Dismissed suggestions Untriaged suggestions Draft issues Published issues Automatically generated suggestions Create Draft to queue a suggestion for refinement. Dismiss to remove a suggestion from the queue. CVE-2025-31638 7.1 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): CHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 2 months, 2 weeks ago WordPress Spare <= 1.7 - Cross Site Scripting (XSS) Vulnerability Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themeton Spare allows Reflected XSS. This issue affects Spare: from n/a through 1.7. spare =<1.7 pkgs.asciiquarium-transparent Aquarium/sea animation in ASCII art (with option of transparent background) nixos-unstable ??? nixpkgs-unstable 1.4 pkgs.materia-theme-transparent Transparent Material Design theme for GNOME/GTK based desktop environments nixos-unstable ??? nixpkgs-unstable 0-unstable-2021-03-22 pkgs.gnomeExtensions.transparent-top-bar Bring back the transparent top bar when free-floating in GNOME Shell 3.32. nixos-unstable ??? nixpkgs-unstable 24 pkgs.gnomeExtensions.transparent-window-moving Makes the window semi-transparent when moving or resizing nixos-unstable ??? nixpkgs-unstable 19 pkgs.sway-contrib.inactive-windows-transparency It makes inactive sway windows transparent nixos-unstable ??? nixpkgs-unstable 0-unstable-2024-03-19 pkgs.gnomeExtensions.transparent-top-bar-adjustable-transparency Fork of: https://github.com/zhanghai/gnome-shell-extension-transparent-top-bar nixos-unstable ??? nixpkgs-unstable 24 Package maintainers: 4 @quantenzitrone quantenzitrone <nix@dev.quantenzitrone.eu> @evils Evils <evils.devils@protonmail.com> @honnip Jung seungwoo <me@honnip.page> @CorbinWunderlich Corbin Wunderlich <corbin@wcopy.net> CVE-2025-28945 8.1 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 2 months, 2 weeks ago WordPress Valen - Sport, Fashion WooCommerce WordPress Theme <= 2.4 - Local File Inclusion Vulnerability Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in snstheme Valen - Sport, Fashion WooCommerce WordPress Theme allows PHP Local File Inclusion. This issue affects Valen - Sport, Fashion WooCommerce WordPress Theme: from n/a through 2.4. valen =<2.4 pkgs.valent Implementation of the KDE Connect protocol, built on GNOME platform libraries nixos-unstable ??? nixpkgs-unstable 1.0.0.alpha.46-unstable-2024-10-26 pkgs.valentina Open source sewing pattern drafting software nixos-unstable ??? nixpkgs-unstable 0.7.53 pkgs.gnomeExtensions.valent GNOME Shell integration for Valent nixos-unstable ??? nixpkgs-unstable 1.0.0.alpha.48 pkgs.sbclPackages.cl-prevalence nixos-unstable ??? nixpkgs-unstable 20250622-git pkgs.haskellPackages.equivalence Maintaining an equivalence relation implemented as union-find using STT nixos-unstable ??? nixpkgs-unstable 0.4.1 pkgs.vscode-extensions.valentjn.vscode-ltex nixos-unstable ??? nixpkgs-unstable 13.1.0 Package maintainers: 7 @0xbe7a Bela Stoyan <nix@be7a.de> @hraban Hraban Luyat <hraban@0brg.net> @Uthar Kasper Gałkowski <galkowskikasper@gmail.com> @7c6f434c Michael Raskin <7c6f434c@mail.ru> @nagy Daniel Nagy <danielnagy@posteo.de> @lukego Luke Gorrie <luke@snabb.co> @Aleksanaa Aleksana QwQ <me@aleksana.moe> CVE-2025-5918 3.9 LOW CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): NONE Availability impact (A): LOW created 2 months, 2 weeks ago Libarchive: reading past eof may be triggered for piped file streams A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for reading past the end of the file. This out-of-bounds read can lead to unintended consequences, including unpredictable program behavior, memory corruption, or a denial-of-service condition. rhcos libarchive <3.8.0 pkgs.libarchive Multi-format archive and compression library nixos-unstable ??? nixpkgs-unstable 3.8.1 pkgs.libarchive-qt Qt based archiving solution with libarchive backend nixos-unstable ??? nixpkgs-unstable 2.0.8 pkgs.haskellPackages.libarchive Haskell interface to libarchive nixos-unstable ??? nixpkgs-unstable 3.0.4.2 pkgs.kodiPackages.vfs-libarchive LibArchive Virtual Filesystem add-on for Kodi nixos-unstable ??? nixpkgs-unstable 20.1.0 pkgs.python312Packages.libarchive-c Python interface to libarchive nixos-unstable ??? nixpkgs-unstable 5.3 pkgs.python313Packages.libarchive-c Python interface to libarchive nixos-unstable ??? nixpkgs-unstable 5.3 pkgs.haskellPackages.archive-libarchive Common interface using libarchive nixos-unstable ??? nixpkgs-unstable 1.0.0.1 pkgs.haskellPackages.libarchive-conduit Read many archive formats with libarchive and conduit nixos-unstable ??? nixpkgs-unstable 0.1.0.0 pkgs.python312Packages.extractcode-libarchive ScanCode Toolkit plugin to provide pre-built binary libraries and utilities and their locations nixos-unstable ??? nixpkgs-unstable 21.5.31 pkgs.python313Packages.extractcode-libarchive ScanCode Toolkit plugin to provide pre-built binary libraries and utilities and their locations nixos-unstable ??? nixpkgs-unstable 21.5.31 Package maintainers: 8 @jcumming Jack Cummings <jack@mudshark.org> @aanderse Aaron Andersen <aaron@fosslib.net> @dschrempf Dominik Schrempf <dominik.schrempf@gmail.com> @edwtjo Edward Tjörnhammar <ed@cflags.cc> @minijackson Rémi Nicole <minijackson@riseup.net> @peterhoeg Peter Hoeg <peter@hoeg.com> @nvmd Sergey Kazenyuk <kazenyuk@pm.me> @cpages Carles Pagès <page@ruiec.cat> CVE-2025-39475 8.1 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 