.sigstore-models Pydantic-based, protobuf-free data models for Sigstore nixos-unstable 0.0.5 nixpkgs-unstable 0.0.5 nixos-unstable-small 0.0.5 pkgs.python312Packages.sigstore-rekor-types Python models for Rekor's API types nixos-unstable 0.0.18 nixpkgs-unstable 0.0.18 nixos-unstable-small 0.0.18 nixos-25.05 0.0.18 nixos-25.05-small 0.0.18 nixpkgs-25.05-darwin 0.0.18 pkgs.python313Packages.sigstore-rekor-types Python models for Rekor's API types nixos-unstable 0.0.18 nixpkgs-unstable 0.0.18 nixos-unstable-small 0.0.18 nixos-25.05 0.0.18 nixos-25.05-small 0.0.18 nixpkgs-25.05-darwin 0.0.18 pkgs.python312Packages.sigstore-protobuf-specs Library for serializing and deserializing Sigstore messages nixos-unstable 0.5.0 nixpkgs-unstable 0.5.0 nixos-unstable-small 0.5.0 nixos-25.05 0.3.2 nixos-25.05-small 0.3.2 nixpkgs-25.05-darwin 0.3.2 pkgs.python313Packages.sigstore-protobuf-specs Library for serializing and deserializing Sigstore messages nixos-unstable 0.5.0 nixpkgs-unstable 0.5.0 nixos-unstable-small 0.5.0 nixos-25.05 0.3.2 nixos-25.05-small 0.3.2 nixpkgs-25.05-darwin 0.3.2 Package maintainers: 3 @bbigras Bruno Bigras <bigras.bruno@gmail.com> @Bot-wxt1221 Bot-wxt1221 <3264117476@qq.com> @fabaff Fabian Affolter <mail@fabian-affolter.ch>
pkgs.k8s-manifest-sigstore Kubectl plugin for signing Kubernetes manifest YAML files with sigstore nixos-unstable 0.5.4 nixpkgs-unstable 0.5.4 nixos-unstable-small 0.5.4 nixos-25.05 0.5.4 nixos-25.05-small 0.5.4 nixpkgs-25.05-darwin 0.5.4
pkgs.python312Packages.sigstore Codesigning tool for Python packages nixos-unstable 4.0.0 nixpkgs-unstable 4.0.0 nixos-unstable-small 4.0.0 nixos-25.05 3.6.2 nixos-25.05-small 3.6.2 nixpkgs-25.05-darwin 3.6.2
pkgs.python313Packages.sigstore Codesigning tool for Python packages nixos-unstable 4.0.0 nixpkgs-unstable 4.0.0 nixos-unstable-small 4.0.0 nixos-25.05 3.6.2 nixos-25.05-small 3.6.2 nixpkgs-25.05-darwin 3.6.2
pkgs.python312Packages.sigstore-models Pydantic-based, protobuf-free data models for Sigstore nixos-unstable 0.0.5 nixpkgs-unstable 0.0.5 nixos-unstable-small 0.0.5
pkgs.python313Packages.sigstore-models Pydantic-based, protobuf-free data models for Sigstore nixos-unstable 0.0.5 nixpkgs-unstable 0.0.5 nixos-unstable-small 0.0.5
pkgs.python312Packages.sigstore-rekor-types Python models for Rekor's API types nixos-unstable 0.0.18 nixpkgs-unstable 0.0.18 nixos-unstable-small 0.0.18 nixos-25.05 0.0.18 nixos-25.05-small 0.0.18 nixpkgs-25.05-darwin 0.0.18
pkgs.python313Packages.sigstore-rekor-types Python models for Rekor's API types nixos-unstable 0.0.18 nixpkgs-unstable 0.0.18 nixos-unstable-small 0.0.18 nixos-25.05 0.0.18 nixos-25.05-small 0.0.18 nixpkgs-25.05-darwin 0.0.18
pkgs.python312Packages.sigstore-protobuf-specs Library for serializing and deserializing Sigstore messages nixos-unstable 0.5.0 nixpkgs-unstable 0.5.0 nixos-unstable-small 0.5.0 nixos-25.05 0.3.2 nixos-25.05-small 0.3.2 nixpkgs-25.05-darwin 0.3.2
pkgs.python313Packages.sigstore-protobuf-specs Library for serializing and deserializing Sigstore messages nixos-unstable 0.5.0 nixpkgs-unstable 0.5.0 nixos-unstable-small 0.5.0 nixos-25.05 0.3.2 nixos-25.05-small 0.3.2 nixpkgs-25.05-darwin 0.3.2
