Dismissed suggestions Untriaged suggestions Draft issues Published issues Automatically generated suggestions Create Draft to queue a suggestion for refinement. Dismiss to remove a suggestion from the queue. CVE-2023-3758 7.1 HIGH CVSS version: 3.1 Attack vector (AV): ADJACENT_NETWORK Attack complexity (AC): HIGH Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 2 months ago Sssd: race condition during authorization leads to gpo policies functioning inconsistently A race condition flaw was found in sssd where the GPO policy is not consistently applied for authenticated users. This may lead to improper authorization issues, granting or denying access to resources inappropriately. sssd <2.9.5 * pkgs.sssd System Security Services Daemon nixos-24.05 2.9.4 nixpkgs-24.05-darwin 2.9.4 nixos-24.05-small 2.9.4 nixos-24.11 2.9.5 nixpkgs-24.11-darwin 2.9.5 nixos-24.11-small 2.9.5 nixos-unstable 2.9.5 nixos-unstable-small 2.9.5 nixpkgs-unstable 2.9.5 Notify package maintainers: 1 @illustris Harikrishnan R <me@illustris.tech> CVE-2022-2084 5.5 MEDIUM CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): NONE Availability impact (A): NONE created 2 months ago sensitive data exposure in cloud-init logs Sensitive data could be exposed in world readable logs of cloud-init before version 22.3 when schema failures are reported. This leak could include hashed passwords. cloud-init <23.0 pkgs.cloud-init Provides configuration and customization of cloud instance nixos-24.05 24.1 nixpkgs-24.05-darwin 24.1 nixos-24.05-small 24.1 nixos-24.11 24.2 nixpkgs-24.11-darwin 24.2 nixos-24.11-small 24.2 nixos-unstable 24.2 nixos-unstable-small 24.2 nixpkgs-unstable 24.2 Notify package maintainers: 2 @jfroche Jean-François Roche <jfroche@pyxel.be> @illustris Harikrishnan R <me@illustris.tech> CVE-2023-30797 7.5 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): NONE Availability impact (A): NONE created 2 months ago Insecure Random Generation in Netflix Lemur Netflix Lemur before version 1.3.2 used insufficiently random values when generating default credentials. The insufficiently random values may allow an attacker to guess the credentials and gain access to resources managed by Lemur. lemur <<1.3.2 pkgs.lemurs Customizable TUI display/login manager written in Rust nixos-24.05 0.3.2 nixpkgs-24.05-darwin 0.3.2 nixos-24.05-small 0.3.2 nixos-24.11 0.3.2 nixpkgs-24.11-darwin 0.3.2 nixos-24.11-small 0.3.2 nixos-unstable 0.3.2 nixos-unstable-small 0.3.2 nixpkgs-unstable 0.3.2 Notify package maintainers: 1 @JeremiahSecrist Jeremiah Secrist <jeremiah@secrist.xyz> CVE-2021-3429 5.5 MEDIUM CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): NONE Availability impact (A): NONE created 2 months ago sensitive data exposure in cloud-init logs When instructing cloud-init to set a random password for a new user account, versions before 21.2 would write that password to the world-readable log file /var/log/cloud-init-output.log. This could allow a local user to log in as another user. cloud-init <21.2 pkgs.cloud-init Provides configuration and customization of cloud instance nixos-24.05 24.1 nixpkgs-24.05-darwin 24.1 nixos-24.05-small 24.1 nixos-24.11 24.2 nixpkgs-24.11-darwin 24.2 nixos-24.11-small 24.2 nixos-unstable 24.2 nixos-unstable-small 24.2 nixpkgs-unstable 24.2 Notify package maintainers: 2 @jfroche Jean-François Roche <jfroche@pyxel.be> @illustris Harikrishnan R <me@illustris.tech> CVE-2023-30798 7.5 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): HIGH created 2 months ago MultipartParser DOS with too many fields or files in Starlette Framework There MultipartParser usage in Encode's Starlette python framework before versions 0.25.0 allows an unauthenticated and remote attacker to specify any number of form fields or files which can cause excessive memory usage resulting in denial of service of the HTTP service. starlette <0.25.0 pkgs.python311Packages.starlette The little ASGI framework that shines nixos-24.05 0.37.2 nixpkgs-24.05-darwin 0.37.2 nixos-24.05-small 0.37.2 nixos-24.11 0.40.0 nixpkgs-24.11-darwin 0.40.0 nixos-24.11-small 0.40.0 nixos-unstable 0.40.0 nixos-unstable-small 0.40.0 nixpkgs-unstable 0.40.0 pkgs.python312Packages.starlette Little ASGI framework that shines nixos-24.05 0.37.2 nixpkgs-24.05-darwin 0.37.2 nixos-24.05-small 0.37.2 nixos-24.11 0.40.0 nixpkgs-24.11-darwin 0.40.0 nixos-24.11-small 0.40.0 nixos-unstable 0.40.0 nixos-unstable-small 0.40.0 nixpkgs-unstable 0.40.0 pkgs.python311Packages.sse-starlette Server Sent Events for Starlette and FastAPI nixos-24.05 2.1.0 nixpkgs-24.05-darwin 2.1.0 nixos-24.05-small 2.1.0 nixos-24.11 2.1.3 nixpkgs-24.11-darwin 2.1.3 nixos-24.11-small 2.1.3 nixos-unstable 2.1.3 nixos-unstable-small 2.1.3 nixpkgs-unstable 2.1.3 pkgs.python311Packages.starlette-wtf A simple tool for integrating Starlette and WTForms nixos-24.05 0.4.5 nixpkgs-24.05-darwin 0.4.5 nixos-24.05-small 0.4.5 nixos-24.11 0.4.5 nixpkgs-24.11-darwin 0.4.5 nixos-24.11-small 0.4.5 nixos-unstable 0.4.5 nixos-unstable-small 0.4.5 nixpkgs-unstable 0.4.5 pkgs.python312Packages.sse-starlette Server Sent Events for Starlette and FastAPI nixos-24.05 2.1.0 nixpkgs-24.05-darwin 2.1.0 nixos-24.05-small 2.1.0 nixos-24.11 2.1.3 nixpkgs-24.11-darwin 2.1.3 nixos-24.11-small 2.1.3 nixos-unstable 2.1.3 nixos-unstable-small 2.1.3 nixpkgs-unstable 2.1.3 pkgs.python312Packages.starlette-wtf Simple tool for integrating Starlette and WTForms nixos-24.05 0.4.5 nixpkgs-24.05-darwin 0.4.5 nixos-24.05-small 0.4.5 nixos-24.11 0.4.5 nixpkgs-24.11-darwin 0.4.5 nixos-24.11-small 0.4.5 nixos-unstable 0.4.5 nixos-unstable-small 0.4.5 nixpkgs-unstable 0.4.5 pkgs.python311Packages.starlette-admin Fast, beautiful and extensible administrative interface framework for Starlette & FastApi applications nixos-24.11 0.14.1 nixpkgs-24.11-darwin 0.14.1 nixos-24.11-small 0.14.1 nixos-unstable 0.14.1 nixos-unstable-small 0.14.1 nixpkgs-unstable 0.14.1 pkgs.python312Packages.starlette-admin Fast, beautiful and extensible administrative interface framework for Starlette & FastApi applications nixos-24.11 0.14.1 nixpkgs-24.11-darwin 0.14.1 nixos-24.11-small 0.14.1 nixos-unstable 0.14.1 nixos-unstable-small 0.14.1 nixpkgs-unstable 0.14.1 pkgs.python311Packages.starlette-context Middleware for Starlette that allows you to store and access the context data of a request nixos-24.05 0.3.6 nixpkgs-24.05-darwin 0.3.6 nixos-24.05-small 0.3.6 nixos-24.11 0.3.6 nixpkgs-24.11-darwin 0.3.6 nixos-24.11-small 0.3.6 nixos-unstable 0.3.6 nixos-unstable-small 0.3.6 nixpkgs-unstable 0.3.6 pkgs.python312Packages.starlette-context Middleware for Starlette that allows you to store and access the context data of a request nixos-24.05 0.3.6 nixpkgs-24.05-darwin 0.3.6 nixos-24.05-small 0.3.6 nixos-24.11 0.3.6 nixpkgs-24.11-darwin 0.3.6 nixos-24.11-small 0.3.6 nixos-unstable 0.3.6 nixos-unstable-small 0.3.6 nixpkgs-unstable 0.3.6 Notify package maintainers: 7 @wd15 Daniel Wheeler <daniel.wheeler2@gmail.com> @fabaff Fabian Affolter <mail@fabian-affolter.ch> @yu-re-ka Yureka <yuka@yuka.dev> @vidister Fiona Weber <v@vidister.de> @n0emis Ember Keske <nixpkgs@n0emis.network> @johannwagner Johann Wagner <nix@wagner.digital> @pbsds Peder Bergebakken Sundt <pbsds@hotmail.com> CVE-2025-24684 7.1 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): CHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 2 months ago WordPress Media Downloader Plugin <= 0.4.7.5 - Reflected Cross Site Scripting (XSS) vulnerability Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ederson Peka Media Downloader allows Reflected XSS. This issue affects Media Downloader: from n/a through 0.4.7.5. media-downloader =<0.4.7.5 pkgs.media-downloader A Qt/C++ GUI front end for yt-dlp and others nixos-24.05 4.6.0 nixpkgs-24.05-darwin 4.6.0 nixos-24.05-small 4.6.0 nixos-24.11 5.2.0 nixpkgs-24.11-darwin 5.2.0 nixos-24.11-small 5.2.0 nixos-unstable 5.2.0 nixos-unstable-small 5.2.0 nixpkgs-unstable 5.2.0 Notify package maintainers: 1 @zendo zendo <linzway@qq.com> CVE-2025-22703 7.1 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): CHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 2 months ago WordPress Forge – Front-End Page Builder plugin <= 1.4.6 - CSRF to Stored Cross Site Scripting (XSS) vulnerability Cross-Site Request Forgery (CSRF) vulnerability in manuelvicedo Forge – Front-End Page Builder allows Stored XSS. This issue affects Forge – Front-End Page Builder: from n/a through 1.4.6. forge =<1.4.6 pkgs.forge OpenGL interop library that can be used with ArrayFire or any other application using CUDA or OpenCL compute backend nixos-24.05 1.0.8 nixpkgs-24.05-darwin 1.0.8 nixos-24.05-small 1.0.8 nixos-24.11 1.0.8 nixpkgs-24.11-darwin 1.0.8 nixos-24.11-small 1.0.8 nixos-unstable 1.0.8 nixos-unstable-small 1.0.8 nixpkgs-unstable 1.0.8 pkgs.forgejo Self-hosted lightweight software forge nixos-24.05 7.0.11 nixpkgs-24.05-darwin 7.0.11 nixos-24.05-small 7.0.11 nixos-24.11 9.0.2 nixpkgs-24.11-darwin 9.0.2 nixos-24.11-small 9.0.2 nixos-unstable 9.0.2 nixos-unstable-small 9.0.2 nixpkgs-unstable 9.0.2 pkgs.forge-mtg Magic: the Gathering card game with rules enforcement nixos-24.05 1.6.57 nixpkgs-24.05-darwin 1.6.57 nixos-24.05-small 1.6.57 nixos-24.11 1.6.65 nixpkgs-24.11-darwin 1.6.65 nixos-24.11-small 1.6.65 nixos-unstable 1.6.65 nixos-unstable-small 1.6.65 nixpkgs-unstable 1.6.65 pkgs.mindforger Thinking Notebook & Markdown IDE nixos-24.05 1.52.0 nixpkgs-24.05-darwin 1.52.0 nixos-24.05-small 1.52.0 nixos-24.11 1.52.0 nixpkgs-24.11-darwin 1.52.0 nixos-24.11-small 1.52.0 nixos-unstable 1.52.0 nixos-unstable-small 1.52.0 nixpkgs-unstable 1.52.0 pkgs.forgejo-cli CLI application for interacting with Forgejo nixos-24.11 0.1.1 nixpkgs-24.11-darwin 0.1.1 nixos-24.11-small 0.1.1 nixos-unstable 0.1.1 nixos-unstable-small 0.1.1 nixpkgs-unstable 0.1.1 pkgs.forgejo-lts Self-hosted lightweight software forge nixos-24.11 7.0.11 nixpkgs-24.11-darwin 7.0.11 nixos-24.11-small 7.0.11 nixos-unstable 7.0.11 nixos-unstable-small 7.0.11 nixpkgs-unstable 7.0.11 pkgs.mcdreforged Rewritten version of MCDaemon, a python tool to control your Minecraft server nixos-24.11 2.13.2 nixpkgs-24.11-darwin 2.13.2 nixos-24.11-small 2.13.2 nixos-unstable 2.13.2 nixos-unstable-small 2.13.2 nixpkgs-unstable 2.13.2 pkgs.forge-sparks Get Git forges notifications nixos-24.05 0.3.0 nixpkgs-24.05-darwin 0.3.0 nixos-24.05-small 0.3.0 nixos-24.11 0.4.0 nixpkgs-24.11-darwin 0.4.0 nixos-24.11-small 0.4.0 nixos-unstable 0.4.0 nixos-unstable-small 0.4.0 nixpkgs-unstable 0.4.0 pkgs.fontforge-gtk Font editor nixos-24.05 20230101 nixpkgs-24.05-darwin 20230101 nixos-24.05-small 20230101 nixos-24.11 20230101 nixpkgs-24.11-darwin 20230101 nixos-24.11-small 20230101 nixos-unstable 20230101 nixos-unstable-small 20230101 nixpkgs-unstable 20230101 pkgs.forgejo-runner Runner for Forgejo based on act nixos-24.05 3.5.1 nixpkgs-24.05-darwin 3.5.1 nixos-24.05-small 3.5.1 nixos-24.11 4.0.1 nixpkgs-24.11-darwin 4.0.1 nixos-24.11-small 4.0.1 nixos-unstable 5.0.3 nixos-unstable-small 5.0.3 nixpkgs-unstable 5.0.3 pkgs.emacsPackages.forge nixos-24.05 20240423.2033 nixpkgs-24.05-darwin 20240423.2033 nixos-24.05-small 20240423.2033 nixos-24.11 20241014.1340 nixpkgs-24.11-darwin 20241014.1340 nixos-24.11-small 20241014.1340 nixos-unstable 20241014.1340 nixos-unstable-small 20241014.1340 nixpkgs-unstable 20241014.1340 pkgs.fontforge-fonttools Font editor nixos-24.05 20230101 nixpkgs-24.05-darwin 20230101 nixos-24.05-small 20230101 nixos-24.11 20230101 nixpkgs-24.11-darwin 20230101 nixos-24.11-small 20230101 nixos-unstable 20230101 nixos-unstable-small 20230101 nixpkgs-unstable 20230101 pkgs.gnomeExtensions.forge Tiling and window manager for GNOME nixos-24.05 78 nixpkgs-24.05-darwin 78 nixos-24.05-small 78 nixos-24.11 84 nixpkgs-24.11-darwin 84 nixos-24.11-small 84 nixos-unstable 84 nixos-unstable-small 84 nixpkgs-unstable 84 pkgs.emacsPackages.orgit-forge nixos-24.05 20240415.1546 nixpkgs-24.05-darwin 20240415.1546 nixos-24.05-small 20240415.1546 nixos-24.11 20240808.1947 nixpkgs-24.11-darwin 20240808.1947 nixos-24.11-small 20240808.1947 nixos-unstable 20240808.1947 nixos-unstable-small 20240808.1947 nixpkgs-unstable 20240808.1947 pkgs.python311Packages.fontforge Font editor nixos-24.05 20230101 nixpkgs-24.05-darwin 20230101 nixos-24.05-small 20230101 nixos-24.11 20230101 nixpkgs-24.11-darwin 20230101 nixos-24.11-small 20230101 nixos-unstable 20230101 nixos-unstable-small 20230101 nixpkgs-unstable 20230101 pkgs.python312Packages.fontforge Font editor nixos-24.05 20230101 nixpkgs-24.05-darwin 20230101 nixos-24.05-small 20230101 nixos-24.11 20230101 nixpkgs-24.11-darwin 20230101 nixos-24.11-small 20230101 nixos-unstable 20230101 nixos-unstable-small 20230101 nixpkgs-unstable 20230101 pkgs.emacsPackages.consult-gh-forge nixos-24.11 20240927.1004 nixpkgs-24.11-darwin 20240927.1004 nixos-24.11-small 20240927.1004 nixos-unstable 20240927.1004 nixos-unstable-small 20240927.1004 nixpkgs-unstable 20240927.1004 Notify package maintainers: 15 @chessai Daniel Cartwright <chessai1996@gmail.com> @twesterhout Tom Westerhout @nycodeghg Marie Ramlow <tabmeier12+nix@gmail.com> @adamcstephens Adam C. Stephens <happy.plan4249@valkor.net> @emilylange Emily Lange <nix@emilylange.de> @urandom2 Colin Arnott <colin@urandom.co.uk> @bendlas Herwig Hochleitner <herwig@bendlas.net> @eigengrau Sebastian Reuße <seb@schattenkopie.de> @cyplo Cyryl Płotnicki <nixos@cyplo.dev> @isabelroses Isabel Roses <isabel@isabelroses.com> @Moraxyc Moraxyc Xu <nix@qaq.li> @michaelgrahamevans Michael Evans <michaelgrahamevans@gmail.com> @erictapen Kerstin Humm <kerstin@erictapen.name> @Kranzes Ilan Joselevich <personal@ilanjoselevich.com> @christoph-heiss Christoph Heiss <christoph@c8h4.io> CVE-2023-4911 7.8 HIGH CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 2 months, 1 week ago Glibc: buffer overflow in ld.so leading to privilege escalation A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges. glibc * <2.39 compat-glibc redhat-virtualization-host * redhat-release-virtualization-host * pkgs.glibc GNU C Library nixos-24.05 2.39-52 nixpkgs-24.05-darwin 2.39-52 nixos-24.05-small 2.39-52 nixos-24.11 2.40-36 nixpkgs-24.11-darwin 2.40-36 nixos-24.11-small 2.40-36 nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36 pkgs.iconv GNU C Library nixos-24.05 2.39-52 nixpkgs-24.05-darwin 2.39-52 nixos-24.05-small 2.39-52 nixos-24.11 2.40-36 nixpkgs-24.11-darwin 2.40-36 nixos-24.11-small 2.40-36 nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36 pkgs.getent nixos-24.05 2.39-52 nixpkgs-24.05-darwin 2.39-52 nixos-24.05-small 2.39-52 nixos-24.11 2.40-36 nixpkgs-24.11-darwin 2.40-36 nixos-24.11-small 2.40-36 nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36 pkgs.locale nixos-24.05 2.39-52 nixpkgs-24.05-darwin 2.39-52 nixos-24.05-small 2.39-52 nixos-24.11 2.40-36 nixpkgs-24.11-darwin 2.40-36 nixos-24.11-small 2.40-36 nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36 pkgs.mtrace Perl script used to interpret and provide human readable output of the trace log contained in the file mtracedata, whose contents were produced by mtrace(3) nixos-24.05 2.39-52 nixpkgs-24.05-darwin 2.39-52 nixos-24.05-small 2.39-52 nixos-24.11 2.40-36 nixpkgs-24.11-darwin 2.40-36 nixos-24.11-small 2.40-36 nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36 pkgs.getconf nixos-24.05 2.39-52 nixpkgs-24.05-darwin 2.39-52 nixos-24.05-small 2.39-52 nixos-24.11 2.40-36 nixpkgs-24.11-darwin 2.40-36 nixos-24.11-small 2.40-36 nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36 pkgs.libiconv nixos-24.05 2.39 nixpkgs-24.05-darwin 2.39 nixos-24.05-small 2.39 nixos-24.11 2.40 nixpkgs-24.11-darwin 2.40 nixos-24.11-small 2.40 nixos-unstable 2.40 nixos-unstable-small 2.40 nixpkgs-unstable 2.40 pkgs.glibcInfo GNU Info manual of the GNU C Library nixos-24.05 2.39-52 nixpkgs-24.05-darwin 2.39-52 nixos-24.05-small 2.39-52 nixos-24.11 2.40-36 nixpkgs-24.11-darwin 2.40-36 nixos-24.11-small 2.40-36 nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36 pkgs.glibc_multi nixos-24.05 2.39-52 nixpkgs-24.05-darwin 2.39-52 nixos-24.05-small 2.39-52 nixos-24.11 2.40-36 nixpkgs-24.11-darwin 2.40-36 nixos-24.11-small 2.40-36 nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36 pkgs.glibcLocales Locale information for the GNU C Library nixos-24.05 2.39-52 nixpkgs-24.05-darwin 2.39-52 nixos-24.05-small 2.39-52 nixos-24.11 2.40-36 nixpkgs-24.11-darwin 2.40-36 nixos-24.11-small 2.40-36 nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36 pkgs.glibc_memusage GNU C Library nixos-24.05 2.39-52 nixpkgs-24.05-darwin 2.39-52 nixos-24.05-small 2.39-52 nixos-24.11 2.40-36 nixpkgs-24.11-darwin 2.40-36 nixos-24.11-small 2.40-36 nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36 pkgs.glibcLocalesUtf8 Locale information for the GNU C Library nixos-24.05 2.39-52 nixpkgs-24.05-darwin 2.39-52 nixos-24.05-small 2.39-52 nixos-24.11 2.40-36 nixpkgs-24.11-darwin 2.40-36 nixos-24.11-small 2.40-36 nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36 pkgs.unixtools.getent nixos-24.05 2.39-52 nixpkgs-24.05-darwin 2.39-52 nixos-24.05-small 2.39-52 nixos-24.11 2.40-36 nixpkgs-24.11-darwin 2.40-36 nixos-24.11-small 2.40-36 nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36 pkgs.unixtools.locale nixos-24.05 2.39-52 nixpkgs-24.05-darwin 2.39-52 nixos-24.05-small 2.39-52 nixos-24.11 2.40-36 nixpkgs-24.11-darwin 2.40-36 nixos-24.11-small 2.40-36 nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36 pkgs.unixtools.getconf nixos-24.05 2.39-52 nixpkgs-24.05-darwin 2.39-52 nixos-24.05-small 2.39-52 nixos-24.11 2.40-36 nixpkgs-24.11-darwin 2.40-36 nixos-24.11-small 2.40-36 nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36 Notify package maintainers: 2 @Ma27 Maximilian Bosch <maximilian@mbosch.me> @connorbaker Connor Baker <connor.baker@tweag.io> CVE-2024-22029 7.8 HIGH CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH updated 2 months ago by @fricklerhandwerk Activity log Created automatic suggestion 2 months, 1 week ago @fricklerhandwerk removed 3 packages pkgs.tomcat_connectors 1.2.48 pkgs.apachetomcatscanner 3.5 pkgs.apachetomcatscanner 3.7.2 2 months ago tomcat packaging allows for escalation to root from tomcat user Insecure permissions in the packaging of tomcat allow local users that win a race during package installation to escalate to root tomcat <9.0.85-150200.57.1 <9.0.85-3.1 pkgs.tomcat9 Implementation of the Java Servlet and JavaServer Pages technologies nixos-24.05 9.0.88 nixpkgs-24.05-darwin 9.0.88 nixos-24.05-small 9.0.88 nixos-24.11 9.0.95 nixpkgs-24.11-darwin 9.0.95 nixos-24.11-small 9.0.95 nixos-unstable 9.0.97 nixos-unstable-small 9.0.97 nixpkgs-unstable 9.0.97 pkgs.tomcat10 Implementation of the Java Servlet and JavaServer Pages technologies nixos-24.05 10.1.23 nixpkgs-24.05-darwin 10.1.23 nixos-24.05-small 10.1.23 nixos-24.11 10.1.30 nixpkgs-24.11-darwin 10.1.30 nixos-24.11-small 10.1.30 nixos-unstable 10.1.33 nixos-unstable-small 10.1.33 nixpkgs-unstable 10.1.33 pkgs.tomcat11 Implementation of the Java Servlet and JavaServer Pages technologies nixos-24.11 11.0.0 nixpkgs-24.11-darwin 11.0.0 nixos-24.11-small 11.0.0 nixos-unstable 11.0.0 nixos-unstable-small 11.0.0 nixpkgs-unstable 11.0.0 pkgs.tomcat-native Optional component for use with Apache Tomcat that allows Tomcat to use certain native resources for performance, compatibility, etc nixos-24.05 2.0.7 nixpkgs-24.05-darwin 2.0.7 nixos-24.05-small 2.0.7 nixos-24.11 2.0.8 nixpkgs-24.11-darwin 2.0.8 nixos-24.11-small 2.0.8 nixos-unstable 2.0.8 nixos-unstable-small 2.0.8 nixpkgs-unstable 2.0.8 pkgs.tomcat_mysql_jdbc nixos-24.05 8.3.0 nixpkgs-24.05-darwin 8.3.0 nixos-24.05-small 8.3.0 nixos-24.11 9.0.0 nixpkgs-24.11-darwin 9.0.0 nixos-24.11-small 9.0.0 nixos-unstable 9.1.0 nixos-unstable-small 9.1.0 nixpkgs-unstable 9.1.0 Notify package maintainers: 2 @anthonyroussel Anthony Roussel <anthony@roussel.dev> @aanderse Aaron Andersen <aaron@fosslib.net> CVE-2023-46846 9.3 CRITICAL CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): CHANGED Confidentiality impact (C): HIGH Integrity impact (I): LOW Availability impact (A): NONE updated 2 months ago by @fricklerhandwerk Activity log Created automatic suggestion 2 months, 1 week ago @fricklerhandwerk removed 3 packages pkgs.prometheus-squid-exporter 1.12.0 pkgs.python311Packages.flyingsquid 0.0.0a0 pkgs.python312Packages.flyingsquid 0.0.0a0 2 months ago Squid: request/response smuggling in http/1.1 and icap SQUID is vulnerable to HTTP request smuggling, caused by chunked decoder lenience, allows a remote attacker to perform Request/Response smuggling past firewall and frontend security systems. squid * <6.4 squid34 squid:4 * pkgs.squid Caching proxy for the Web supporting HTTP, HTTPS, FTP, and more nixos-24.05 6.8 nixpkgs-24.05-darwin 6.8 nixos-24.05-small 6.8 nixos-24.11 6.10 nixpkgs-24.11-darwin 6.10 nixos-24.11-small 6.10 nixos-unstable 6.10 nixos-unstable-small 6.10 nixpkgs-unstable 6.10 Notify package maintainers: 1 @7c6f434c Michael Raskin <7c6f434c@mail.ru>