2 months, 2 weeks ago WordPress Arlo <= 6.0.3 - Local File Inclusion Vulnerability Path Traversal vulnerability in Frenify Arlo allows PHP Local File Inclusion. This issue affects Arlo: from n/a through 6.0.3. arlo =<6.0.3 pkgs.barlow Grotesk variable font superfamily nixos-unstable ??? nixpkgs-unstable 1.422 pkgs.clearlooks-phenix GTK3 port of the Clearlooks theme nixos-unstable ??? nixpkgs-unstable 7.1 pkgs.python312Packages.pyarlo Python library to work with Netgear Arlo cameras nixos-unstable ??? nixpkgs-unstable 0.2.4 pkgs.python313Packages.pyarlo Python library to work with Netgear Arlo cameras nixos-unstable ??? nixpkgs-unstable 0.2.4 pkgs.python312Packages.warlock Python object model built on JSON schema and JSON patch nixos-unstable ??? nixpkgs-unstable 2.0.1 pkgs.python313Packages.warlock Python object model built on JSON schema and JSON patch nixos-unstable ??? nixpkgs-unstable 2.0.1 pkgs.haskellPackages.barlow-lens lens via string literals nixos-unstable ??? nixpkgs-unstable 0.1.0.2 pkgs.rubyPackages.charlock_holmes nixos-unstable ??? nixpkgs-unstable 0.7.9 pkgs.python312Packages.solarlog-cli Python library to access the Solar-Log JSON interface nixos-unstable ??? nixpkgs-unstable 0.5.0 pkgs.python313Packages.solarlog-cli Python library to access the Solar-Log JSON interface nixos-unstable ??? nixpkgs-unstable 0.5.0 pkgs.rubyPackages_3_1.charlock_holmes nixos-unstable ??? nixpkgs-unstable 0.7.9 pkgs.rubyPackages_3_2.charlock_holmes nixos-unstable ??? nixpkgs-unstable 0.7.9 pkgs.rubyPackages_3_3.charlock_holmes nixos-unstable ??? nixpkgs-unstable 0.7.9 pkgs.rubyPackages_3_4.charlock_holmes nixos-unstable ??? nixpkgs-unstable 0.7.9 pkgs.python312Packages.zeversolarlocal Python module to interact with Zeversolar inverters nixos-unstable ??? nixpkgs-unstable 1.1.0 pkgs.python313Packages.zeversolarlocal Python module to interact with Zeversolar inverters nixos-unstable ??? nixpkgs-unstable 1.1.0 pkgs.home-assistant-component-tests.solarlog Open source home automation that puts local control and privacy first nixos-unstable ??? nixpkgs-unstable 2025.9.3 Package maintainers: 4 @fabaff Fabian Affolter <mail@fabian-affolter.ch> @prikhi Pavan Rikhi <pavan.rikhi@gmail.com> @dotlambda Robert Schütz <rschuetz17@gmail.com> @mweinelt Martin Weinelt <hexa@darmstadt.ccc.de> CVE-2025-32291 10.0 CRITICAL CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): CHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 2 months, 2 weeks ago WordPress SUMO Affiliates Pro <= 10.7.0 - Arbitrary File Upload Vulnerability Unrestricted Upload of File with Dangerous Type vulnerability in FantasticPlugins SUMO Affiliates Pro allows Using Malicious Files. This issue affects SUMO Affiliates Pro: from n/a through 10.7.0. affs =<10.7.0 pkgs.unyaffs Tool to extract files from a YAFFS2 file system image nixos-unstable ??? nixpkgs-unstable 0.9 pkgs.yaffshiv Simple YAFFS file system parser and extractor nixos-unstable ??? nixpkgs-unstable 0-unstable-2024-08-30 Package maintainers: 2 @KSJ2000 KSJ2000 <katsho123@outlook.com> @stigtsp Stig Palmquist <stig@stig.io> CVE-2025-39476 7.5 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 2 months, 2 weeks ago WordPress Revo theme <= 4.0.26 - Local File Inclusion Vulnerability Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in magentech Revo allows PHP Local File Inclusion. This issue affects Revo: from n/a through 4.0.26. revo =<4.0.26 pkgs.prevo Offline version of the Esperanto dictionary Reta Vortaro nixos-unstable ??? nixpkgs-unstable 0.2 pkgs.revolver Progress spinner for ZSH scripts nixos-unstable ??? nixpkgs-unstable 0.2.4-unstable-2020-09-30 pkgs.adminerevo Database management in a single PHP file nixos-unstable ??? nixpkgs-unstable 4.8.4 pkgs.prevo-data Data for offline version of the Esperanto dictionary Reta Vortaro nixos-unstable ??? nixpkgs-unstable 2020-03-08 pkgs.prevo-tools CLI tools for the offline version of the Esperanto dictionary Reta Vortaro nixos-unstable ??? nixpkgs-unstable 0.2 pkgs.trevorproxy Module to rotate the source IP address via SSH proxies and other methods nixos-unstable ??? nixpkgs-unstable 1.0.9 pkgs.trevorspray Modular password spraying tool nixos-unstable ??? nixpkgs-unstable 2.3.1 pkgs.revolt-desktop Open source user-first chat platform nixos-unstable ??? nixpkgs-unstable 1.0.8 pkgs.python312Packages.pyrevolve Python library to manage checkpointing for adjoints nixos-unstable ??? nixpkgs-unstable 2.2.6 pkgs.python312Packages.trevorproxy Module to rotate the source IP address via SSH proxies and other methods nixos-unstable ??? nixpkgs-unstable 1.0.9 pkgs.python313Packages.trevorproxy Module to rotate the source IP address via SSH proxies and other methods nixos-unstable ??? nixpkgs-unstable 1.0.9 pkgs.python312Packages.brevo-python Fully-featured Python API client to interact with Brevo nixos-unstable ??? nixpkgs-unstable 1.2.0 pkgs.python313Packages.brevo-python Fully-featured Python API client to interact with Brevo nixos-unstable ??? nixpkgs-unstable 1.2.0 Package maintainers: 7 @soyouzpanda soyouzpanda <soyouzpanda@soyouzpanda.fr> @fabaff Fabian Affolter <mail@fabian-affolter.ch> @AtilaSaraiva Átila Saraiva <atilasaraiva@gmail.com> @heyimnova Nova Witterick <git@heyimnova.dev> @magistau Mg. Tau <nix@alice-carroll.pet> @d-brasher D. Brasher @das-g Raphael Das Gupta <nixpkgs@raphael.dasgupta.ch> CVE-2025-5916 3.9 LOW CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): NONE Availability impact (A): LOW created 2 months, 2 weeks ago Libarchive: integer overflow while reading warc files at archive_read_support_format_warc.c A vulnerability has been identified in the libarchive library. This flaw involves an integer overflow that can be triggered when processing a Web Archive (WARC) file that claims to have more than INT64_MAX - 4 content bytes. An attacker could craft a malicious WARC archive to induce this overflow, potentially leading to unpredictable program behavior, memory corruption, or a denial-of-service condition within applications that process such archives using libarchive. rhcos libarchive <3.8.0 pkgs.libarchive Multi-format archive and compression library nixos-unstable ??? nixpkgs-unstable 3.8.1 pkgs.libarchive-qt Qt based archiving solution with libarchive backend nixos-unstable ??? nixpkgs-unstable 2.0.8 pkgs.haskellPackages.libarchive Haskell interface to libarchive nixos-unstable ??? nixpkgs-unstable 3.0.4.2 pkgs.kodiPackages.vfs-libarchive LibArchive Virtual Filesystem add-on for Kodi nixos-unstable ??? nixpkgs-unstable 20.1.0 pkgs.python312Packages.libarchive-c Python interface to libarchive nixos-unstable ??? nixpkgs-unstable 5.3 pkgs.python313Packages.libarchive-c Python interface to libarchive nixos-unstable ??? nixpkgs-unstable 5.3 pkgs.haskellPackages.archive-libarchive Common interface using libarchive nixos-unstable ??? nixpkgs-unstable 1.0.0.1 pkgs.haskellPackages.libarchive-conduit Read many archive formats with libarchive and conduit nixos-unstable ??? nixpkgs-unstable 0.1.0.0 pkgs.python312Packages.extractcode-libarchive ScanCode Toolkit plugin to provide pre-built binary libraries and utilities and their locations nixos-unstable ??? nixpkgs-unstable 21.5.31 pkgs.python313Packages.extractcode-libarchive ScanCode Toolkit plugin to provide pre-built binary libraries and utilities and their locations nixos-unstable ??? nixpkgs-unstable 21.5.31 Package maintainers: 8 @jcumming Jack Cummings <jack@mudshark.org> @aanderse Aaron Andersen <aaron@fosslib.net> @dschrempf Dominik Schrempf <dominik.schrempf@gmail.com> @edwtjo Edward Tjörnhammar <ed@cflags.cc> @minijackson Rémi Nicole <minijackson@riseup.net> @peterhoeg Peter Hoeg <peter@hoeg.com> @nvmd Sergey Kazenyuk <kazenyuk@pm.me> @cpages Carles Pagès <page@ruiec.cat> CVE-2025-5915 3.9 LOW CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): NONE Availability impact (A): LOW created 2 months, 2 weeks ago Libarchive: heap buffer over read in copy_from_lzss_window() at archive_read_support_format_rar.c A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer over-read due to the size of a filter block potentially exceeding the Lempel-Ziv-Storer-Schieber (LZSS) window. This means the library may attempt to read beyond the allocated memory buffer, which can result in unpredictable program behavior, crashes (denial of service), or the disclosure of sensitive information from adjacent memory regions. rhcos libarchive <3.8.0 pkgs.libarchive Multi-format archive and compression library nixos-unstable ??? nixpkgs-unstable 3.8.1 pkgs.libarchive-qt Qt based archiving solution with libarchive backend nixos-unstable ??? nixpkgs-unstable 2.0.8 pkgs.haskellPackages.libarchive Haskell interface to libarchive nixos-unstable ??? nixpkgs-unstable 3.0.4.2 pkgs.kodiPackages.vfs-libarchive LibArchive Virtual Filesystem add-on for Kodi nixos-unstable ??? nixpkgs-unstable 20.1.0 pkgs.python312Packages.libarchive-c Python interface to libarchive nixos-unstable ??? nixpkgs-unstable 5.3 pkgs.python313Packages.libarchive-c Python interface to libarchive nixos-unstable ??? nixpkgs-unstable 5.3 pkgs.haskellPackages.archive-libarchive Common interface using libarchive nixos-unstable ??? nixpkgs-unstable 1.0.0.1 pkgs.haskellPackages.libarchive-conduit Read many archive formats with libarchive and conduit nixos-unstable ??? nixpkgs-unstable 0.1.0.0 pkgs.python312Packages.extractcode-libarchive ScanCode Toolkit plugin to provide pre-built binary libraries and utilities and their locations nixos-unstable ??? nixpkgs-unstable 21.5.31 pkgs.python313Packages.extractcode-libarchive ScanCode Toolkit plugin to provide pre-built binary libraries and utilities and their locations nixos-unstable ??? nixpkgs-unstable 21.5.31 Package maintainers: 8 @jcumming Jack Cummings <jack@mudshark.org> @aanderse Aaron Andersen <aaron@fosslib.net> @dschrempf Dominik Schrempf <dominik.schrempf@gmail.com> @edwtjo Edward Tjörnhammar <ed@cflags.cc> @minijackson Rémi Nicole <minijackson@riseup.net> @peterhoeg Peter Hoeg <peter@hoeg.com> @nvmd Sergey Kazenyuk <kazenyuk@pm.me> @cpages Carles Pagès <page@ruiec.cat> CVE-2025-47711 4.3 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): LOW created 2 months, 2 weeks ago Nbdkit: nbdkit-server: off-by-one error when processing block status may lead to a denial of service There's a flaw in the nbdkit server when handling responses from its plugins regarding the status of data blocks. If a client makes a specific request for a very large data range, and a plugin responds with an even larger single block, the nbdkit server can encounter a critical internal error, leading to a denial-of-service. nbdkit <1.38.6 <1.42.3 <1.40.6 virt:av/nbdkit virt:8.2/nbdkit virt:rhel/nbdkit pkgs.nbdkit NBD server with stable plugin ABI and permissive license