CVE-2025-6545 created 4 months ago pbkdf2 silently returns predictable uninitialized/zero-filled memory for non-normalized or unimplemented algos supported by Node.js Improper Input Validation vulnerability in pbkdf2 allows Signature Spoofing by Improper Validation. This vulnerability is associated with program files lib/to-buffer.Js. This issue affects pbkdf2: from 3.0.10 through 3.1.2. Affected products pbkdf2 =<3.1.2 Matching in nixpkgs pkgs.fastpbkdf2 Fast PBKDF2-HMAC-{SHA1,SHA256,SHA512} implementation in C nixos-unstable - nixpkgs-unstable 1.0.0 pkgs.python312Packages.pbkdf2 nixos-unstable - nixpkgs-unstable pbkdf2-1.3 pkgs.python313Packages.pbkdf2 nixos-unstable - nixpkgs-unstable pbkdf2-1.3 pkgs.python312Packages.fastpbkdf2 Python bindings for fastpbkdf2 nixos-unstable - nixpkgs-unstable fastpbkdf2-0.2 pkgs.python313Packages.fastpbkdf2 Python bindings for fastpbkdf2 nixos-unstable - nixpkgs-unstable fastpbkdf2-0.2 pkgs.chickenPackages_5.chickenEggs.pbkdf2 Password-Based Key Derivation Function as defined in RFC2898 nixos-unstable - nixpkgs-unstable pbkdf2-1.3 Package maintainers: 2 @ledif Adam Fidel <refuse@gmail.com> @jqueiroz Jonathan Queiroz <nixos@johnjq.com>
pkgs.fastpbkdf2 Fast PBKDF2-HMAC-{SHA1,SHA256,SHA512} implementation in C nixos-unstable - nixpkgs-unstable 1.0.0
pkgs.python312Packages.fastpbkdf2 Python bindings for fastpbkdf2 nixos-unstable - nixpkgs-unstable fastpbkdf2-0.2
pkgs.python313Packages.fastpbkdf2 Python bindings for fastpbkdf2 nixos-unstable - nixpkgs-unstable fastpbkdf2-0.2
pkgs.chickenPackages_5.chickenEggs.pbkdf2 Password-Based Key Derivation Function as defined in RFC2898 nixos-unstable - nixpkgs-unstable pbkdf2-1.3
CVE-2025-5416 updated 2 months, 2 weeks ago by @LeSuisse Activity log Created automatic suggestion 4 months ago @LeSuisse removed 3 packages terraform-providers.keycloak python312Packages.python-keycloak python313Packages.python-keycloak 2 months, 2 weeks ago Keycloak-core: keycloak environment information A vulnerability has been identified in Keycloak that could lead to unauthorized information disclosure. While it requires an already authenticated user, the /admin/serverinfo endpoint can inadvertently provide sensitive environment information. Affected products keycloak Matching in nixpkgs pkgs.keycloak Identity and access management for modern applications and services nixos-unstable - nixpkgs-unstable 26.3.4 Package maintainers: 4 @ngerstle Nicholas Gerstle <ngerstle@gmail.com> @NickCao Nick Cao <nickcao@nichi.co> @talyz Kim Lindberger <kim.lindberger@gmail.com> @leona-ya Leona Maroni <nix@leona.is>
pkgs.keycloak Identity and access management for modern applications and services nixos-unstable - nixpkgs-unstable 26.3.4
CVE-2025-6019 created 4 months ago Libblockdev: lpe from allow_active to root in libblockdev via udisks A Local Privilege Escalation (LPE) vulnerability was found in libblockdev. Generally, the "allow_active" setting in Polkit permits a physically present user to take certain actions based on the session type. Due to the way libblockdev interacts with the udisks daemon, an "allow_active" user on a system may be able escalate to full root privileges on the target host. Normally, udisks mounts user-provided filesystem images with security flags like nosuid and nodev to prevent privilege escalation. However, a local attacker can create a specially crafted XFS image containing a SUID-root shell, then trick udisks into resizing it. This mounts their malicious filesystem with root privileges, allowing them to execute their SUID-root shell and gain complete control of the system. Affected products libblockdev * <3.3.1 Matching in nixpkgs pkgs.libblockdev Library for manipulating block devices nixos-unstable - nixpkgs-unstable 3.3.0 Package maintainers: 1 @JohnAZoidberg Daniel Schäfer <git@danielschaefer.me>