CVE-2025-24976 created 10 hours ago Distribution's token authentication allows attacker to inject an untrusted signing key in a JWT Distribution is a toolkit to pack, ship, store, and deliver container content. Systems running registry versions 3.0.0-beta.1 through 3.0.0-rc.2 with token authentication enabled may be vulnerable to an issue in which token authentication allows an attacker to inject an untrusted signing key in a JSON web token (JWT). The issue lies in how the JSON web key (JWK) verification is performed. When a JWT contains a JWK header without a certificate chain, the code only checks if the KeyID (`kid`) matches one of the trusted keys, but doesn't verify that the actual key material matches. A fix for the issue is available at commit 5ea9aa028db65ca5665f6af2c20ecf9dc34e5fcd and expected to be a part of version 3.0.0-rc.3. There is no way to work around this issue without patching if the system requires token authentication. Affected products distribution ==>= 3.0.0-beta.1, <= 3.0.0-rc.2 Matching in nixpkgs pkgs.distribution Toolkit to pack, ship, store, and deliver container content nixos-unstable 3.0.0 nixpkgs-unstable 3.0.0 nixos-unstable-small 3.0.0 nixos-25.05 3.0.0 nixos-25.05-small 3.0.0 nixpkgs-25.05-darwin 3.0.0 pkgs.protege-distribution OWL2 ontology editor from Stanford, with third-party plugins included nixos-unstable 5.6.3 nixpkgs-unstable 5.6.3 nixos-unstable-small 5.6.3 nixos-25.05 5.6.3 nixos-25.05-small 5.6.3 nixpkgs-25.05-darwin 5.6.3 pkgs.perlPackages.LinuxDistribution Perl extension to detect on which Linux distribution we are running nixos-unstable 0.23 nixpkgs-unstable 0.23 nixos-unstable-small 0.23 nixos-25.05 0.23 nixos-25.05-small 0.23 nixpkgs-25.05-darwin 0.23 pkgs.perl538Packages.LinuxDistribution Perl extension to detect on which Linux distribution we are running nixos-unstable 0.23 nixpkgs-unstable 0.23 nixos-unstable-small 0.23 nixos-25.05 0.23 nixos-25.05-small 0.23 nixpkgs-25.05-darwin 0.23 pkgs.perl540Packages.LinuxDistribution Perl extension to detect on which Linux distribution we are running nixos-unstable 0.23 nixpkgs-unstable 0.23 nixos-unstable-small 0.23 nixos-25.05 0.23 nixos-25.05-small 0.23 nixpkgs-25.05-darwin 0.23 pkgs.perlPackages.DistributionMetadata Distribution::Metadata - gather distribution metadata in local nixos-unstable 0.10 nixpkgs-unstable 0.10 nixos-unstable-small 0.10 pkgs.haskellPackages.normaldistribution Minimum fuss normally distributed random values nixos-unstable 1.1.0.3 nixpkgs-unstable 1.1.0.3 nixos-unstable-small 1.1.0.3 nixos-25.05 1.1.0.3 nixos-25.05-small 1.1.0.3 nixpkgs-25.05-darwin 1.1.0.3 pkgs.perlPackages.ParseLocalDistribution Parses local .pm files as PAUSE does nixos-unstable 0.19 nixpkgs-unstable 0.19 nixos-unstable-small 0.19 nixos-25.05 0.19 nixos-25.05-small 0.19 nixpkgs-25.05-darwin 0.19 pkgs.haskellPackages.distribution-nixpkgs Types and functions to manipulate the Nixpkgs distribution nixos-unstable 1.7.1.1 nixpkgs-unstable 1.7.1.1 nixos-unstable-small 1.7.1.1 nixos-25.05 1.7.1.1 nixos-25.05-small 1.7.1.1 nixpkgs-25.05-darwin 1.7.1.1 pkgs.perl538Packages.DistributionMetadata Distribution::Metadata - gather distribution metadata in local nixos-unstable 0.10 nixpkgs-unstable 0.10 nixos-unstable-small 0.10 pkgs.perl540Packages.DistributionMetadata Distribution::Metadata - gather distribution metadata in local nixos-unstable 0.10 nixpkgs-unstable 0.10 nixos-unstable-small 0.10 pkgs.perlPackages.StatisticsDistributions Perl module for calculating critical values and upper probabilities of common statistical distributions nixos-unstable 1.02 nixpkgs-unstable 1.02 nixos-unstable-small 1.02 nixos-25.05 1.02 nixos-25.05-small 1.02 nixpkgs-25.05-darwin 1.02 pkgs.haskellPackages.distribution-opensuse Types, functions, and tools to manipulate the openSUSE distribution nixos-unstable 1.1.4 nixpkgs-unstable 1.1.4 nixos-unstable-small 1.1.4 nixos-25.05 1.1.4 nixos-25.05-small 1.1.4 nixpkgs-25.05-darwin 1.1.4 pkgs.haskellPackages.splitmix-distributions Random samplers for some common distributions, based on splitmix nixos-unstable 1.1.0 nixpkgs-unstable 1.1.0 nixos-unstable-small 1.1.0 nixos-25.05 1.0.0 nixos-25.05-small 1.0.0 nixpkgs-25.05-darwin 1.0.0 pkgs.perl538Packages.ParseLocalDistribution