nixos-unstable ??? nixpkgs-unstable 1.44.1 Package maintainers: 1 @lukts30 lukts30 <llukas21307@gmail.com> CVE-2025-0620 6.6 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): HIGH User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 2 months, 2 weeks ago Samba: smbd doesn't pick up group membership changes when re-authenticating an expired smb session A flaw was found in Samba. The smbd service daemon does not pick up group membership changes when re-authenticating an expired SMB session. This issue can expose file shares until clients disconnect and then connect again. rhcos samba <4.21.6 samba4 pkgs.samba4 Standard Windows interoperability suite of programs for Linux and Unix nixos-unstable ??? nixpkgs-unstable 4.22.3 pkgs.sambamba SAM/BAM processing tool nixos-unstable ??? nixpkgs-unstable 1.0.1 pkgs.sambaFull Standard Windows interoperability suite of programs for Linux and Unix nixos-unstable ??? nixpkgs-unstable 4.22.3 pkgs.samba4Full Standard Windows interoperability suite of programs for Linux and Unix nixos-unstable ??? nixpkgs-unstable 4.22.3 Package maintainers: 2 @aneeshusa Aneesh Agrawal <aneeshusa@gmail.com> @jbedo Justin Bedő <cu@cua0.org>
CVE-2025-31638 7.1 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): CHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 2 months, 2 weeks ago WordPress Spare <= 1.7 - Cross Site Scripting (XSS) Vulnerability Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themeton Spare allows Reflected XSS. This issue affects Spare: from n/a through 1.7. spare =<1.7 pkgs.asciiquarium-transparent Aquarium/sea animation in ASCII art (with option of transparent background) nixos-unstable ??? nixpkgs-unstable 1.4 pkgs.materia-theme-transparent Transparent Material Design theme for GNOME/GTK based desktop environments nixos-unstable ??? nixpkgs-unstable 0-unstable-2021-03-22 pkgs.gnomeExtensions.transparent-top-bar Bring back the transparent top bar when free-floating in GNOME Shell 3.32. nixos-unstable ??? nixpkgs-unstable 24 pkgs.gnomeExtensions.transparent-window-moving Makes the window semi-transparent when moving or resizing nixos-unstable ??? nixpkgs-unstable 19 pkgs.sway-contrib.inactive-windows-transparency It makes inactive sway windows transparent nixos-unstable ??? nixpkgs-unstable 0-unstable-2024-03-19 pkgs.gnomeExtensions.transparent-top-bar-adjustable-transparency Fork of: https://github.com/zhanghai/gnome-shell-extension-transparent-top-bar nixos-unstable ??? nixpkgs-unstable 24 Package maintainers: 4 @quantenzitrone quantenzitrone <nix@dev.quantenzitrone.eu> @evils Evils <evils.devils@protonmail.com> @honnip Jung seungwoo <me@honnip.page> @CorbinWunderlich Corbin Wunderlich <corbin@wcopy.net>
pkgs.asciiquarium-transparent Aquarium/sea animation in ASCII art (with option of transparent background) nixos-unstable ??? nixpkgs-unstable 1.4
pkgs.materia-theme-transparent Transparent Material Design theme for GNOME/GTK based desktop environments nixos-unstable ??? nixpkgs-unstable 0-unstable-2021-03-22
pkgs.gnomeExtensions.transparent-top-bar Bring back the transparent top bar when free-floating in GNOME Shell 3.32. nixos-unstable ??? nixpkgs-unstable 24
pkgs.gnomeExtensions.transparent-window-moving Makes the window semi-transparent when moving or resizing nixos-unstable ??? nixpkgs-unstable 19
pkgs.sway-contrib.inactive-windows-transparency It makes inactive sway windows transparent nixos-unstable ??? nixpkgs-unstable 0-unstable-2024-03-19
pkgs.gnomeExtensions.transparent-top-bar-adjustable-transparency Fork of: https://github.com/zhanghai/gnome-shell-extension-transparent-top-bar nixos-unstable ??? nixpkgs-unstable 24
CVE-2025-28945 8.1 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 2 months, 2 weeks ago WordPress Valen - Sport, Fashion WooCommerce WordPress Theme <= 2.4 - Local File Inclusion Vulnerability Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in snstheme Valen - Sport, Fashion WooCommerce WordPress Theme allows PHP Local File Inclusion. This issue affects Valen - Sport, Fashion WooCommerce WordPress Theme: from n/a through 2.4. valen =<2.4 pkgs.valent Implementation of the KDE Connect protocol, built on GNOME platform libraries nixos-unstable ??? nixpkgs-unstable 1.0.0.alpha.46-unstable-2024-10-26 pkgs.valentina Open source sewing pattern drafting software nixos-unstable ??? nixpkgs-unstable 0.7.53 pkgs.gnomeExtensions.valent GNOME Shell integration for Valent nixos-unstable ??? nixpkgs-unstable 1.0.0.alpha.48 pkgs.sbclPackages.cl-prevalence nixos-unstable ??? nixpkgs-unstable 20250622-git pkgs.haskellPackages.equivalence Maintaining an equivalence relation implemented as union-find using STT nixos-unstable ??? nixpkgs-unstable 0.4.1 pkgs.vscode-extensions.valentjn.vscode-ltex nixos-unstable ??? nixpkgs-unstable 13.1.0 Package maintainers: 7 @0xbe7a Bela Stoyan <nix@be7a.de> @hraban Hraban Luyat <hraban@0brg.net> @Uthar Kasper Gałkowski <galkowskikasper@gmail.com> @7c6f434c Michael Raskin <7c6f434c@mail.ru> @nagy Daniel Nagy <danielnagy@posteo.de> @lukego Luke Gorrie <luke@snabb.co> @Aleksanaa Aleksana QwQ <me@aleksana.moe>
pkgs.valent Implementation of the KDE Connect protocol, built on GNOME platform libraries nixos-unstable ??? nixpkgs-unstable 1.0.0.alpha.46-unstable-2024-10-26
pkgs.valentina Open source sewing pattern drafting software nixos-unstable ??? nixpkgs-unstable 0.7.53
