Dismissed suggestions Untriaged suggestions Draft issues Published issues Automatically generated suggestions Create Draft to queue a suggestion for refinement. Dismiss to remove a suggestion from the queue. CVE-2025-58993 7.6 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): HIGH User interaction (UI): NONE Scope (S): CHANGED Confidentiality impact (C): HIGH Integrity impact (I): NONE Availability impact (A): LOW created 1 month, 1 week ago WordPress Tutor LMS Plugin <= 3.7.4 - SQL Injection Vulnerability Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS allows SQL Injection. This issue affects Tutor LMS: from n/a through 3.7.4. tutor =<3.7.4 pkgs.typstPackages.tutor_0_3_0 Utilities to create exams nixos-unstable ??? nixpkgs-unstable 0.3.0 pkgs.typstPackages.tutor_0_4_0 Utilities to create exams nixos-unstable ??? nixpkgs-unstable 0.4.0 pkgs.typstPackages.tutor_0_6_1 Utilities to create exams nixos-unstable ??? nixpkgs-unstable 0.6.1 pkgs.typstPackages.tutor_0_7_0 Utilities to create exams nixos-unstable ??? nixpkgs-unstable 0.7.0 pkgs.typstPackages.tutor_0_8_0 Utilities to create exams nixos-unstable ??? nixpkgs-unstable 0.8.0 pkgs.haskellPackages.timeless-tutorials Initial project template from stack nixos-unstable ??? nixpkgs-unstable 1.0.0.0 Package maintainers: 1 @cherrypiejam Gongqi Huang CVE-2025-8277 3.1 LOW CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): LOW created 1 month, 1 week ago Libssh: memory exhaustion via repeated key exchange in libssh A flaw was found in libssh's handling of key exchange (KEX) processes when a client repeatedly sends incorrect KEX guesses. The library fails to free memory during these rekey operations, which can gradually exhaust system memory. This issue can lead to crashes on the client side, particularly when using libgcrypt, which impacts application stability and availability. rhcos libssh libssh2 pkgs.libssh SSH client library nixos-unstable ??? nixpkgs-unstable 0.11.2 pkgs.libssh2 Client-side C library implementing the SSH2 protocol nixos-unstable ??? nixpkgs-unstable 1.11.1 pkgs.haskellPackages.libssh libssh bindings nixos-unstable ??? nixpkgs-unstable 0.1.0.0 pkgs.python312Packages.ansible-pylibssh Python bindings to client functionality of libssh specific to Ansible use case nixos-unstable ??? nixpkgs-unstable 1.2.2 pkgs.python313Packages.ansible-pylibssh Python bindings to client functionality of libssh specific to Ansible use case nixos-unstable ??? nixpkgs-unstable 1.2.2 pkgs.tests.pkg-config.defaultPkgConfigPackages.libssh2 Test whether libssh2-1.11.1 exposes pkg-config modules libssh2 nixos-unstable ??? nixpkgs-unstable libssh2 Package maintainers: 3 @geluk Johan Geluk <johan+nix@geluk.io> @svanderburg Sander van der Burg <s.vanderburg@tudelft.nl> @SuperSandro2000 Sandro Jäckel <sandro.jaeckel@gmail.com> CVE-2025-40928 7.5 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): HIGH created 1 month, 1 week ago JSON::XS before version 4.04 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other unspecified impact JSON::XS before version 4.04 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other unspecified impact JSON-XS <4.04 pkgs.perlPackages.JSONXS JSON serialising/deserialising, done correctly and fast nixos-unstable ??? nixpkgs-unstable 4.03 pkgs.perl538Packages.JSONXS JSON serialising/deserialising, done correctly and fast nixos-unstable ??? nixpkgs-unstable 4.03 pkgs.perl540Packages.JSONXS JSON serialising/deserialising, done correctly and fast nixos-unstable ??? nixpkgs-unstable 4.03 pkgs.perlPackages.CpanelJSONXS CPanel fork of JSON::XS, fast and correct serializing nixos-unstable ??? nixpkgs-unstable 4.37 pkgs.perl538Packages.CpanelJSONXS CPanel fork of JSON::XS, fast and correct serializing nixos-unstable ??? nixpkgs-unstable 4.37 pkgs.perl540Packages.CpanelJSONXS CPanel fork of JSON::XS, fast and correct serializing nixos-unstable ??? nixpkgs-unstable 4.37 pkgs.perlPackages.JSONXSVersionOneAndTwo Support versions 1 and 2 of JSON::XS nixos-unstable ??? nixpkgs-unstable 0.31 pkgs.perl538Packages.JSONXSVersionOneAndTwo Support versions 1 and 2 of JSON::XS nixos-unstable ??? nixpkgs-unstable 0.31 pkgs.perl540Packages.JSONXSVersionOneAndTwo Support versions 1 and 2 of JSON::XS nixos-unstable ??? nixpkgs-unstable 0.31 CVE-2025-40929 5.6 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 1 month, 1 week ago Cpanel::JSON::XS before version 4.40 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other unspecified impact Cpanel::JSON::XS before version 4.40 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other unspecified impact Cpanel-JSON-XS <4.40 pkgs.perlPackages.CpanelJSONXS CPanel fork of JSON::XS, fast and correct serializing nixos-unstable ??? nixpkgs-unstable 4.37 pkgs.perl538Packages.CpanelJSONXS CPanel fork of JSON::XS, fast and correct serializing nixos-unstable ??? nixpkgs-unstable 4.37 pkgs.perl540Packages.CpanelJSONXS CPanel fork of JSON::XS, fast and correct serializing nixos-unstable ??? nixpkgs-unstable 4.37 CVE-2025-58822 6.5 