Parses local .pm files as PAUSE does nixos-unstable 0.19 nixpkgs-unstable 0.19 nixos-unstable-small 0.19 nixos-25.05 0.19 nixos-25.05-small 0.19 nixpkgs-25.05-darwin 0.19 pkgs.perl540Packages.ParseLocalDistribution Parses local .pm files as PAUSE does nixos-unstable 0.19 nixpkgs-unstable 0.19 nixos-unstable-small 0.19 nixos-25.05 0.19 nixos-25.05-small 0.19 nixpkgs-25.05-darwin 0.19 pkgs.haskellPackages.ngx-export-distribution Build custom libraries for Nginx Haskell module nixos-unstable 0.6.0.1 nixpkgs-unstable 0.6.0.1 nixos-unstable-small 0.6.0.1 nixos-25.05 0.6.0.1 nixos-25.05-small 0.6.0.1 nixpkgs-25.05-darwin 0.6.0.1 pkgs.perl538Packages.StatisticsDistributions Perl module for calculating critical values and upper probabilities of common statistical distributions nixos-unstable 1.02 nixpkgs-unstable 1.02 nixos-unstable-small 1.02 nixos-25.05 1.02 nixos-25.05-small 1.02 nixpkgs-25.05-darwin 1.02 pkgs.perl540Packages.StatisticsDistributions Perl module for calculating critical values and upper probabilities of common statistical distributions nixos-unstable 1.02 nixpkgs-unstable 1.02 nixos-unstable-small 1.02 nixos-25.05 1.02 nixos-25.05-small 1.02 nixpkgs-25.05-darwin 1.02 pkgs.haskellPackages.distribution-nixpkgs-unstable Types and functions to manipulate the Nixpkgs distribution nixos-unstable 1.7.1.1-unstable-2025-11-11 nixpkgs-unstable 1.7.1.1-unstable-2025-11-11 nixos-unstable-small 1.7.1.1-unstable-2025-11-11 Package maintainers: 3 @katexochen Paul Meyer <katexochen0@gmail.com> @sternenseemann Lukas Epple <sternenseemann@systemli.org> @nessdoor Tomas Antonio Lopez <entropy.overseer@protonmail.com>
pkgs.distribution Toolkit to pack, ship, store, and deliver container content nixos-unstable 3.0.0 nixpkgs-unstable 3.0.0 nixos-unstable-small 3.0.0 nixos-25.05 3.0.0 nixos-25.05-small 3.0.0 nixpkgs-25.05-darwin 3.0.0
pkgs.protege-distribution OWL2 ontology editor from Stanford, with third-party plugins included nixos-unstable 5.6.3 nixpkgs-unstable 5.6.3 nixos-unstable-small 5.6.3 nixos-25.05 5.6.3 nixos-25.05-small 5.6.3 nixpkgs-25.05-darwin 5.6.3
pkgs.perlPackages.LinuxDistribution Perl extension to detect on which Linux distribution we are running nixos-unstable 0.23 nixpkgs-unstable 0.23 nixos-unstable-small 0.23 nixos-25.05 0.23 nixos-25.05-small 0.23 nixpkgs-25.05-darwin 0.23
pkgs.perl538Packages.LinuxDistribution Perl extension to detect on which Linux distribution we are running nixos-unstable 0.23 nixpkgs-unstable 0.23 nixos-unstable-small 0.23 nixos-25.05 0.23 nixos-25.05-small 0.23 nixpkgs-25.05-darwin 0.23
pkgs.perl540Packages.LinuxDistribution Perl extension to detect on which Linux distribution we are running nixos-unstable 0.23 nixpkgs-unstable 0.23 nixos-unstable-small 0.23 nixos-25.05 0.23 nixos-25.05-small 0.23 nixpkgs-25.05-darwin 0.23
pkgs.perlPackages.DistributionMetadata Distribution::Metadata - gather distribution metadata in local nixos-unstable 0.10 nixpkgs-unstable 0.10 nixos-unstable-small 0.10
pkgs.haskellPackages.normaldistribution Minimum fuss normally distributed random values nixos-unstable 1.1.0.3 nixpkgs-unstable 1.1.0.3 nixos-unstable-small 1.1.0.3 nixos-25.05 1.1.0.3 nixos-25.05-small 1.1.0.3 nixpkgs-25.05-darwin 1.1.0.3
pkgs.perlPackages.ParseLocalDistribution Parses local .pm files as PAUSE does nixos-unstable 0.19 nixpkgs-unstable 0.19 nixos-unstable-small 0.19 nixos-25.05 0.19 nixos-25.05-small 0.19 nixpkgs-25.05-darwin 0.19
pkgs.haskellPackages.distribution-nixpkgs Types and functions to manipulate the Nixpkgs distribution nixos-unstable 1.7.1.1 nixpkgs-unstable 1.7.1.1 nixos-unstable-small 1.7.1.1 nixos-25.05 1.7.1.1 nixos-25.05-small 1.7.1.1 nixpkgs-25.05-darwin 1.7.1.1