CVE-2023-3758 7.1 HIGH CVSS version: 3.1 Attack vector (AV): ADJACENT_NETWORK Attack complexity (AC): HIGH Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 2 months ago Sssd: race condition during authorization leads to gpo policies functioning inconsistently A race condition flaw was found in sssd where the GPO policy is not consistently applied for authenticated users. This may lead to improper authorization issues, granting or denying access to resources inappropriately. sssd <2.9.5 * pkgs.sssd System Security Services Daemon nixos-24.05 2.9.4 nixpkgs-24.05-darwin 2.9.4 nixos-24.05-small 2.9.4 nixos-24.11 2.9.5 nixpkgs-24.11-darwin 2.9.5 nixos-24.11-small 2.9.5 nixos-unstable 2.9.5 nixos-unstable-small 2.9.5 nixpkgs-unstable 2.9.5 Notify package maintainers: 1 @illustris Harikrishnan R <me@illustris.tech>
pkgs.sssd System Security Services Daemon nixos-24.05 2.9.4 nixpkgs-24.05-darwin 2.9.4 nixos-24.05-small 2.9.4 nixos-24.11 2.9.5 nixpkgs-24.11-darwin 2.9.5 nixos-24.11-small 2.9.5 nixos-unstable 2.9.5 nixos-unstable-small 2.9.5 nixpkgs-unstable 2.9.5
CVE-2022-2084 5.5 MEDIUM CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): NONE Availability impact (A): NONE created 2 months ago sensitive data exposure in cloud-init logs Sensitive data could be exposed in world readable logs of cloud-init before version 22.3 when schema failures are reported. This leak could include hashed passwords. cloud-init <23.0 pkgs.cloud-init Provides configuration and customization of cloud instance nixos-24.05 24.1 nixpkgs-24.05-darwin 24.1 nixos-24.05-small 24.1 nixos-24.11 24.2 nixpkgs-24.11-darwin 24.2 nixos-24.11-small 24.2 nixos-unstable 24.2 nixos-unstable-small 24.2 nixpkgs-unstable 24.2 Notify package maintainers: 2 @jfroche Jean-François Roche <jfroche@pyxel.be> @illustris Harikrishnan R <me@illustris.tech>
pkgs.cloud-init Provides configuration and customization of cloud instance nixos-24.05 24.1 nixpkgs-24.05-darwin 24.1 nixos-24.05-small 24.1 nixos-24.11 24.2 nixpkgs-24.11-darwin 24.2 nixos-24.11-small 24.2 nixos-unstable 24.2 nixos-unstable-small 24.2 nixpkgs-unstable 24.2
CVE-2023-30797 7.5 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): NONE Availability impact (A): NONE created 2 months ago Insecure Random Generation in Netflix Lemur Netflix Lemur before version 1.3.2 used insufficiently random values when generating default credentials. The insufficiently random values may allow an attacker to guess the credentials and gain access to resources managed by Lemur. lemur <<1.3.2 pkgs.lemurs Customizable TUI display/login manager written in Rust nixos-24.05 0.3.2 nixpkgs-24.05-darwin 0.3.2 nixos-24.05-small 0.3.2 nixos-24.11 0.3.2 nixpkgs-24.11-darwin 0.3.2 nixos-24.11-small 0.3.2 nixos-unstable 0.3.2 nixos-unstable-small 0.3.2 nixpkgs-unstable 0.3.2 Notify package maintainers: 1 @JeremiahSecrist Jeremiah Secrist <jeremiah@secrist.xyz>
pkgs.lemurs Customizable TUI display/login manager written in Rust nixos-24.05 0.3.2 nixpkgs-24.05-darwin 0.3.2 nixos-24.05-small 0.3.2 nixos-24.11 0.3.2 nixpkgs-24.11-darwin 0.3.2 nixos-24.11-small 0.3.2 nixos-unstable 0.3.2 nixos-unstable-small 0.3.2 nixpkgs-unstable 0.3.2
CVE-2021-3429 5.5 MEDIUM CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): NONE Availability impact (A): NONE created 2 months ago sensitive data exposure in cloud-init logs When instructing cloud-init to set a random password for a new user account, versions before 21.2 would write that password to the world-readable log file /var/log/cloud-init-output.log. This could allow a local user to log in as another user. cloud-init <21.2 pkgs.cloud-init Provides configuration and customization of cloud instance nixos-24.05 24.1 nixpkgs-24.05-darwin 24.1 nixos-24.05-small 24.1 nixos-24.11 24.2 nixpkgs-24.11-darwin 24.2 nixos-24.11-small 24.2 nixos-unstable 24.2 nixos-unstable-small 24.2 nixpkgs-unstable 24.2 Notify package maintainers: 2 @jfroche Jean-François Roche <jfroche@pyxel.be> @illustris Harikrishnan R <me@illustris.tech>
pkgs.cloud-init Provides configuration and customization of cloud instance nixos-24.05 24.1 nixpkgs-24.05-darwin 24.1 nixos-24.05-small 24.1 nixos-24.11 24.2 nixpkgs-24.11-darwin 24.2 nixos-24.11-small 24.2 nixos-unstable 24.2 nixos-unstable-small 24.2 nixpkgs-unstable 24.2
CVE-2023-30798 7.5 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): HIGH created 2 months ago MultipartParser DOS with too many fields or files in Starlette Framework There MultipartParser usage in Encode's Starlette python framework before versions 0.25.0 allows an unauthenticated and remote attacker to specify any number of form fields or files which can cause excessive memory usage resulting in denial of service of the HTTP service. starlette <0.25.0 pkgs.python311Packages.starlette The little ASGI framework that shines nixos-24.05 0.37.2 nixpkgs-24.05-darwin 0.37.2 nixos-24.05-small 0.37.2 nixos-24.11 0.40.0 nixpkgs-24.11-darwin 0.40.0 nixos-24.11-small 0.40.0 nixos-unstable 0.40.0 nixos-unstable-small 0.40.0 nixpkgs-unstable 0.40.0 pkgs.python312Packages.starlette Little ASGI framework that shines nixos-24.05 0.37.2 nixpkgs-24.05-darwin 0.37.2 nixos-24.05-small 0.37.2 nixos-24.11 0.40.0 nixpkgs-24.11-darwin 0.40.0 nixos-24.11-small 0.40.0 nixos-unstable 0.40.0 nixos-unstable-small 0.40.0 nixpkgs-unstable 0.40.0 pkgs.python311Packages.sse-starlette Server Sent Events for Starlette and FastAPI nixos-24.05 2.1.0 nixpkgs-24.05-darwin 2.1.0 nixos-24.05-small 2.1.0 nixos-24.11 2.1.3 nixpkgs-24.11-darwin 2.1.3 nixos-24.11-small 2.1.3 nixos-unstable 2.1.3 nixos-unstable-small 2.1.3 nixpkgs-unstable 2.1.3 pkgs.python311Packages.starlette-wtf A simple tool for integrating Starlette and WTForms nixos-24.05 0.4.5 nixpkgs-24.05-darwin 0.4.5 nixos-24.05-small 0.4.5 nixos-24.11 0.4.5 nixpkgs-24.11-darwin 0.4.5 nixos-24.11-small 0.4.5 nixos-unstable 0.4.5 nixos-unstable-small 0.4.5 nixpkgs-unstable 0.4.5 pkgs.python312Packages.sse-starlette Server Sent Events for Starlette and FastAPI nixos-24.05 2.1.0 nixpkgs-24.05-darwin 2.1.0 nixos-24.05-small 2.1.0 nixos-24.11 2.1.3 nixpkgs-24.11-darwin 2.1.3 nixos-24.11-small 2.1.3 nixos-unstable 2.1.3 nixos-unstable-small 2.1.3 nixpkgs-unstable 2.1.3 pkgs.python312Packages.starlette-wtf Simple tool for integrating Starlette and WTForms nixos-24.05 0.4.5 nixpkgs-24.05-darwin 0.4.5 nixos-24.05-small 0.4.5 nixos-24.11 0.4.5 nixpkgs-24.11-darwin 0.4.5 nixos-24.11-small 0.4.5 nixos-unstable 0.4.5 nixos-unstable-small 0.4.5 nixpkgs-unstable 0.4.5 pkgs.python311Packages.starlette-admin Fast, beautiful and extensible administrative interface framework for Starlette & FastApi applications nixos-24.11 0.14.1 nixpkgs-24.11-darwin 0.14.1 nixos-24.11-small 0.14.1 nixos-unstable 0.14.1 nixos-unstable-small 0.14.1 nixpkgs-unstable 0.14.1 pkgs.python312Packages.starlette-admin Fast, beautiful and extensible administrative interface framework for Starlette & FastApi applications nixos-24.11 0.14.1 nixpkgs-24.11-darwin 0.14.1 nixos-24.11-small 0.14.1 