pkgs.gnomeExtensions.valent GNOME Shell integration for Valent nixos-unstable ??? nixpkgs-unstable 1.0.0.alpha.48
pkgs.haskellPackages.equivalence Maintaining an equivalence relation implemented as union-find using STT nixos-unstable ??? nixpkgs-unstable 0.4.1
CVE-2025-5918 3.9 LOW CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): NONE Availability impact (A): LOW created 2 months, 2 weeks ago Libarchive: reading past eof may be triggered for piped file streams A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for reading past the end of the file. This out-of-bounds read can lead to unintended consequences, including unpredictable program behavior, memory corruption, or a denial-of-service condition. rhcos libarchive <3.8.0 pkgs.libarchive Multi-format archive and compression library nixos-unstable ??? nixpkgs-unstable 3.8.1 pkgs.libarchive-qt Qt based archiving solution with libarchive backend nixos-unstable ??? nixpkgs-unstable 2.0.8 pkgs.haskellPackages.libarchive Haskell interface to libarchive nixos-unstable ??? nixpkgs-unstable 3.0.4.2 pkgs.kodiPackages.vfs-libarchive LibArchive Virtual Filesystem add-on for Kodi nixos-unstable ??? nixpkgs-unstable 20.1.0 pkgs.python312Packages.libarchive-c Python interface to libarchive nixos-unstable ??? nixpkgs-unstable 5.3 pkgs.python313Packages.libarchive-c Python interface to libarchive nixos-unstable ??? nixpkgs-unstable 5.3 pkgs.haskellPackages.archive-libarchive Common interface using libarchive nixos-unstable ??? nixpkgs-unstable 1.0.0.1 pkgs.haskellPackages.libarchive-conduit Read many archive formats with libarchive and conduit nixos-unstable ??? nixpkgs-unstable 0.1.0.0 pkgs.python312Packages.extractcode-libarchive ScanCode Toolkit plugin to provide pre-built binary libraries and utilities and their locations nixos-unstable ??? nixpkgs-unstable 21.5.31 pkgs.python313Packages.extractcode-libarchive ScanCode Toolkit plugin to provide pre-built binary libraries and utilities and their locations nixos-unstable ??? nixpkgs-unstable 21.5.31 Package maintainers: 8 @jcumming Jack Cummings <jack@mudshark.org> @aanderse Aaron Andersen <aaron@fosslib.net> @dschrempf Dominik Schrempf <dominik.schrempf@gmail.com> @edwtjo Edward Tjörnhammar <ed@cflags.cc> @minijackson Rémi Nicole <minijackson@riseup.net> @peterhoeg Peter Hoeg <peter@hoeg.com> @nvmd Sergey Kazenyuk <kazenyuk@pm.me> @cpages Carles Pagès <page@ruiec.cat>
pkgs.libarchive Multi-format archive and compression library nixos-unstable ??? nixpkgs-unstable 3.8.1
pkgs.libarchive-qt Qt based archiving solution with libarchive backend nixos-unstable ??? nixpkgs-unstable 2.0.8
pkgs.haskellPackages.libarchive Haskell interface to libarchive nixos-unstable ??? nixpkgs-unstable 3.0.4.2
pkgs.kodiPackages.vfs-libarchive LibArchive Virtual Filesystem add-on for Kodi nixos-unstable ??? nixpkgs-unstable 20.1.0
pkgs.python312Packages.libarchive-c Python interface to libarchive nixos-unstable ??? nixpkgs-unstable 5.3
pkgs.python313Packages.libarchive-c Python interface to libarchive nixos-unstable ??? nixpkgs-unstable 5.3
pkgs.haskellPackages.archive-libarchive Common interface using libarchive nixos-unstable ??? nixpkgs-unstable 1.0.0.1
pkgs.haskellPackages.libarchive-conduit Read many archive formats with libarchive and conduit nixos-unstable ??? nixpkgs-unstable 0.1.0.0
pkgs.python312Packages.extractcode-libarchive ScanCode Toolkit plugin to provide pre-built binary libraries and utilities and their locations nixos-unstable ??? nixpkgs-unstable 21.5.31
pkgs.python313Packages.extractcode-libarchive ScanCode Toolkit plugin to provide pre-built binary libraries and utilities and their locations nixos-unstable ??? nixpkgs-unstable 21.5.31
CVE-2025-39475 8.1 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 2 months, 2 weeks ago WordPress Arlo <= 6.0.3 - Local File Inclusion Vulnerability Path Traversal vulnerability in Frenify Arlo allows PHP Local File Inclusion. This issue affects Arlo: from n/a through 6.0.3. arlo =<6.0.3 pkgs.barlow Grotesk variable font superfamily nixos-unstable ??? nixpkgs-unstable 1.422 pkgs.clearlooks-phenix GTK3 port of the Clearlooks theme nixos-unstable ??? nixpkgs-unstable 7.1 pkgs.python312Packages.pyarlo Python library to work with Netgear Arlo cameras nixos-unstable ??? nixpkgs-unstable 0.2.4 pkgs.python313Packages.pyarlo Python library to work with Netgear Arlo cameras nixos-unstable ??? nixpkgs-unstable 0.2.4 pkgs.python312Packages.warlock Python object model built on JSON schema and JSON patch nixos-unstable ??? nixpkgs-unstable 2.0.1 pkgs.python313Packages.warlock Python object model built on JSON schema and JSON patch nixos-unstable ??? nixpkgs-unstable 2.0.1 pkgs.haskellPackages.barlow-lens lens via string literals nixos-unstable ??? nixpkgs-unstable 0.1.0.2 pkgs.rubyPackages.charlock_holmes nixos-unstable ??? nixpkgs-unstable 0.7.9 pkgs.python312Packages.solarlog-cli Python library to access the Solar-Log JSON interface nixos-unstable ??? nixpkgs-unstable 0.5.0 pkgs.python313Packages.solarlog-cli Python library to access the Solar-Log JSON interface nixos-unstable ??? nixpkgs-unstable 0.5.0 pkgs.rubyPackages_3_1.charlock_holmes nixos-unstable ??? nixpkgs-unstable 0.7.9 pkgs.rubyPackages_3_2.charlock_holmes nixos-unstable ??? nixpkgs-unstable 0.7.9 pkgs.rubyPackages_3_3.charlock_holmes nixos-unstable ??? nixpkgs-unstable 0.7.9 pkgs.rubyPackages_3_4.charlock_holmes nixos-unstable ??? nixpkgs-unstable 0.7.9 pkgs.python312Packages.zeversolarlocal Python module to interact with Zeversolar inverters nixos-unstable ??? nixpkgs-unstable 1.1.0 pkgs.python313Packages.zeversolarlocal Python module to interact with Zeversolar inverters nixos-unstable ??? nixpkgs-unstable 1.1.0 pkgs.home-assistant-component-tests.solarlog Open source home automation that puts local control and privacy first nixos-unstable ??? nixpkgs-unstable 2025.9.3 Package maintainers: 4 @fabaff Fabian Affolter <mail@fabian-affolter.ch> @prikhi Pavan Rikhi <pavan.rikhi@gmail.com> @dotlambda Robert Schütz <rschuetz17@gmail.com> @mweinelt Martin Weinelt <hexa@darmstadt.ccc.de>