CVE-2025-6384 created 4 months ago Improper Control of Dynamically-Managed Code Resources in Crafter Studio Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of CrafterCMS allows authenticated developers to execute OS commands via Groovy Sandbox Bypass. By inserting malicious Groovy elements, an attacker may bypass Sandbox restrictions and obtain RCE (Remote Code Execution). This issue affects CrafterCMS: from 4.0.0 through 4.2.2. Affected products Studio <4.3.0 Matching in nixpkgs pkgs.rstudio Set of integrated tools for the R language nixos-unstable - nixpkgs-unstable 2025.05.1+513 pkgs.rstudio-server Set of integrated tools for the R language nixos-unstable - nixpkgs-unstable 2025.05.1+513 pkgs.rstudioWrapper nixos-unstable - nixpkgs-unstable 2025.05.1+513-wrapper pkgs.rstudioServerWrapper nixos-unstable - nixpkgs-unstable 2025.05.1+513-wrapper pkgs.vscode-extensions.visualstudiotoolsforunity.vstuc Integrates Visual Studio Code for Unity nixos-unstable - nixpkgs-unstable 1.1.3 pkgs.vscode-extensions.visualstudioexptteam.vscodeintellicode AI-assisted development nixos-unstable - nixpkgs-unstable 1.3.2 pkgs.vscode-extensions.visualstudioexptteam.intellicode-api-usage-examples See relevant code examples from GitHub for over 100K different APIs right in your editor nixos-unstable - nixpkgs-unstable 0.2.9 Package maintainers: 5 @TomaSajt TomaSajt @cfhammill Chris Hammill <cfhammill@gmail.com> @ciil Simon Lackerbauer <simon@lackerbauer.com> @TheMaxMur Maxim Muravev <muravjev.mak@yandex.ru> @mibmo mib <mib@kanp.ai>
pkgs.rstudio Set of integrated tools for the R language nixos-unstable - nixpkgs-unstable 2025.05.1+513
pkgs.rstudio-server Set of integrated tools for the R language nixos-unstable - nixpkgs-unstable 2025.05.1+513
pkgs.vscode-extensions.visualstudiotoolsforunity.vstuc Integrates Visual Studio Code for Unity nixos-unstable - nixpkgs-unstable 1.1.3
pkgs.vscode-extensions.visualstudioexptteam.vscodeintellicode AI-assisted development nixos-unstable - nixpkgs-unstable 1.3.2
pkgs.vscode-extensions.visualstudioexptteam.intellicode-api-usage-examples See relevant code examples from GitHub for over 100K different APIs right in your editor nixos-unstable - nixpkgs-unstable 0.2.9
CVE-2025-49254 created 4 months ago WordPress Nika <= 1.2.8 - Local File Inclusion Vulnerability Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Nika allows PHP Local File Inclusion. This issue affects Nika: from n/a through 1.2.8. Affected products nika =<1.2.8 Matching in nixpkgs pkgs.nika-fonts Persian/Arabic Open Source Font nixos-unstable - nixpkgs-unstable 1.0.0 pkgs.python312Packages.minikanren Relational programming in Python nixos-unstable - nixpkgs-unstable 1.0.5 pkgs.python313Packages.minikanren Relational programming in Python nixos-unstable - nixpkgs-unstable 1.0.5 Package maintainers: 1 @Etjean Etienne Jean <et.jean@outlook.fr>
pkgs.python312Packages.minikanren Relational programming in Python nixos-unstable - nixpkgs-unstable 1.0.5
pkgs.python313Packages.minikanren Relational programming in Python nixos-unstable - nixpkgs-unstable 1.0.5
CVE-2025-49179 created 4 months ago Xorg-x11-server-xwayland: xorg-x11-server: tigervnc: integer overflow in x record extension A flaw was found in the X Record extension. The RecordSanityCheckRegisterClients function does not check for an integer overflow when computing request length, which allows a client to bypass length checks. Affected products tigervnc * xwayland <24.1.7 xorg-x11-server * xorg-x11-server-Xwayland * Matching in nixpkgs pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-unstable - nixpkgs-unstable 1.15.0
pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-unstable - nixpkgs-unstable 1.15.0
CVE-2025-49175 created 4 months ago Xorg-x11-server-xwayland: xorg-x11-server: tigervnc: out-of-bounds read in x rendering extension animated cursors A flaw was found in the X Rendering extension's handling of animated cursors. If a client provides no cursors, the server assumes at least one is present, leading to an out-of-bounds read and potential crash. Affected products tigervnc * xwayland <24.1.8 xorg-x11-server * xorg-x11-server-Xwayland * Matching in nixpkgs pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-unstable - nixpkgs-unstable 1.15.0
pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-unstable - nixpkgs-unstable 1.15.0
CVE-2025-49176 created 4 months ago Xorg-x11-server-xwayland: xorg-x11-server: tigervnc: integer overflow in big requests extension A flaw was found in the Big Requests extension. The request length is multiplied by 4 before checking against the maximum allowed size, potentially causing an integer overflow and bypassing the size check. Affected products tigervnc * xwayland <24.1.7 xorg-x11-server * xorg-x11-server-Xwayland * Matching in nixpkgs pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-unstable - nixpkgs-unstable 1.15.0
pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-unstable - nixpkgs-unstable 1.15.0
CVE-2025-24761 created 4 months ago WordPress DSK <= 2.2 - Local File Inclusion Vulnerability Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in snstheme DSK allows PHP Local File Inclusion. This issue affects DSK: from n/a through 2.2. Affected products dsk =<2.2 Matching in nixpkgs pkgs.idsk Manipulating CPC dsk images and files nixos-unstable - nixpkgs-unstable 0.20 pkgs.libdsk Library for accessing discs and disc image files nixos-unstable - nixpkgs-unstable 1.5.22 pkgs.robotfindskitten Yet another zen simulation; A simple find-the-kitten game nixos-unstable - nixpkgs-unstable 2.8284271.702 pkgs.python312Packages.pmdsky-debug-py Autogenerated and statically check-able pmdsky-debug symbol definitions for Python nixos-unstable - nixpkgs-unstable 10.0.48 pkgs.python313Packages.pmdsky-debug-py Autogenerated and statically check-able pmdsky-debug symbol definitions for Python nixos-unstable - nixpkgs-unstable 10.0.48 Package maintainers: 2 @wegank Weijia Wang <contact@weijia.wang> @marius851000 Marius David <nix@mariusdavid.fr>
pkgs.libdsk Library for accessing discs and disc image files nixos-unstable - nixpkgs-unstable 1.5.22
pkgs.robotfindskitten Yet another zen simulation; A simple find-the-kitten game nixos-unstable - nixpkgs-unstable 2.8284271.702
pkgs.python312Packages.pmdsky-debug-py Autogenerated and statically check-able pmdsky-debug symbol definitions for Python nixos-unstable - nixpkgs-unstable 10.0.48
pkgs.python313Packages.pmdsky-debug-py Autogenerated and statically check-able pmdsky-debug symbol definitions for Python nixos-unstable - nixpkgs-unstable 10.0.48
CVE-2025-31919 created 4 months ago WordPress Spare <= 1.7 - PHP Object Injection Vulnerability Deserialization of Untrusted Data vulnerability in themeton Spare allows Object Injection. This issue affects Spare: from n/a through 1.7. Affected products spare =<1.7 Matching in nixpkgs pkgs.asciiquarium-transparent Aquarium/sea animation in ASCII art (with option of transparent background) nixos-unstable - nixpkgs-unstable 1.4 pkgs.materia-theme-transparent Transparent Material Design theme for GNOME/GTK based desktop environments nixos-unstable - nixpkgs-unstable 0-unstable-2021-03-22 pkgs.gnomeExtensions.transparent-top-bar Bring back the transparent top bar when free-floating in GNOME Shell 3.32. nixos-unstable - nixpkgs-unstable 24 pkgs.gnomeExtensions.transparent-window-moving Makes the window semi-transparent when moving or resizing nixos-unstable - nixpkgs-unstable 19 pkgs.sway-contrib.inactive-windows-transparency It makes inactive sway windows transparent nixos-unstable - nixpkgs-unstable 0-unstable-2024-03-19 pkgs.gnomeExtensions.transparent-top-bar-adjustable-transparency Fork of: https://github.com/zhanghai/gnome-shell-extension-transparent-top-bar nixos-unstable - nixpkgs-unstable 24 Package maintainers: 4 @quantenzitrone quantenzitrone <nix@dev.quantenzitrone.eu> @honnip Jung seungwoo <me@honnip.page> @CorbinWunderlich Corbin Wunderlich <corbin@wcopy.net> @evils Evils <evils.devils@protonmail.com>
pkgs.asciiquarium-transparent Aquarium/sea animation in ASCII art (with option of transparent background) nixos-unstable - nixpkgs-unstable 1.4
pkgs.materia-theme-transparent Transparent Material Design theme for GNOME/GTK based desktop environments nixos-unstable - nixpkgs-unstable 0-unstable-2021-03-22
pkgs.gnomeExtensions.transparent-top-bar Bring back the transparent top bar when free-floating in GNOME Shell 3.32. nixos-unstable - nixpkgs-unstable 24
pkgs.gnomeExtensions.transparent-window-moving Makes the window semi-transparent when moving or resizing nixos-unstable - nixpkgs-unstable 19
pkgs.sway-contrib.inactive-windows-transparency It makes inactive sway windows transparent nixos-unstable - nixpkgs-unstable 0-unstable-2024-03-19
pkgs.gnomeExtensions.transparent-top-bar-adjustable-transparency Fork of: https://github.com/zhanghai/gnome-shell-extension-transparent-top-bar nixos-unstable - nixpkgs-unstable 24