nixos-unstable 0.14.1 nixos-unstable-small 0.14.1 nixpkgs-unstable 0.14.1 pkgs.python311Packages.starlette-context Middleware for Starlette that allows you to store and access the context data of a request nixos-24.05 0.3.6 nixpkgs-24.05-darwin 0.3.6 nixos-24.05-small 0.3.6 nixos-24.11 0.3.6 nixpkgs-24.11-darwin 0.3.6 nixos-24.11-small 0.3.6 nixos-unstable 0.3.6 nixos-unstable-small 0.3.6 nixpkgs-unstable 0.3.6 pkgs.python312Packages.starlette-context Middleware for Starlette that allows you to store and access the context data of a request nixos-24.05 0.3.6 nixpkgs-24.05-darwin 0.3.6 nixos-24.05-small 0.3.6 nixos-24.11 0.3.6 nixpkgs-24.11-darwin 0.3.6 nixos-24.11-small 0.3.6 nixos-unstable 0.3.6 nixos-unstable-small 0.3.6 nixpkgs-unstable 0.3.6 Notify package maintainers: 7 @wd15 Daniel Wheeler <daniel.wheeler2@gmail.com> @fabaff Fabian Affolter <mail@fabian-affolter.ch> @yu-re-ka Yureka <yuka@yuka.dev> @vidister Fiona Weber <v@vidister.de> @n0emis Ember Keske <nixpkgs@n0emis.network> @johannwagner Johann Wagner <nix@wagner.digital> @pbsds Peder Bergebakken Sundt <pbsds@hotmail.com>
pkgs.python311Packages.starlette The little ASGI framework that shines nixos-24.05 0.37.2 nixpkgs-24.05-darwin 0.37.2 nixos-24.05-small 0.37.2 nixos-24.11 0.40.0 nixpkgs-24.11-darwin 0.40.0 nixos-24.11-small 0.40.0 nixos-unstable 0.40.0 nixos-unstable-small 0.40.0 nixpkgs-unstable 0.40.0
pkgs.python312Packages.starlette Little ASGI framework that shines nixos-24.05 0.37.2 nixpkgs-24.05-darwin 0.37.2 nixos-24.05-small 0.37.2 nixos-24.11 0.40.0 nixpkgs-24.11-darwin 0.40.0 nixos-24.11-small 0.40.0 nixos-unstable 0.40.0 nixos-unstable-small 0.40.0 nixpkgs-unstable 0.40.0
pkgs.python311Packages.sse-starlette Server Sent Events for Starlette and FastAPI nixos-24.05 2.1.0 nixpkgs-24.05-darwin 2.1.0 nixos-24.05-small 2.1.0 nixos-24.11 2.1.3 nixpkgs-24.11-darwin 2.1.3 nixos-24.11-small 2.1.3 nixos-unstable 2.1.3 nixos-unstable-small 2.1.3 nixpkgs-unstable 2.1.3
pkgs.python311Packages.starlette-wtf A simple tool for integrating Starlette and WTForms nixos-24.05 0.4.5 nixpkgs-24.05-darwin 0.4.5 nixos-24.05-small 0.4.5 nixos-24.11 0.4.5 nixpkgs-24.11-darwin 0.4.5 nixos-24.11-small 0.4.5 nixos-unstable 0.4.5 nixos-unstable-small 0.4.5 nixpkgs-unstable 0.4.5
pkgs.python312Packages.sse-starlette Server Sent Events for Starlette and FastAPI nixos-24.05 2.1.0 nixpkgs-24.05-darwin 2.1.0 nixos-24.05-small 2.1.0 nixos-24.11 2.1.3 nixpkgs-24.11-darwin 2.1.3 nixos-24.11-small 2.1.3 nixos-unstable 2.1.3 nixos-unstable-small 2.1.3 nixpkgs-unstable 2.1.3
pkgs.python312Packages.starlette-wtf Simple tool for integrating Starlette and WTForms nixos-24.05 0.4.5 nixpkgs-24.05-darwin 0.4.5 nixos-24.05-small 0.4.5 nixos-24.11 0.4.5 nixpkgs-24.11-darwin 0.4.5 nixos-24.11-small 0.4.5 nixos-unstable 0.4.5 nixos-unstable-small 0.4.5 nixpkgs-unstable 0.4.5
pkgs.python311Packages.starlette-admin Fast, beautiful and extensible administrative interface framework for Starlette & FastApi applications nixos-24.11 0.14.1 nixpkgs-24.11-darwin 0.14.1 nixos-24.11-small 0.14.1 nixos-unstable 0.14.1 nixos-unstable-small 0.14.1 nixpkgs-unstable 0.14.1
pkgs.python312Packages.starlette-admin Fast, beautiful and extensible administrative interface framework for Starlette & FastApi applications nixos-24.11 0.14.1 nixpkgs-24.11-darwin 0.14.1 nixos-24.11-small 0.14.1 nixos-unstable 0.14.1 nixos-unstable-small 0.14.1 nixpkgs-unstable 0.14.1
pkgs.python311Packages.starlette-context Middleware for Starlette that allows you to store and access the context data of a request nixos-24.05 0.3.6 nixpkgs-24.05-darwin 0.3.6 nixos-24.05-small 0.3.6 nixos-24.11 0.3.6 nixpkgs-24.11-darwin 0.3.6 nixos-24.11-small 0.3.6 nixos-unstable 0.3.6 nixos-unstable-small 0.3.6 nixpkgs-unstable 0.3.6
pkgs.python312Packages.starlette-context Middleware for Starlette that allows you to store and access the context data of a request nixos-24.05 0.3.6 nixpkgs-24.05-darwin 0.3.6 nixos-24.05-small 0.3.6 nixos-24.11 0.3.6 nixpkgs-24.11-darwin 0.3.6 nixos-24.11-small 0.3.6 nixos-unstable 0.3.6 nixos-unstable-small 0.3.6 nixpkgs-unstable 0.3.6
CVE-2025-24684 7.1 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): CHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 2 months ago WordPress Media Downloader Plugin <= 0.4.7.5 - Reflected Cross Site Scripting (XSS) vulnerability Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ederson Peka Media Downloader allows Reflected XSS. This issue affects Media Downloader: from n/a through 0.4.7.5. media-downloader =<0.4.7.5 pkgs.media-downloader A Qt/C++ GUI front end for yt-dlp and others nixos-24.05 4.6.0 nixpkgs-24.05-darwin 4.6.0 nixos-24.05-small 4.6.0 nixos-24.11 5.2.0 nixpkgs-24.11-darwin 5.2.0 nixos-24.11-small 5.2.0 nixos-unstable 5.2.0 nixos-unstable-small 5.2.0 nixpkgs-unstable 5.2.0 Notify package maintainers: 1 @zendo zendo <linzway@qq.com>
pkgs.media-downloader A Qt/C++ GUI front end for yt-dlp and others nixos-24.05 4.6.0 nixpkgs-24.05-darwin 4.6.0 nixos-24.05-small 4.6.0 nixos-24.11 5.2.0 nixpkgs-24.11-darwin 5.2.0 nixos-24.11-small 5.2.0 nixos-unstable 5.2.0 nixos-unstable-small 5.2.0 nixpkgs-unstable 5.2.0
CVE-2025-22703 7.1 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): CHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 2 months ago WordPress Forge – Front-End Page Builder plugin <= 1.4.6 - CSRF to Stored Cross Site Scripting (XSS) vulnerability Cross-Site Request Forgery (CSRF) vulnerability in manuelvicedo Forge – Front-End Page Builder allows Stored XSS. This issue affects Forge – Front-End Page Builder: from n/a through 1.4.6. forge =<1.4.6 pkgs.forge OpenGL interop library that can be used with ArrayFire or any other application using CUDA or OpenCL compute backend nixos-24.05 1.0.8 nixpkgs-24.05-darwin 1.0.8 nixos-24.05-small 1.0.8 nixos-24.11 1.0.8 nixpkgs-24.11-darwin 1.0.8 nixos-24.11-small 1.0.8 nixos-unstable 1.0.8 nixos-unstable-small 1.0.8 nixpkgs-unstable 1.0.8 pkgs.forgejo Self-hosted lightweight software forge nixos-24.05 7.0.11 nixpkgs-24.05-darwin 7.0.11 nixos-24.05-small 7.0.11 nixos-24.11 9.0.2 nixpkgs-24.11-darwin 9.0.2 nixos-24.11-small 9.0.2 nixos-unstable 9.0.2 nixos-unstable-small 9.0.2 nixpkgs-unstable 9.0.2 pkgs.forge-mtg Magic: the Gathering card game with rules enforcement nixos-24.05 1.6.57 nixpkgs-24.05-darwin 1.6.57 nixos-24.05-small 1.6.57 nixos-24.11 1.6.65 nixpkgs-24.11-darwin 1.6.65 nixos-24.11-small 1.6.65 nixos-unstable 1.6.65 nixos-unstable-small 1.6.65 nixpkgs-unstable 1.6.65 pkgs.mindforger Thinking Notebook & Markdown IDE nixos-24.05 1.52.0 nixpkgs-24.05-darwin 1.52.0 nixos-24.05-small 1.52.0 nixos-24.11 1.52.0 nixpkgs-24.11-darwin 1.52.0 nixos-24.11-small 1.52.0 nixos-unstable 1.52.0 nixos-unstable-small 1.52.0 nixpkgs-unstable 1.52.0 pkgs.forgejo-cli CLI application for interacting with Forgejo nixos-24.11 0.1.1 nixpkgs-24.11-darwin 0.1.1 nixos-24.11-small 0.1.1 nixos-unstable 0.1.1 nixos-unstable-small 0.1.1 nixpkgs-unstable 0.1.1 pkgs.forgejo-lts Self-hosted lightweight