pkgs.python312Packages.pyarlo Python library to work with Netgear Arlo cameras nixos-unstable ??? nixpkgs-unstable 0.2.4
pkgs.python313Packages.pyarlo Python library to work with Netgear Arlo cameras nixos-unstable ??? nixpkgs-unstable 0.2.4
pkgs.python312Packages.warlock Python object model built on JSON schema and JSON patch nixos-unstable ??? nixpkgs-unstable 2.0.1
pkgs.python313Packages.warlock Python object model built on JSON schema and JSON patch nixos-unstable ??? nixpkgs-unstable 2.0.1
pkgs.haskellPackages.barlow-lens lens via string literals nixos-unstable ??? nixpkgs-unstable 0.1.0.2
pkgs.python312Packages.solarlog-cli Python library to access the Solar-Log JSON interface nixos-unstable ??? nixpkgs-unstable 0.5.0
pkgs.python313Packages.solarlog-cli Python library to access the Solar-Log JSON interface nixos-unstable ??? nixpkgs-unstable 0.5.0
pkgs.python312Packages.zeversolarlocal Python module to interact with Zeversolar inverters nixos-unstable ??? nixpkgs-unstable 1.1.0
pkgs.python313Packages.zeversolarlocal Python module to interact with Zeversolar inverters nixos-unstable ??? nixpkgs-unstable 1.1.0
pkgs.home-assistant-component-tests.solarlog Open source home automation that puts local control and privacy first nixos-unstable ??? nixpkgs-unstable 2025.9.3
CVE-2025-32291 10.0 CRITICAL CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): CHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 2 months, 2 weeks ago WordPress SUMO Affiliates Pro <= 10.7.0 - Arbitrary File Upload Vulnerability Unrestricted Upload of File with Dangerous Type vulnerability in FantasticPlugins SUMO Affiliates Pro allows Using Malicious Files. This issue affects SUMO Affiliates Pro: from n/a through 10.7.0. affs =<10.7.0 pkgs.unyaffs Tool to extract files from a YAFFS2 file system image nixos-unstable ??? nixpkgs-unstable 0.9 pkgs.yaffshiv Simple YAFFS file system parser and extractor nixos-unstable ??? nixpkgs-unstable 0-unstable-2024-08-30 Package maintainers: 2 @KSJ2000 KSJ2000 <katsho123@outlook.com> @stigtsp Stig Palmquist <stig@stig.io>
pkgs.unyaffs Tool to extract files from a YAFFS2 file system image nixos-unstable ??? nixpkgs-unstable 0.9
pkgs.yaffshiv Simple YAFFS file system parser and extractor nixos-unstable ??? nixpkgs-unstable 0-unstable-2024-08-30
CVE-2025-39476 7.5 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 2 months, 2 weeks ago WordPress Revo theme <= 4.0.26 - Local File Inclusion Vulnerability Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in magentech Revo allows PHP Local File Inclusion. This issue affects Revo: from n/a through 4.0.26. revo =<4.0.26 pkgs.prevo Offline version of the Esperanto dictionary Reta Vortaro nixos-unstable ??? nixpkgs-unstable 0.2 pkgs.revolver Progress spinner for ZSH scripts nixos-unstable ??? nixpkgs-unstable 0.2.4-unstable-2020-09-30 pkgs.adminerevo Database management in a single PHP file nixos-unstable ??? nixpkgs-unstable 4.8.4 pkgs.prevo-data Data for offline version of the Esperanto dictionary Reta Vortaro nixos-unstable ??? nixpkgs-unstable 2020-03-08 pkgs.prevo-tools CLI tools for the offline version of the Esperanto dictionary Reta Vortaro nixos-unstable ??? nixpkgs-unstable 0.2 pkgs.trevorproxy Module to rotate the source IP address via SSH proxies and other methods nixos-unstable ??? nixpkgs-unstable 1.0.9 pkgs.trevorspray Modular password spraying tool nixos-unstable ??? nixpkgs-unstable 2.3.1 pkgs.revolt-desktop Open source user-first chat platform nixos-unstable ??? nixpkgs-unstable 1.0.8 pkgs.python312Packages.pyrevolve Python library to manage checkpointing for adjoints nixos-unstable ??? nixpkgs-unstable 2.2.6 pkgs.python312Packages.trevorproxy Module to rotate the source IP address via SSH proxies and other methods nixos-unstable ??? nixpkgs-unstable 1.0.9 pkgs.python313Packages.trevorproxy Module to rotate the source IP address via SSH proxies and other methods nixos-unstable ??? nixpkgs-unstable 1.0.9 pkgs.python312Packages.brevo-python Fully-featured Python API client to interact with Brevo nixos-unstable ??? nixpkgs-unstable 1.2.0 pkgs.python313Packages.brevo-python Fully-featured Python API client to interact with Brevo nixos-unstable ??? nixpkgs-unstable 1.2.0 Package maintainers: 7 @soyouzpanda soyouzpanda <soyouzpanda@soyouzpanda.fr> @fabaff Fabian Affolter <mail@fabian-affolter.ch> @AtilaSaraiva Átila Saraiva <atilasaraiva@gmail.com> @heyimnova Nova Witterick <git@heyimnova.dev> @magistau Mg. Tau <nix@alice-carroll.pet> @d-brasher D. Brasher @das-g Raphael Das Gupta <nixpkgs@raphael.dasgupta.ch>
pkgs.prevo Offline version of the Esperanto dictionary Reta Vortaro nixos-unstable ??? nixpkgs-unstable 0.2
pkgs.revolver Progress spinner for ZSH scripts nixos-unstable ??? nixpkgs-unstable 0.2.4-unstable-2020-09-30