pkgs.perl538Packages.DistributionMetadata Distribution::Metadata - gather distribution metadata in local nixos-unstable 0.10 nixpkgs-unstable 0.10 nixos-unstable-small 0.10
pkgs.perl540Packages.DistributionMetadata Distribution::Metadata - gather distribution metadata in local nixos-unstable 0.10 nixpkgs-unstable 0.10 nixos-unstable-small 0.10
pkgs.perlPackages.StatisticsDistributions Perl module for calculating critical values and upper probabilities of common statistical distributions nixos-unstable 1.02 nixpkgs-unstable 1.02 nixos-unstable-small 1.02 nixos-25.05 1.02 nixos-25.05-small 1.02 nixpkgs-25.05-darwin 1.02
pkgs.haskellPackages.distribution-opensuse Types, functions, and tools to manipulate the openSUSE distribution nixos-unstable 1.1.4 nixpkgs-unstable 1.1.4 nixos-unstable-small 1.1.4 nixos-25.05 1.1.4 nixos-25.05-small 1.1.4 nixpkgs-25.05-darwin 1.1.4
pkgs.haskellPackages.splitmix-distributions Random samplers for some common distributions, based on splitmix nixos-unstable 1.1.0 nixpkgs-unstable 1.1.0 nixos-unstable-small 1.1.0 nixos-25.05 1.0.0 nixos-25.05-small 1.0.0 nixpkgs-25.05-darwin 1.0.0
pkgs.perl538Packages.ParseLocalDistribution Parses local .pm files as PAUSE does nixos-unstable 0.19 nixpkgs-unstable 0.19 nixos-unstable-small 0.19 nixos-25.05 0.19 nixos-25.05-small 0.19 nixpkgs-25.05-darwin 0.19
pkgs.perl540Packages.ParseLocalDistribution Parses local .pm files as PAUSE does nixos-unstable 0.19 nixpkgs-unstable 0.19 nixos-unstable-small 0.19 nixos-25.05 0.19 nixos-25.05-small 0.19 nixpkgs-25.05-darwin 0.19
pkgs.haskellPackages.ngx-export-distribution Build custom libraries for Nginx Haskell module nixos-unstable 0.6.0.1 nixpkgs-unstable 0.6.0.1 nixos-unstable-small 0.6.0.1 nixos-25.05 0.6.0.1 nixos-25.05-small 0.6.0.1 nixpkgs-25.05-darwin 0.6.0.1
pkgs.perl538Packages.StatisticsDistributions Perl module for calculating critical values and upper probabilities of common statistical distributions nixos-unstable 1.02 nixpkgs-unstable 1.02 nixos-unstable-small 1.02 nixos-25.05 1.02 nixos-25.05-small 1.02 nixpkgs-25.05-darwin 1.02
pkgs.perl540Packages.StatisticsDistributions Perl module for calculating critical values and upper probabilities of common statistical distributions nixos-unstable 1.02 nixpkgs-unstable 1.02 nixos-unstable-small 1.02 nixos-25.05 1.02 nixos-25.05-small 1.02 nixpkgs-25.05-darwin 1.02
pkgs.haskellPackages.distribution-nixpkgs-unstable Types and functions to manipulate the Nixpkgs distribution nixos-unstable 1.7.1.1-unstable-2025-11-11 nixpkgs-unstable 1.7.1.1-unstable-2025-11-11 nixos-unstable-small 1.7.1.1-unstable-2025-11-11
CVE-2025-32963 created 10 hours ago Minio Operator uses Kubernetes apiserver audience for AssumeRoleWithWebIdentity STS MinIO Operator STS is a native IAM Authentication for Kubernetes. Prior to version 7.1.0, if no audiences are provided for the `spec.audiences` field, the default will be of the Kubernetes apiserver. Without scoping, it can be replayed to other internal systems, which may unintentionally trust it. This issue has been patched in version 7.1.0. Affected products operator ==< 7.1.0 Matching in nixpkgs pkgs.operator-sdk SDK for building Kubernetes applications. Provides high level APIs, useful abstractions, and project scaffolding nixos-unstable 1.39.2 nixpkgs-unstable 1.39.2 nixos-unstable-small 1.39.2 nixos-25.05 1.39.2 nixos-25.05-small 1.39.2 nixpkgs-25.05-darwin 1.39.2 pkgs.atomic-operator Tool to execute Atomic Red Team tests (Atomics) nixos-unstable 0.8.5 nixpkgs-unstable 0.8.5 nixos-unstable-small 0.8.5 nixos-25.05 0.8.5 nixos-25.05-small 0.8.5 nixpkgs-25.05-darwin 0.8.5 pkgs.fluxcd-operator Kubernetes controller for managing the lifecycle of Flux CD nixos-unstable 0.23.0 