software forge nixos-24.11 7.0.11 nixpkgs-24.11-darwin 7.0.11 nixos-24.11-small 7.0.11 nixos-unstable 7.0.11 nixos-unstable-small 7.0.11 nixpkgs-unstable 7.0.11 pkgs.mcdreforged Rewritten version of MCDaemon, a python tool to control your Minecraft server nixos-24.11 2.13.2 nixpkgs-24.11-darwin 2.13.2 nixos-24.11-small 2.13.2 nixos-unstable 2.13.2 nixos-unstable-small 2.13.2 nixpkgs-unstable 2.13.2 pkgs.forge-sparks Get Git forges notifications nixos-24.05 0.3.0 nixpkgs-24.05-darwin 0.3.0 nixos-24.05-small 0.3.0 nixos-24.11 0.4.0 nixpkgs-24.11-darwin 0.4.0 nixos-24.11-small 0.4.0 nixos-unstable 0.4.0 nixos-unstable-small 0.4.0 nixpkgs-unstable 0.4.0 pkgs.fontforge-gtk Font editor nixos-24.05 20230101 nixpkgs-24.05-darwin 20230101 nixos-24.05-small 20230101 nixos-24.11 20230101 nixpkgs-24.11-darwin 20230101 nixos-24.11-small 20230101 nixos-unstable 20230101 nixos-unstable-small 20230101 nixpkgs-unstable 20230101 pkgs.forgejo-runner Runner for Forgejo based on act nixos-24.05 3.5.1 nixpkgs-24.05-darwin 3.5.1 nixos-24.05-small 3.5.1 nixos-24.11 4.0.1 nixpkgs-24.11-darwin 4.0.1 nixos-24.11-small 4.0.1 nixos-unstable 5.0.3 nixos-unstable-small 5.0.3 nixpkgs-unstable 5.0.3 pkgs.emacsPackages.forge nixos-24.05 20240423.2033 nixpkgs-24.05-darwin 20240423.2033 nixos-24.05-small 20240423.2033 nixos-24.11 20241014.1340 nixpkgs-24.11-darwin 20241014.1340 nixos-24.11-small 20241014.1340 nixos-unstable 20241014.1340 nixos-unstable-small 20241014.1340 nixpkgs-unstable 20241014.1340 pkgs.fontforge-fonttools Font editor nixos-24.05 20230101 nixpkgs-24.05-darwin 20230101 nixos-24.05-small 20230101 nixos-24.11 20230101 nixpkgs-24.11-darwin 20230101 nixos-24.11-small 20230101 nixos-unstable 20230101 nixos-unstable-small 20230101 nixpkgs-unstable 20230101 pkgs.gnomeExtensions.forge Tiling and window manager for GNOME nixos-24.05 78 nixpkgs-24.05-darwin 78 nixos-24.05-small 78 nixos-24.11 84 nixpkgs-24.11-darwin 84 nixos-24.11-small 84 nixos-unstable 84 nixos-unstable-small 84 nixpkgs-unstable 84 pkgs.emacsPackages.orgit-forge nixos-24.05 20240415.1546 nixpkgs-24.05-darwin 20240415.1546 nixos-24.05-small 20240415.1546 nixos-24.11 20240808.1947 nixpkgs-24.11-darwin 20240808.1947 nixos-24.11-small 20240808.1947 nixos-unstable 20240808.1947 nixos-unstable-small 20240808.1947 nixpkgs-unstable 20240808.1947 pkgs.python311Packages.fontforge Font editor nixos-24.05 20230101 nixpkgs-24.05-darwin 20230101 nixos-24.05-small 20230101 nixos-24.11 20230101 nixpkgs-24.11-darwin 20230101 nixos-24.11-small 20230101 nixos-unstable 20230101 nixos-unstable-small 20230101 nixpkgs-unstable 20230101 pkgs.python312Packages.fontforge Font editor nixos-24.05 20230101 nixpkgs-24.05-darwin 20230101 nixos-24.05-small 20230101 nixos-24.11 20230101 nixpkgs-24.11-darwin 20230101 nixos-24.11-small 20230101 nixos-unstable 20230101 nixos-unstable-small 20230101 nixpkgs-unstable 20230101 pkgs.emacsPackages.consult-gh-forge nixos-24.11 20240927.1004 nixpkgs-24.11-darwin 20240927.1004 nixos-24.11-small 20240927.1004 nixos-unstable 20240927.1004 nixos-unstable-small 20240927.1004 nixpkgs-unstable 20240927.1004 Notify package maintainers: 15 @chessai Daniel Cartwright <chessai1996@gmail.com> @twesterhout Tom Westerhout @nycodeghg Marie Ramlow <tabmeier12+nix@gmail.com> @adamcstephens Adam C. Stephens <happy.plan4249@valkor.net> @emilylange Emily Lange <nix@emilylange.de> @urandom2 Colin Arnott <colin@urandom.co.uk> @bendlas Herwig Hochleitner <herwig@bendlas.net> @eigengrau Sebastian Reuße <seb@schattenkopie.de> @cyplo Cyryl Płotnicki <nixos@cyplo.dev> @isabelroses Isabel Roses <isabel@isabelroses.com> @Moraxyc Moraxyc Xu <nix@qaq.li> @michaelgrahamevans Michael Evans <michaelgrahamevans@gmail.com> @erictapen Kerstin Humm <kerstin@erictapen.name> @Kranzes Ilan Joselevich <personal@ilanjoselevich.com> @christoph-heiss Christoph Heiss <christoph@c8h4.io>
pkgs.forge OpenGL interop library that can be used with ArrayFire or any other application using CUDA or OpenCL compute backend nixos-24.05 1.0.8 nixpkgs-24.05-darwin 1.0.8 nixos-24.05-small 1.0.8 nixos-24.11 1.0.8 nixpkgs-24.11-darwin 1.0.8 nixos-24.11-small 1.0.8 nixos-unstable 1.0.8 nixos-unstable-small 1.0.8 nixpkgs-unstable 1.0.8
pkgs.forgejo Self-hosted lightweight software forge nixos-24.05 7.0.11 nixpkgs-24.05-darwin 7.0.11 nixos-24.05-small 7.0.11 nixos-24.11 9.0.2 nixpkgs-24.11-darwin 9.0.2 nixos-24.11-small 9.0.2 nixos-unstable 9.0.2 nixos-unstable-small 9.0.2 nixpkgs-unstable 9.0.2
pkgs.forge-mtg Magic: the Gathering card game with rules enforcement nixos-24.05 1.6.57 nixpkgs-24.05-darwin 1.6.57 nixos-24.05-small 1.6.57 nixos-24.11 1.6.65 nixpkgs-24.11-darwin 1.6.65 nixos-24.11-small 1.6.65 nixos-unstable 1.6.65 nixos-unstable-small 1.6.65 nixpkgs-unstable 1.6.65
pkgs.mindforger Thinking Notebook & Markdown IDE nixos-24.05 1.52.0 nixpkgs-24.05-darwin 1.52.0 nixos-24.05-small 1.52.0 nixos-24.11 1.52.0 nixpkgs-24.11-darwin 1.52.0 nixos-24.11-small 1.52.0 nixos-unstable 1.52.0 nixos-unstable-small 1.52.0 nixpkgs-unstable 1.52.0
pkgs.forgejo-cli CLI application for interacting with Forgejo nixos-24.11 0.1.1 nixpkgs-24.11-darwin 0.1.1 nixos-24.11-small 0.1.1 nixos-unstable 0.1.1 nixos-unstable-small 0.1.1 nixpkgs-unstable 0.1.1
pkgs.forgejo-lts Self-hosted lightweight software forge nixos-24.11 7.0.11 nixpkgs-24.11-darwin 7.0.11 nixos-24.11-small 7.0.11 nixos-unstable 7.0.11 nixos-unstable-small 7.0.11 nixpkgs-unstable 7.0.11
pkgs.mcdreforged Rewritten version of MCDaemon, a python tool to control your Minecraft server nixos-24.11 2.13.2 nixpkgs-24.11-darwin 2.13.2 nixos-24.11-small 2.13.2 nixos-unstable 2.13.2 nixos-unstable-small 2.13.2 nixpkgs-unstable 2.13.2
pkgs.forge-sparks Get Git forges notifications nixos-24.05 0.3.0 nixpkgs-24.05-darwin 0.3.0 nixos-24.05-small 0.3.0 nixos-24.11 0.4.0 nixpkgs-24.11-darwin 0.4.0 nixos-24.11-small 0.4.0 nixos-unstable 0.4.0 nixos-unstable-small 0.4.0 nixpkgs-unstable 0.4.0
pkgs.fontforge-gtk Font editor nixos-24.05 20230101 nixpkgs-24.05-darwin 20230101 nixos-24.05-small 20230101 nixos-24.11 20230101 nixpkgs-24.11-darwin 20230101 nixos-24.11-small 20230101 nixos-unstable 20230101 nixos-unstable-small 20230101 nixpkgs-unstable 20230101
pkgs.forgejo-runner Runner for Forgejo based on act nixos-24.05 3.5.1 nixpkgs-24.05-darwin 3.5.1 nixos-24.05-small 3.5.1 nixos-24.11 4.0.1 nixpkgs-24.11-darwin 4.0.1 nixos-24.11-small 4.0.1 nixos-unstable 5.0.3 nixos-unstable-small 5.0.3 nixpkgs-unstable 5.0.3
pkgs.emacsPackages.forge nixos-24.05 20240423.2033 nixpkgs-24.05-darwin 20240423.2033 nixos-24.05-small 20240423.2033 nixos-24.11 20241014.1340 nixpkgs-24.11-darwin 20241014.1340 nixos-24.11-small 20241014.1340 nixos-unstable 20241014.1340 nixos-unstable-small 20241014.1340 nixpkgs-unstable 20241014.1340
pkgs.fontforge-fonttools Font editor nixos-24.05 20230101 nixpkgs-24.05-darwin 20230101 nixos-24.05-small 20230101 nixos-24.11 20230101 nixpkgs-24.11-darwin 20230101 nixos-24.11-small 20230101 nixos-unstable 20230101 nixos-unstable-small 20230101 nixpkgs-unstable 20230101