pkgs.prevo-data Data for offline version of the Esperanto dictionary Reta Vortaro nixos-unstable ??? nixpkgs-unstable 2020-03-08
pkgs.prevo-tools CLI tools for the offline version of the Esperanto dictionary Reta Vortaro nixos-unstable ??? nixpkgs-unstable 0.2
pkgs.trevorproxy Module to rotate the source IP address via SSH proxies and other methods nixos-unstable ??? nixpkgs-unstable 1.0.9
pkgs.python312Packages.pyrevolve Python library to manage checkpointing for adjoints nixos-unstable ??? nixpkgs-unstable 2.2.6
pkgs.python312Packages.trevorproxy Module to rotate the source IP address via SSH proxies and other methods nixos-unstable ??? nixpkgs-unstable 1.0.9
pkgs.python313Packages.trevorproxy Module to rotate the source IP address via SSH proxies and other methods nixos-unstable ??? nixpkgs-unstable 1.0.9
pkgs.python312Packages.brevo-python Fully-featured Python API client to interact with Brevo nixos-unstable ??? nixpkgs-unstable 1.2.0
pkgs.python313Packages.brevo-python Fully-featured Python API client to interact with Brevo nixos-unstable ??? nixpkgs-unstable 1.2.0
CVE-2025-5916 3.9 LOW CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): NONE Availability impact (A): LOW created 2 months, 2 weeks ago Libarchive: integer overflow while reading warc files at archive_read_support_format_warc.c A vulnerability has been identified in the libarchive library. This flaw involves an integer overflow that can be triggered when processing a Web Archive (WARC) file that claims to have more than INT64_MAX - 4 content bytes. An attacker could craft a malicious WARC archive to induce this overflow, potentially leading to unpredictable program behavior, memory corruption, or a denial-of-service condition within applications that process such archives using libarchive. rhcos libarchive <3.8.0 pkgs.libarchive Multi-format archive and compression library nixos-unstable ??? nixpkgs-unstable 3.8.1 pkgs.libarchive-qt Qt based archiving solution with libarchive backend nixos-unstable ??? nixpkgs-unstable 2.0.8 pkgs.haskellPackages.libarchive Haskell interface to libarchive nixos-unstable ??? nixpkgs-unstable 3.0.4.2 pkgs.kodiPackages.vfs-libarchive LibArchive Virtual Filesystem add-on for Kodi nixos-unstable ??? nixpkgs-unstable 20.1.0 pkgs.python312Packages.libarchive-c Python interface to libarchive nixos-unstable ??? nixpkgs-unstable 5.3 pkgs.python313Packages.libarchive-c Python interface to libarchive nixos-unstable ??? nixpkgs-unstable 5.3 pkgs.haskellPackages.archive-libarchive Common interface using libarchive nixos-unstable ??? nixpkgs-unstable 1.0.0.1 pkgs.haskellPackages.libarchive-conduit Read many archive formats with libarchive and conduit nixos-unstable ??? nixpkgs-unstable 0.1.0.0 pkgs.python312Packages.extractcode-libarchive ScanCode Toolkit plugin to provide pre-built binary libraries and utilities and their locations nixos-unstable ??? nixpkgs-unstable 21.5.31 pkgs.python313Packages.extractcode-libarchive ScanCode Toolkit plugin to provide pre-built binary libraries and utilities and their locations nixos-unstable ??? nixpkgs-unstable 21.5.31 Package maintainers: 8 @jcumming Jack Cummings <jack@mudshark.org> @aanderse Aaron Andersen <aaron@fosslib.net> @dschrempf Dominik Schrempf <dominik.schrempf@gmail.com> @edwtjo Edward Tjörnhammar <ed@cflags.cc> @minijackson Rémi Nicole <minijackson@riseup.net> @peterhoeg Peter Hoeg <peter@hoeg.com> @nvmd Sergey Kazenyuk <kazenyuk@pm.me> @cpages Carles Pagès <page@ruiec.cat>
pkgs.libarchive Multi-format archive and compression library nixos-unstable ??? nixpkgs-unstable 3.8.1
pkgs.libarchive-qt Qt based archiving solution with libarchive backend nixos-unstable ??? nixpkgs-unstable 2.0.8
pkgs.haskellPackages.libarchive Haskell interface to libarchive nixos-unstable ??? nixpkgs-unstable 3.0.4.2
pkgs.kodiPackages.vfs-libarchive LibArchive Virtual Filesystem add-on for Kodi nixos-unstable ??? nixpkgs-unstable 20.1.0
pkgs.python312Packages.libarchive-c Python interface to libarchive nixos-unstable ??? nixpkgs-unstable 5.3
pkgs.python313Packages.libarchive-c Python interface to libarchive nixos-unstable ??? nixpkgs-unstable 5.3
pkgs.haskellPackages.archive-libarchive Common interface using libarchive nixos-unstable ??? nixpkgs-unstable 1.0.0.1
pkgs.haskellPackages.libarchive-conduit Read many archive formats with libarchive and conduit nixos-unstable ??? nixpkgs-unstable 0.1.0.0
pkgs.python312Packages.extractcode-libarchive ScanCode Toolkit plugin to provide pre-built binary libraries and utilities and their locations nixos-unstable ??? nixpkgs-unstable 21.5.31
pkgs.python313Packages.extractcode-libarchive ScanCode Toolkit plugin to provide pre-built binary libraries and utilities and their locations nixos-unstable ??? nixpkgs-unstable 21.5.31