nixpkgs-unstable 0.23.0 nixos-unstable-small 0.23.0 nixos-25.05 0.19.0 nixos-25.05-small 0.19.0 nixpkgs-25.05-darwin 0.19.0 pkgs.fluxcd-operator-mcp Kubernetes controller for managing the lifecycle of Flux CD nixos-unstable 0.29.0 nixpkgs-unstable 0.29.0 nixos-unstable-small 0.29.0 pkgs.python312Packages.linear-operator LinearOperator implementation to wrap the numerical nuts and bolts of GPyTorch nixos-unstable 0.6 nixpkgs-unstable 0.6 nixos-unstable-small 0.6 nixos-25.05 0.6 nixos-25.05-small 0.6 nixpkgs-25.05-darwin 0.6 pkgs.python313Packages.linear-operator LinearOperator implementation to wrap the numerical nuts and bolts of GPyTorch nixos-unstable 0.6 nixpkgs-unstable 0.6 nixos-unstable-small 0.6 nixos-25.05 0.6 nixos-25.05-small 0.6 nixpkgs-25.05-darwin 0.6 pkgs.chickenPackages_5.chickenEggs.F-operator Shift/Reset Control Operators nixos-unstable 4.1.4 nixpkgs-unstable 4.1.4 nixos-unstable-small 4.1.4 pkgs.pkgsRocm.python3Packages.linear-operator LinearOperator implementation to wrap the numerical nuts and bolts of GPyTorch nixos-unstable 0.6 nixpkgs-unstable 0.6 nixos-unstable-small 0.6 Package maintainers: 4 @fabaff Fabian Affolter <mail@fabian-affolter.ch> @mattfield Matt Field <matt@mild.systems> @arnarg Arnar Ingason <arnarg@fastmail.com> @veprbl Dmitry Kalinkin <veprbl@gmail.com>
pkgs.operator-sdk SDK for building Kubernetes applications. Provides high level APIs, useful abstractions, and project scaffolding nixos-unstable 1.39.2 nixpkgs-unstable 1.39.2 nixos-unstable-small 1.39.2 nixos-25.05 1.39.2 nixos-25.05-small 1.39.2 nixpkgs-25.05-darwin 1.39.2
pkgs.atomic-operator Tool to execute Atomic Red Team tests (Atomics) nixos-unstable 0.8.5 nixpkgs-unstable 0.8.5 nixos-unstable-small 0.8.5 nixos-25.05 0.8.5 nixos-25.05-small 0.8.5 nixpkgs-25.05-darwin 0.8.5
pkgs.fluxcd-operator Kubernetes controller for managing the lifecycle of Flux CD nixos-unstable 0.23.0 nixpkgs-unstable 0.23.0 nixos-unstable-small 0.23.0 nixos-25.05 0.19.0 nixos-25.05-small 0.19.0 nixpkgs-25.05-darwin 0.19.0
pkgs.fluxcd-operator-mcp Kubernetes controller for managing the lifecycle of Flux CD nixos-unstable 0.29.0 nixpkgs-unstable 0.29.0 nixos-unstable-small 0.29.0
pkgs.python312Packages.linear-operator LinearOperator implementation to wrap the numerical nuts and bolts of GPyTorch nixos-unstable 0.6 nixpkgs-unstable 0.6 nixos-unstable-small 0.6 nixos-25.05 0.6 nixos-25.05-small 0.6 nixpkgs-25.05-darwin 0.6
pkgs.python313Packages.linear-operator LinearOperator implementation to wrap the numerical nuts and bolts of GPyTorch nixos-unstable 0.6 nixpkgs-unstable 0.6 nixos-unstable-small 0.6 nixos-25.05 0.6 nixos-25.05-small 0.6 nixpkgs-25.05-darwin 0.6
pkgs.chickenPackages_5.chickenEggs.F-operator Shift/Reset Control Operators nixos-unstable 4.1.4 nixpkgs-unstable 4.1.4 nixos-unstable-small 4.1.4
pkgs.pkgsRocm.python3Packages.linear-operator LinearOperator implementation to wrap the numerical nuts and bolts of GPyTorch nixos-unstable 0.6 nixpkgs-unstable 0.6 nixos-unstable-small 0.6
CVE-2025-31130 created 10 hours ago gitoxide does not detect SHA-1 collision attacks gitoxide is an implementation of git written in Rust. Before 0.42.0, gitoxide uses SHA-1 hash implementations without any collision detection, leaving it vulnerable to hash collision attacks. gitoxide uses the sha1_smol or sha1 crate, both of which implement standard SHA-1 without any mitigations for collision attacks. This means that two distinct Git objects with colliding SHA-1 hashes would break the Git object model and integrity checks when used with gitoxide. This vulnerability is fixed in 0.42.0. Affected products gitoxide ==< 0.42.0 Matching in nixpkgs pkgs.gitoxide Command-line application for interacting with git repositories nixos-unstable 0.45.0 nixpkgs-unstable 0.45.0 nixos-unstable-small 0.45.0 nixos-25.05 0.42.0 nixos-25.05-small 0.42.0 nixpkgs-25.05-darwin 0.42.0 Package maintainers: 1 @syberant Sybrand Aarnoutse <sybrand@neuralcoding.com>