pkgs.gnomeExtensions.forge Tiling and window manager for GNOME nixos-24.05 78 nixpkgs-24.05-darwin 78 nixos-24.05-small 78 nixos-24.11 84 nixpkgs-24.11-darwin 84 nixos-24.11-small 84 nixos-unstable 84 nixos-unstable-small 84 nixpkgs-unstable 84
pkgs.emacsPackages.orgit-forge nixos-24.05 20240415.1546 nixpkgs-24.05-darwin 20240415.1546 nixos-24.05-small 20240415.1546 nixos-24.11 20240808.1947 nixpkgs-24.11-darwin 20240808.1947 nixos-24.11-small 20240808.1947 nixos-unstable 20240808.1947 nixos-unstable-small 20240808.1947 nixpkgs-unstable 20240808.1947
pkgs.python311Packages.fontforge Font editor nixos-24.05 20230101 nixpkgs-24.05-darwin 20230101 nixos-24.05-small 20230101 nixos-24.11 20230101 nixpkgs-24.11-darwin 20230101 nixos-24.11-small 20230101 nixos-unstable 20230101 nixos-unstable-small 20230101 nixpkgs-unstable 20230101
pkgs.python312Packages.fontforge Font editor nixos-24.05 20230101 nixpkgs-24.05-darwin 20230101 nixos-24.05-small 20230101 nixos-24.11 20230101 nixpkgs-24.11-darwin 20230101 nixos-24.11-small 20230101 nixos-unstable 20230101 nixos-unstable-small 20230101 nixpkgs-unstable 20230101
pkgs.emacsPackages.consult-gh-forge nixos-24.11 20240927.1004 nixpkgs-24.11-darwin 20240927.1004 nixos-24.11-small 20240927.1004 nixos-unstable 20240927.1004 nixos-unstable-small 20240927.1004 nixpkgs-unstable 20240927.1004
CVE-2023-4911 7.8 HIGH CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 2 months, 1 week ago Glibc: buffer overflow in ld.so leading to privilege escalation A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges. glibc * <2.39 compat-glibc redhat-virtualization-host * redhat-release-virtualization-host * pkgs.glibc GNU C Library nixos-24.05 2.39-52 nixpkgs-24.05-darwin 2.39-52 nixos-24.05-small 2.39-52 nixos-24.11 2.40-36 nixpkgs-24.11-darwin 2.40-36 nixos-24.11-small 2.40-36 nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36 pkgs.iconv GNU C Library nixos-24.05 2.39-52 nixpkgs-24.05-darwin 2.39-52 nixos-24.05-small 2.39-52 nixos-24.11 2.40-36 nixpkgs-24.11-darwin 2.40-36 nixos-24.11-small 2.40-36 nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36 pkgs.getent nixos-24.05 2.39-52 nixpkgs-24.05-darwin 2.39-52 nixos-24.05-small 2.39-52 nixos-24.11 2.40-36 nixpkgs-24.11-darwin 2.40-36 nixos-24.11-small 2.40-36 nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36 pkgs.locale nixos-24.05 2.39-52 nixpkgs-24.05-darwin 2.39-52 nixos-24.05-small 2.39-52 nixos-24.11 2.40-36 nixpkgs-24.11-darwin 2.40-36 nixos-24.11-small 2.40-36 nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36 pkgs.mtrace Perl script used to interpret and provide human readable output of the trace log contained in the file mtracedata, whose contents were produced by mtrace(3) nixos-24.05 2.39-52 nixpkgs-24.05-darwin 2.39-52 nixos-24.05-small 2.39-52 nixos-24.11 2.40-36 nixpkgs-24.11-darwin 2.40-36 nixos-24.11-small 2.40-36 nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36 pkgs.getconf nixos-24.05 2.39-52 nixpkgs-24.05-darwin 2.39-52 nixos-24.05-small 2.39-52 nixos-24.11 2.40-36 nixpkgs-24.11-darwin 2.40-36 nixos-24.11-small 2.40-36 nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36 pkgs.libiconv nixos-24.05 2.39 nixpkgs-24.05-darwin 2.39 nixos-24.05-small 2.39 nixos-24.11 2.40 nixpkgs-24.11-darwin 2.40 nixos-24.11-small 2.40 nixos-unstable 2.40 nixos-unstable-small 2.40 nixpkgs-unstable 2.40 pkgs.glibcInfo GNU Info manual of the GNU C Library nixos-24.05 2.39-52 nixpkgs-24.05-darwin 2.39-52 nixos-24.05-small 2.39-52 nixos-24.11 2.40-36 nixpkgs-24.11-darwin 2.40-36 nixos-24.11-small 2.40-36 nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36 pkgs.glibc_multi nixos-24.05 2.39-52 nixpkgs-24.05-darwin 2.39-52 nixos-24.05-small 2.39-52 nixos-24.11 2.40-36 nixpkgs-24.11-darwin 2.40-36 nixos-24.11-small 2.40-36 nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36 pkgs.glibcLocales Locale information for the GNU C Library nixos-24.05 2.39-52 nixpkgs-24.05-darwin 2.39-52 nixos-24.05-small 2.39-52 nixos-24.11 2.40-36 nixpkgs-24.11-darwin 2.40-36 nixos-24.11-small 2.40-36 nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36 pkgs.glibc_memusage GNU C Library nixos-24.05 2.39-52 nixpkgs-24.05-darwin 2.39-52 nixos-24.05-small 2.39-52 nixos-24.11 2.40-36 nixpkgs-24.11-darwin 2.40-36 nixos-24.11-small 2.40-36 nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36 pkgs.glibcLocalesUtf8 Locale information for the GNU C Library nixos-24.05 2.39-52 nixpkgs-24.05-darwin 2.39-52 nixos-24.05-small 2.39-52 nixos-24.11 2.40-36 nixpkgs-24.11-darwin 2.40-36 nixos-24.11-small 2.40-36 nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36 pkgs.unixtools.getent nixos-24.05 2.39-52 nixpkgs-24.05-darwin 2.39-52 nixos-24.05-small 2.39-52 nixos-24.11 2.40-36 nixpkgs-24.11-darwin 2.40-36 nixos-24.11-small 2.40-36 nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36 pkgs.unixtools.locale nixos-24.05 2.39-52 nixpkgs-24.05-darwin 2.39-52 nixos-24.05-small 2.39-52 nixos-24.11 2.40-36 nixpkgs-24.11-darwin 2.40-36 nixos-24.11-small 2.40-36 nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36 pkgs.unixtools.getconf nixos-24.05 2.39-52 nixpkgs-24.05-darwin 2.39-52 nixos-24.05-small 2.39-52 nixos-24.11 2.40-36 nixpkgs-24.11-darwin 2.40-36 nixos-24.11-small 2.40-36 nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36 Notify package maintainers: 2 @Ma27 Maximilian Bosch <maximilian@mbosch.me> @connorbaker Connor Baker <connor.baker@tweag.io>
pkgs.glibc GNU C Library nixos-24.05 2.39-52 nixpkgs-24.05-darwin 2.39-52 nixos-24.05-small 2.39-52 nixos-24.11 2.40-36 nixpkgs-24.11-darwin 2.40-36 nixos-24.11-small 2.40-36 nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36
pkgs.iconv GNU C Library nixos-24.05 2.39-52 nixpkgs-24.05-darwin 2.39-52 nixos-24.05-small 2.39-52 nixos-24.11 2.40-36 nixpkgs-24.11-darwin 2.40-36 nixos-24.11-small 2.40-36 nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36
pkgs.getent nixos-24.05 2.39-52 nixpkgs-24.05-darwin 2.39-52 nixos-24.05-small 2.39-52 nixos-24.11 2.40-36 nixpkgs-24.11-darwin 2.40-36 nixos-24.11-small 2.40-36 nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36
pkgs.locale nixos-24.05 2.39-52 nixpkgs-24.05-darwin 2.39-52 nixos-24.05-small 2.39-52 nixos-24.11 2.40-36 nixpkgs-24.11-darwin 2.40-36 nixos-24.11-small 2.40-36 nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36
pkgs.mtrace Perl script used to interpret and provide human readable output of the trace log contained in the file mtracedata, whose contents were produced by mtrace(3) nixos-24.05 2.39-52 nixpkgs-24.05-darwin 2.39-52 nixos-24.05-small 2.39-52 nixos-24.11 2.40-36 nixpkgs-24.11-darwin 2.40-36 nixos-24.11-small 2.40-36 nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36
pkgs.getconf nixos-24.05 2.39-52 nixpkgs-24.05-darwin 2.39-52 nixos-24.05-small 2.39-52 nixos-24.11 2.40-36 nixpkgs-24.11-darwin 2.40-36 nixos-24.11-small 2.40-36 nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36