CVE-2025-5915 3.9 LOW CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): NONE Availability impact (A): LOW created 2 months, 2 weeks ago Libarchive: heap buffer over read in copy_from_lzss_window() at archive_read_support_format_rar.c A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer over-read due to the size of a filter block potentially exceeding the Lempel-Ziv-Storer-Schieber (LZSS) window. This means the library may attempt to read beyond the allocated memory buffer, which can result in unpredictable program behavior, crashes (denial of service), or the disclosure of sensitive information from adjacent memory regions. rhcos libarchive <3.8.0 pkgs.libarchive Multi-format archive and compression library nixos-unstable ??? nixpkgs-unstable 3.8.1 pkgs.libarchive-qt Qt based archiving solution with libarchive backend nixos-unstable ??? nixpkgs-unstable 2.0.8 pkgs.haskellPackages.libarchive Haskell interface to libarchive nixos-unstable ??? nixpkgs-unstable 3.0.4.2 pkgs.kodiPackages.vfs-libarchive LibArchive Virtual Filesystem add-on for Kodi nixos-unstable ??? nixpkgs-unstable 20.1.0 pkgs.python312Packages.libarchive-c Python interface to libarchive nixos-unstable ??? nixpkgs-unstable 5.3 pkgs.python313Packages.libarchive-c Python interface to libarchive nixos-unstable ??? nixpkgs-unstable 5.3 pkgs.haskellPackages.archive-libarchive Common interface using libarchive nixos-unstable ??? nixpkgs-unstable 1.0.0.1 pkgs.haskellPackages.libarchive-conduit Read many archive formats with libarchive and conduit nixos-unstable ??? nixpkgs-unstable 0.1.0.0 pkgs.python312Packages.extractcode-libarchive ScanCode Toolkit plugin to provide pre-built binary libraries and utilities and their locations nixos-unstable ??? nixpkgs-unstable 21.5.31 pkgs.python313Packages.extractcode-libarchive ScanCode Toolkit plugin to provide pre-built binary libraries and utilities and their locations nixos-unstable ??? nixpkgs-unstable 21.5.31 Package maintainers: 8 @jcumming Jack Cummings <jack@mudshark.org> @aanderse Aaron Andersen <aaron@fosslib.net> @dschrempf Dominik Schrempf <dominik.schrempf@gmail.com> @edwtjo Edward Tjörnhammar <ed@cflags.cc> @minijackson Rémi Nicole <minijackson@riseup.net> @peterhoeg Peter Hoeg <peter@hoeg.com> @nvmd Sergey Kazenyuk <kazenyuk@pm.me> @cpages Carles Pagès <page@ruiec.cat>
pkgs.libarchive Multi-format archive and compression library nixos-unstable ??? nixpkgs-unstable 3.8.1
pkgs.libarchive-qt Qt based archiving solution with libarchive backend nixos-unstable ??? nixpkgs-unstable 2.0.8
pkgs.haskellPackages.libarchive Haskell interface to libarchive nixos-unstable ??? nixpkgs-unstable 3.0.4.2
pkgs.kodiPackages.vfs-libarchive LibArchive Virtual Filesystem add-on for Kodi nixos-unstable ??? nixpkgs-unstable 20.1.0
pkgs.python312Packages.libarchive-c Python interface to libarchive nixos-unstable ??? nixpkgs-unstable 5.3
pkgs.python313Packages.libarchive-c Python interface to libarchive nixos-unstable ??? nixpkgs-unstable 5.3
pkgs.haskellPackages.archive-libarchive Common interface using libarchive nixos-unstable ??? nixpkgs-unstable 1.0.0.1
pkgs.haskellPackages.libarchive-conduit Read many archive formats with libarchive and conduit nixos-unstable ??? nixpkgs-unstable 0.1.0.0
pkgs.python312Packages.extractcode-libarchive ScanCode Toolkit plugin to provide pre-built binary libraries and utilities and their locations nixos-unstable ??? nixpkgs-unstable 21.5.31
pkgs.python313Packages.extractcode-libarchive ScanCode Toolkit plugin to provide pre-built binary libraries and utilities and their locations nixos-unstable ??? nixpkgs-unstable 21.5.31
CVE-2025-47711 4.3 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): LOW created 2 months, 2 weeks ago Nbdkit: nbdkit-server: off-by-one error when processing block status may lead to a denial of service There's a flaw in the nbdkit server when handling responses from its plugins regarding the status of data blocks. If a client makes a specific request for a very large data range, and a plugin responds with an even larger single block, the nbdkit server can encounter a critical internal error, leading to a denial-of-service. nbdkit <1.38.6 <1.42.3 <1.40.6 virt:av/nbdkit virt:8.2/nbdkit virt:rhel/nbdkit pkgs.nbdkit NBD server with stable plugin ABI and permissive license nixos-unstable ??? nixpkgs-unstable 1.44.1 Package maintainers: 1 @lukts30 lukts30 <llukas21307@gmail.com>
pkgs.nbdkit NBD server with stable plugin ABI and permissive license nixos-unstable ??? nixpkgs-unstable 1.44.1
CVE-2025-0620 6.6 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): HIGH User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 2 months, 2 weeks ago Samba: smbd doesn't pick up group membership changes when re-authenticating an expired smb session A flaw was found in Samba. The smbd service daemon does not pick up group membership changes when re-authenticating an expired SMB session. This issue can expose file shares until clients disconnect and then connect again. rhcos samba <4.21.6 samba4 pkgs.samba4 Standard Windows interoperability suite of programs for Linux and Unix nixos-unstable ??? nixpkgs-unstable 4.22.3 pkgs.sambamba SAM/BAM processing tool nixos-unstable ??? nixpkgs-unstable 1.0.1 pkgs.sambaFull Standard Windows interoperability suite of programs for Linux and Unix nixos-unstable ??? nixpkgs-unstable 4.22.3 pkgs.samba4Full Standard Windows interoperability suite of programs for Linux and Unix nixos-unstable ??? nixpkgs-unstable 4.22.3 Package maintainers: 2 @aneeshusa Aneesh Agrawal <aneeshusa@gmail.com> @jbedo Justin Bedő <cu@cua0.org>
pkgs.samba4 Standard Windows interoperability suite of programs for Linux and Unix nixos-unstable ??? nixpkgs-unstable 4.22.3
pkgs.sambaFull Standard Windows interoperability suite of programs for Linux and Unix nixos-unstable ??? nixpkgs-unstable 4.22.3
pkgs.samba4Full Standard Windows interoperability suite of programs for Linux and Unix nixos-unstable ??? nixpkgs-unstable 4.22.3