pkgs.gitoxide Command-line application for interacting with git repositories nixos-unstable 0.45.0 nixpkgs-unstable 0.45.0 nixos-unstable-small 0.45.0 nixos-25.05 0.42.0 nixos-25.05-small 0.42.0 nixpkgs-25.05-darwin 0.42.0
CVE-2025-3839 created 10 hours ago Epiphany: insecure external protocol invocation in epiphany A flaw was found in Epiphany, a tool that allows websites to open external URL handler applications with minimal user interaction. This design can be misused to exploit vulnerabilities within those handlers, making them appear remotely exploitable. The browser fails to properly warn or gate this action, resulting in potential code execution on the client device via trusted UI behavior. Affected products epiphany <47.5 <48.1 Matching in nixpkgs pkgs.epiphany WebKit based web browser for GNOME nixos-unstable 49.1 nixpkgs-unstable 49.1 nixos-unstable-small 49.1 nixos-25.05 48.3 nixos-25.05-small 48.3 nixpkgs-25.05-darwin 48.3 pkgs.pantheon.epiphany WebKit based web browser for GNOME nixos-unstable 49.1 nixpkgs-unstable 49.1 nixos-unstable-small 49.1 nixos-25.05 48.3 nixos-25.05-small 48.3 nixpkgs-25.05-darwin 48.3 Package maintainers: 5 @bobby285271 Bobby Rong <rjl931189261@126.com> @davidak David Kleuker <post@davidak.de> @jtojnar Jan Tojnar <jtojnar@gmail.com> @hedning Tor Hedin Brønner <torhedinbronner@gmail.com> @dasj19 Daniel Șerbănescu <daniel@serbanescu.dk>
pkgs.epiphany WebKit based web browser for GNOME nixos-unstable 49.1 nixpkgs-unstable 49.1 nixos-unstable-small 49.1 nixos-25.05 48.3 nixos-25.05-small 48.3 nixpkgs-25.05-darwin 48.3
pkgs.pantheon.epiphany WebKit based web browser for GNOME nixos-unstable 49.1 nixpkgs-unstable 49.1 nixos-unstable-small 49.1 nixos-25.05 48.3 nixos-25.05-small 48.3 nixpkgs-25.05-darwin 48.3
CVE-2026-24474 created 10 hours ago Dioxus Components has JavaScript injection via user-supplied IDs Dioxus Components is a shadcn-style component library for the Dioxus app framework. Prior to commit 41e4242ecb1062d04ae42a5215363c1d9fd4e23a, `use_animated_open` formats a string for `eval` with an `id` that can be user supplied. Commit 41e4242ecb1062d04ae42a5215363c1d9fd4e23a patches the issue. Affected products components ==< 41e4242ecb1062d04ae42a5215363c1d9fd4e23a Matching in nixpkgs pkgs.lomiri.lomiri-settings-components QML settings components for the Lomiri Desktop Environment nixos-unstable 1.1.3 nixpkgs-unstable 1.1.3 nixos-unstable-small 1.1.3 nixos-25.05 1.1.2 nixos-25.05-small 1.1.2 nixpkgs-25.05-darwin 1.1.2 pkgs.python312Packages.dash-core-components Dash component starter pack nixos-unstable 2.0.0 nixpkgs-unstable 2.0.0 nixos-unstable-small 2.0.0 nixos-25.05 2.0.0 nixos-25.05-small 2.0.0 nixpkgs-25.05-darwin 2.0.0 pkgs.python312Packages.dash-html-components HTML components for Dash nixos-unstable 2.0.0 nixpkgs-unstable 2.0.0 nixos-unstable-small 2.0.0 nixos-25.05 2.0.0 nixos-25.05-small 2.0.0 nixpkgs-25.05-darwin 2.0.0 pkgs.python313Packages.dash-core-components Dash component starter pack nixos-unstable 2.0.0 nixpkgs-unstable 2.0.0 nixos-unstable-small 2.0.0 nixos-25.05 2.0.0 nixos-25.05-small 2.0.0 nixpkgs-25.05-darwin 2.0.0 pkgs.python313Packages.dash-html-components HTML components for Dash nixos-unstable 2.0.0 nixpkgs-unstable 2.0.0 nixos-unstable-small 2.0.0 nixos-25.05 2.0.0 nixos-25.05-small 2.0.0 nixpkgs-25.05-darwin 2.0.0 pkgs.python312Packages.connected-components-3d Connected components on discrete and continuous multilabel 3D & 2D images