pkgs.libiconv nixos-24.05 2.39 nixpkgs-24.05-darwin 2.39 nixos-24.05-small 2.39 nixos-24.11 2.40 nixpkgs-24.11-darwin 2.40 nixos-24.11-small 2.40 nixos-unstable 2.40 nixos-unstable-small 2.40 nixpkgs-unstable 2.40
pkgs.glibcInfo GNU Info manual of the GNU C Library nixos-24.05 2.39-52 nixpkgs-24.05-darwin 2.39-52 nixos-24.05-small 2.39-52 nixos-24.11 2.40-36 nixpkgs-24.11-darwin 2.40-36 nixos-24.11-small 2.40-36 nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36
pkgs.glibc_multi nixos-24.05 2.39-52 nixpkgs-24.05-darwin 2.39-52 nixos-24.05-small 2.39-52 nixos-24.11 2.40-36 nixpkgs-24.11-darwin 2.40-36 nixos-24.11-small 2.40-36 nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36
pkgs.glibcLocales Locale information for the GNU C Library nixos-24.05 2.39-52 nixpkgs-24.05-darwin 2.39-52 nixos-24.05-small 2.39-52 nixos-24.11 2.40-36 nixpkgs-24.11-darwin 2.40-36 nixos-24.11-small 2.40-36 nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36
pkgs.glibc_memusage GNU C Library nixos-24.05 2.39-52 nixpkgs-24.05-darwin 2.39-52 nixos-24.05-small 2.39-52 nixos-24.11 2.40-36 nixpkgs-24.11-darwin 2.40-36 nixos-24.11-small 2.40-36 nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36
pkgs.glibcLocalesUtf8 Locale information for the GNU C Library nixos-24.05 2.39-52 nixpkgs-24.05-darwin 2.39-52 nixos-24.05-small 2.39-52 nixos-24.11 2.40-36 nixpkgs-24.11-darwin 2.40-36 nixos-24.11-small 2.40-36 nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36
pkgs.unixtools.getent nixos-24.05 2.39-52 nixpkgs-24.05-darwin 2.39-52 nixos-24.05-small 2.39-52 nixos-24.11 2.40-36 nixpkgs-24.11-darwin 2.40-36 nixos-24.11-small 2.40-36 nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36
pkgs.unixtools.locale nixos-24.05 2.39-52 nixpkgs-24.05-darwin 2.39-52 nixos-24.05-small 2.39-52 nixos-24.11 2.40-36 nixpkgs-24.11-darwin 2.40-36 nixos-24.11-small 2.40-36 nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36
pkgs.unixtools.getconf nixos-24.05 2.39-52 nixpkgs-24.05-darwin 2.39-52 nixos-24.05-small 2.39-52 nixos-24.11 2.40-36 nixpkgs-24.11-darwin 2.40-36 nixos-24.11-small 2.40-36 nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36
CVE-2024-22029 7.8 HIGH CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH updated 2 months ago by @fricklerhandwerk Activity log Created automatic suggestion 2 months, 1 week ago @fricklerhandwerk removed 3 packages pkgs.tomcat_connectors 1.2.48 pkgs.apachetomcatscanner 3.5 pkgs.apachetomcatscanner 3.7.2 2 months ago tomcat packaging allows for escalation to root from tomcat user Insecure permissions in the packaging of tomcat allow local users that win a race during package installation to escalate to root tomcat <9.0.85-150200.57.1 <9.0.85-3.1 pkgs.tomcat9 Implementation of the Java Servlet and JavaServer Pages technologies nixos-24.05 9.0.88 nixpkgs-24.05-darwin 9.0.88 nixos-24.05-small 9.0.88 nixos-24.11 9.0.95 nixpkgs-24.11-darwin 9.0.95 nixos-24.11-small 9.0.95 nixos-unstable 9.0.97 nixos-unstable-small 9.0.97 nixpkgs-unstable 9.0.97 pkgs.tomcat10 Implementation of the Java Servlet and JavaServer Pages technologies nixos-24.05 10.1.23 nixpkgs-24.05-darwin 10.1.23 nixos-24.05-small 10.1.23 nixos-24.11 10.1.30 nixpkgs-24.11-darwin 10.1.30 nixos-24.11-small 10.1.30 nixos-unstable 10.1.33 nixos-unstable-small 10.1.33 nixpkgs-unstable 10.1.33 pkgs.tomcat11 Implementation of the Java Servlet and JavaServer Pages technologies nixos-24.11 11.0.0 nixpkgs-24.11-darwin 11.0.0 nixos-24.11-small 11.0.0 nixos-unstable 11.0.0 nixos-unstable-small 11.0.0 nixpkgs-unstable 11.0.0 pkgs.tomcat-native Optional component for use with Apache Tomcat that allows Tomcat to use certain native resources for performance, compatibility, etc nixos-24.05 2.0.7 nixpkgs-24.05-darwin 2.0.7 nixos-24.05-small 2.0.7 nixos-24.11 2.0.8 nixpkgs-24.11-darwin 2.0.8 nixos-24.11-small 2.0.8 nixos-unstable 2.0.8 nixos-unstable-small 2.0.8 nixpkgs-unstable 2.0.8 pkgs.tomcat_mysql_jdbc nixos-24.05 8.3.0 nixpkgs-24.05-darwin 8.3.0 nixos-24.05-small 8.3.0 nixos-24.11 9.0.0 nixpkgs-24.11-darwin 9.0.0 nixos-24.11-small 9.0.0 nixos-unstable 9.1.0 nixos-unstable-small 9.1.0 nixpkgs-unstable 9.1.0 Notify package maintainers: 2 @anthonyroussel Anthony Roussel <anthony@roussel.dev> @aanderse Aaron Andersen <aaron@fosslib.net>
pkgs.tomcat9 Implementation of the Java Servlet and JavaServer Pages technologies nixos-24.05 9.0.88 nixpkgs-24.05-darwin 9.0.88 nixos-24.05-small 9.0.88 nixos-24.11 9.0.95 nixpkgs-24.11-darwin 9.0.95 nixos-24.11-small 9.0.95 nixos-unstable 9.0.97 nixos-unstable-small 9.0.97 nixpkgs-unstable 9.0.97
pkgs.tomcat10 Implementation of the Java Servlet and JavaServer Pages technologies nixos-24.05 10.1.23 nixpkgs-24.05-darwin 10.1.23 nixos-24.05-small 10.1.23 nixos-24.11 10.1.30 nixpkgs-24.11-darwin 10.1.30 nixos-24.11-small 10.1.30 nixos-unstable 10.1.33 nixos-unstable-small 10.1.33 nixpkgs-unstable 10.1.33
pkgs.tomcat11 Implementation of the Java Servlet and JavaServer Pages technologies nixos-24.11 11.0.0 nixpkgs-24.11-darwin 11.0.0 nixos-24.11-small 11.0.0 nixos-unstable 11.0.0 nixos-unstable-small 11.0.0 nixpkgs-unstable 11.0.0
pkgs.tomcat-native Optional component for use with Apache Tomcat that allows Tomcat to use certain native resources for performance, compatibility, etc nixos-24.05 2.0.7 nixpkgs-24.05-darwin 2.0.7 nixos-24.05-small 2.0.7 nixos-24.11 2.0.8 nixpkgs-24.11-darwin 2.0.8 nixos-24.11-small 2.0.8 nixos-unstable 2.0.8 nixos-unstable-small 2.0.8 nixpkgs-unstable 2.0.8
pkgs.tomcat_mysql_jdbc nixos-24.05 8.3.0 nixpkgs-24.05-darwin 8.3.0 nixos-24.05-small 8.3.0 nixos-24.11 9.0.0 nixpkgs-24.11-darwin 9.0.0 nixos-24.11-small 9.0.0 nixos-unstable 9.1.0 nixos-unstable-small 9.1.0 nixpkgs-unstable 9.1.0
CVE-2023-46846 9.3 CRITICAL CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): CHANGED Confidentiality impact (C): HIGH Integrity impact (I): LOW Availability impact (A): NONE updated 2 months ago by @fricklerhandwerk Activity log Created automatic suggestion 2 months, 1 week ago @fricklerhandwerk removed 3 packages pkgs.prometheus-squid-exporter 1.12.0 pkgs.python311Packages.flyingsquid 0.0.0a0 pkgs.python312Packages.flyingsquid 0.0.0a0 2 months ago Squid: request/response smuggling in http/1.1 and icap SQUID is vulnerable to HTTP request smuggling, caused by chunked decoder lenience, allows a remote attacker to perform Request/Response smuggling past firewall and frontend security systems. squid * <6.4 squid34 squid:4 * pkgs.squid Caching proxy for the Web supporting HTTP, HTTPS, FTP, and more nixos-24.05 6.8 nixpkgs-24.05-darwin 6.8 nixos-24.05-small 6.8 nixos-24.11 6.10 nixpkgs-24.11-darwin 6.10 nixos-24.11-small 6.10 nixos-unstable 6.10 nixos-unstable-small 6.10 nixpkgs-unstable 6.10 Notify package maintainers: 1 @7c6f434c Michael Raskin <7c6f434c@mail.ru>
pkgs.squid Caching proxy for the Web supporting HTTP, HTTPS, FTP, and more nixos-24.05 6.8 nixpkgs-24.05-darwin 6.8 nixos-24.05-small 6.8 nixos-24.11 6.10 nixpkgs-24.11-darwin 6.10 nixos-24.11-small 6.10 nixos-unstable 6.10 nixos-unstable-small 6.10 nixpkgs-unstable 6.10