nixos-unstable 3d-3.22.0 nixpkgs-unstable 3d-3.22.0 nixos-unstable-small 3d-3.22.0 nixos-25.05 3d-3.22.0 nixos-25.05-small 3d-3.22.0 nixpkgs-25.05-darwin 3d-3.22.0 pkgs.python313Packages.connected-components-3d Connected components on discrete and continuous multilabel 3D & 2D images nixos-unstable 3d-3.22.0 nixpkgs-unstable 3d-3.22.0 nixos-unstable-small 3d-3.22.0 nixos-25.05 3d-3.22.0 nixos-25.05-small 3d-3.22.0 nixpkgs-25.05-darwin 3d-3.22.0 pkgs.python312Packages.dash-bootstrap-components Bootstrap components for Plotly Dash nixos-unstable 2.0.4 nixpkgs-unstable 2.0.4 nixos-unstable-small 2.0.4 nixos-25.05 2.0.2 nixos-25.05-small 2.0.2 nixpkgs-25.05-darwin 2.0.2 pkgs.python313Packages.dash-bootstrap-components Bootstrap components for Plotly Dash nixos-unstable 2.0.4 nixpkgs-unstable 2.0.4 nixos-unstable-small 2.0.4 nixos-25.05 2.0.2 nixos-25.05-small 2.0.2 nixpkgs-25.05-darwin 2.0.2 pkgs.vscode-extensions.styled-components.vscode-styled-components Syntax highlighting and IntelliSense for styled-components nixos-unstable 1.7.8 nixpkgs-unstable 1.7.8 nixos-unstable-small 1.7.8 nixos-25.05 1.7.8 nixos-25.05-small 1.7.8 nixpkgs-25.05-darwin 1.7.8 Package maintainers: 4 @OPNA2608 Cosima Neidahl <opna2608@protonmail.com> @bcdarwin Ben Darwin <bcdarwin@gmail.com> @fabaff Fabian Affolter <mail@fabian-affolter.ch> @antoinerg Antoine Roy-Gobeil <roygobeil.antoine@gmail.com>
pkgs.lomiri.lomiri-settings-components QML settings components for the Lomiri Desktop Environment nixos-unstable 1.1.3 nixpkgs-unstable 1.1.3 nixos-unstable-small 1.1.3 nixos-25.05 1.1.2 nixos-25.05-small 1.1.2 nixpkgs-25.05-darwin 1.1.2
pkgs.python312Packages.dash-core-components Dash component starter pack nixos-unstable 2.0.0 nixpkgs-unstable 2.0.0 nixos-unstable-small 2.0.0 nixos-25.05 2.0.0 nixos-25.05-small 2.0.0 nixpkgs-25.05-darwin 2.0.0
pkgs.python312Packages.dash-html-components HTML components for Dash nixos-unstable 2.0.0 nixpkgs-unstable 2.0.0 nixos-unstable-small 2.0.0 nixos-25.05 2.0.0 nixos-25.05-small 2.0.0 nixpkgs-25.05-darwin 2.0.0
pkgs.python313Packages.dash-core-components Dash component starter pack nixos-unstable 2.0.0 nixpkgs-unstable 2.0.0 nixos-unstable-small 2.0.0 nixos-25.05 2.0.0 nixos-25.05-small 2.0.0 nixpkgs-25.05-darwin 2.0.0
pkgs.python313Packages.dash-html-components HTML components for Dash nixos-unstable 2.0.0 nixpkgs-unstable 2.0.0 nixos-unstable-small 2.0.0 nixos-25.05 2.0.0 nixos-25.05-small 2.0.0 nixpkgs-25.05-darwin 2.0.0
pkgs.python312Packages.connected-components-3d Connected components on discrete and continuous multilabel 3D & 2D images nixos-unstable 3d-3.22.0 nixpkgs-unstable 3d-3.22.0 nixos-unstable-small 3d-3.22.0 nixos-25.05 3d-3.22.0 nixos-25.05-small 3d-3.22.0 nixpkgs-25.05-darwin 3d-3.22.0
pkgs.python313Packages.connected-components-3d Connected components on discrete and continuous multilabel 3D & 2D images nixos-unstable 3d-3.22.0 nixpkgs-unstable 3d-3.22.0 nixos-unstable-small 3d-3.22.0 nixos-25.05 3d-3.22.0 nixos-25.05-small 3d-3.22.0 nixpkgs-25.05-darwin 3d-3.22.0
pkgs.python312Packages.dash-bootstrap-components Bootstrap components for Plotly Dash nixos-unstable 2.0.4 nixpkgs-unstable 2.0.4 nixos-unstable-small 2.0.4 nixos-25.05 2.0.2 nixos-25.05-small 2.0.2 nixpkgs-25.05-darwin 2.0.2
pkgs.python313Packages.dash-bootstrap-components Bootstrap components for Plotly Dash nixos-unstable 2.0.4 nixpkgs-unstable 2.0.4 nixos-unstable-small 2.0.4 nixos-25.05 2.0.2 nixos-25.05-small 2.0.2 nixpkgs-25.05-darwin 2.0.2
pkgs.vscode-extensions.styled-components.vscode-styled-components Syntax highlighting and IntelliSense for styled-components nixos-unstable 1.7.8 nixpkgs-unstable 1.7.8 nixos-unstable-small 1.7.8 nixos-25.05 1.7.8 nixos-25.05-small 1.7.8 nixpkgs-25.05-darwin 1.7.8
CVE-2025-59432 created 10 hours ago Timing Attack Vulnerability in SCRAM Authentication SCRAM (Salted Challenge Response Authentication Mechanism) is part of the family of Simple Authentication and Security Layer (SASL, RFC 4422) authentication mechanisms. Prior to version 3.2, a timing attack vulnerability exists in the SCRAM Java implementation. The issue arises because Arrays.equals was used to compare secret values such as client proofs and server signatures. Since Arrays.equals performs a short-circuit comparison, the execution time varies depending on how many leading bytes match. This behavior could allow an attacker to perform a timing side-channel attack and potentially infer sensitive authentication material. All users relying on SCRAM authentication are impacted. This vulnerability has been patched in version 3.1 by replacing Arrays.equals with MessageDigest.isEqual, which ensures constant-time comparison. Affected products scram ==< 3.2 Matching in nixpkgs pkgs.perlPackages.AuthenSCRAM Salted Challenge Response Authentication Mechanism (RFC 5802) nixos-unstable 0.011 nixpkgs-unstable 0.011 nixos-unstable-small 0.011 nixos-25.05 0.011 nixos-25.05-small 0.011 nixpkgs-25.05-darwin 0.011 pkgs.python312Packages.scramp Implementation of the SCRAM authentication protocol nixos-unstable 1.4.5 nixpkgs-unstable 1.4.5 nixos-unstable-small 1.4.5 nixos-25.05 1.4.5 nixos-25.05-small 1.4.5 nixpkgs-25.05-darwin 1.4.5 pkgs.python313Packages.scramp Implementation of the SCRAM authentication protocol nixos-unstable 1.4.5 nixpkgs-unstable 1.4.5 nixos-unstable-small 1.4.5 nixos-25.05 1.4.5 nixos-25.05-small 1.4.5 nixpkgs-25.05-darwin 1.4.5 pkgs.perl538Packages.AuthenSCRAM Salted Challenge Response Authentication Mechanism (RFC 5802) nixos-unstable 0.011 nixpkgs-unstable 0.011 nixos-unstable-small 0.011 nixos-25.05 0.011 nixos-25.05-small 0.011 nixpkgs-25.05-darwin 0.011 pkgs.perl540Packages.AuthenSCRAM Salted Challenge Response Authentication Mechanism (RFC 5802) nixos-unstable 0.011 nixpkgs-unstable 0.011 nixos-unstable-small 0.011 pkgs.haskellPackages.yaml-unscrambler Flexible declarative YAML parsing toolkit nixos-unstable 0.1.0.20 nixpkgs-unstable 0.1.0.20 nixos-unstable-small 0.1.0.20 nixos-25.05 0.1.0.19 nixos-25.05-small 0.1.0.19 nixpkgs-25.05-darwin 0.1.0.19 Package maintainers: 1 @stigtsp Stig Palmquist <stig@stig.io>
pkgs.perlPackages.AuthenSCRAM Salted Challenge Response Authentication Mechanism (RFC 5802) nixos-unstable 0.011 nixpkgs-unstable 0.011 nixos-unstable-small 0.011 nixos-25.05 0.011 nixos-25.05-small 0.011 nixpkgs-25.05-darwin 0.011
pkgs.python312Packages.scramp Implementation of the SCRAM authentication protocol nixos-unstable 1.4.5 nixpkgs-unstable 1.4.5 nixos-unstable-small 1.4.5 nixos-25.05 1.4.5 nixos-25.05-small 1.4.5 nixpkgs-25.05-darwin 1.4.5
pkgs.python313Packages.scramp Implementation of the SCRAM authentication protocol nixos-unstable 1.4.5 nixpkgs-unstable 1.4.5 nixos-unstable-small 1.4.5 nixos-25.05 1.4.5 nixos-25.05-small 1.4.5 nixpkgs-25.05-darwin 1.4.5
pkgs.perl538Packages.AuthenSCRAM Salted Challenge Response Authentication Mechanism (RFC 5802) nixos-unstable 0.011 nixpkgs-unstable 0.011 nixos-unstable-small 0.011 nixos-25.05 0.011 nixos-25.05-small 0.011 nixpkgs-25.05-darwin 0.011
pkgs.perl540Packages.AuthenSCRAM Salted Challenge Response Authentication Mechanism (RFC 5802) nixos-unstable 0.011 nixpkgs-unstable 0.011 nixos-unstable-small 0.011
pkgs.haskellPackages.yaml-unscrambler Flexible declarative YAML parsing toolkit nixos-unstable 0.1.0.20 nixpkgs-unstable 0.1.0.20 nixos-unstable-small 0.1.0.20 nixos-25.05 0.1.0.19 nixos-25.05-small 0.1.0.19 nixpkgs-25.05-darwin 0.1.0.19