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): REQUIRED Scope (S): CHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 1 month, 1 week ago WordPress WP Mail Plugin <= 1.3 - Cross Site Scripting (XSS) Vulnerability Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mndpsingh287 WP Mail allows DOM-Based XSS. This issue affects WP Mail: from n/a through 1.3. wp-mail =<1.3 pkgs.wordpressPackages.plugins.wp-mail-smtp nixos-unstable ??? nixpkgs-unstable 4.4.0 CVE-2025-58806 7.1 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): CHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 1 month, 1 week ago WordPress WordPress Error Monitoring by Bugsnag Plugin <= 1.6.3 - Cross Site Request Forgery (CSRF) Vulnerability Cross-Site Request Forgery (CSRF) vulnerability in imjoehaines WordPress Error Monitoring by Bugsnag allows Stored XSS. This issue affects WordPress Error Monitoring by Bugsnag: from n/a through 1.6.3. bugsnag =<1.6.3 pkgs.haskellPackages.bugsnag Bugsnag error reporter for Haskell nixos-unstable ??? nixpkgs-unstable 1.1.0.2 pkgs.python312Packages.bugsnag Automatic error monitoring for Python applications nixos-unstable ??? nixpkgs-unstable 4.8.0 pkgs.python313Packages.bugsnag Automatic error monitoring for Python applications nixos-unstable ??? nixpkgs-unstable 4.8.0 pkgs.haskellPackages.bugsnag-hs A Bugsnag client for Haskell nixos-unstable ??? nixpkgs-unstable 0.2.0.12 pkgs.haskellPackages.bugsnag-wai WAI integration for Bugsnag error reporting for Haskell nixos-unstable ??? nixpkgs-unstable 1.0.1.1 pkgs.haskellPackages.bugsnag-yesod Yesod integration for Bugsnag error reporting for Haskell nixos-unstable ??? nixpkgs-unstable 1.0.1.0 CVE-2025-10044 4.3 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): LOW Availability impact (A): NONE created 1 month, 1 week ago Keycloak: keycloak error_description injection on error pages A flaw was found in Keycloak. Keycloak’s account console and other pages accept arbitrary text in the error_description query parameter. This text is directly rendered in error pages without validation or sanitization. While HTML encoding prevents XSS, an attacker can craft URLs with misleading messages (e.g., fake support phone numbers or URLs), which are displayed within the trusted Keycloak UI. This creates a phishing vector, potentially tricking users into contacting malicious actors. keycloak pkgs.keycloak Identity and access management for modern applications and services nixos-unstable ??? nixpkgs-unstable 26.3.4 pkgs.terraform-providers.keycloak nixos-unstable ??? nixpkgs-unstable 5.4.0 pkgs.python312Packages.python-keycloak Provides access to the Keycloak API nixos-unstable ??? nixpkgs-unstable 4.0.0 pkgs.python313Packages.python-keycloak Provides access to the Keycloak API nixos-unstable ??? nixpkgs-unstable 4.0.0 Package maintainers: 4 @talyz Kim Lindberger <kim.lindberger@gmail.com> @ngerstle Nicholas Gerstle <ngerstle@gmail.com> @leona-ya Leona Maroni <nix@leona.is> @NickCao Nick Cao <nickcao@nichi.co> CVE-2025-58820 5.9 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): HIGH User interaction (UI): REQUIRED Scope (S): CHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 1 month, 1 week ago WordPress Carousel Ultimate Plugin <= 1.8 - Cross Site Scripting (XSS) Vulnerability Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themepoints Carousel Ultimate allows Stored XSS. This issue affects Carousel Ultimate: from n/a through 1.8. carousel =<1.8 pkgs.haskellPackages.data-carousel A rotating sequence data structure nixos-unstable ??? nixpkgs-unstable 0.1.0.0 CVE-2025-58801 5.4 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): LOW Availability impact (A): LOW created 1 month, 1 week ago WordPress Responder Plugin <= 4.3.8 - Cross Site Request Forgery (CSRF) Vulnerability Cross-Site Request Forgery (CSRF) vulnerability in KCS Responder allows Cross Site Request Forgery. This issue affects Responder: from n/a through 4.3.8. responder =<4.3.8 pkgs.responder LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server nixos-unstable ??? nixpkgs-unstable 3.1.7.0 Package maintainers: 1 @fabaff Fabian Affolter <mail@fabian-affolter.ch> CVE-2025-9566 8.1 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): HIGH Availability impact (A): HIGH created 1 month, 1 week ago Podman: podman kube play command may overwrite host files There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file container a Secrete or a ConfigMap volume mount and such volume contains a symbolic link to a host file path. In a successful attack, the attacker can only control the target file to be overwritten but not the content to be written into the file. Binary-Affected: podman Upstream-version-introduced: v4.0.0 Upstream-version-fixed: v5.6.1 rhcos podman * devspaces/udi-rhel9 container-tools:rhel8 * devspaces/udi-base-rhel9 container-tools:rhel8/podman pkgs.podman Program for managing pods, containers and container images nixos-unstable ??? nixpkgs-unstable 5.6.1 pkgs.podman-tui Podman Terminal UI nixos-unstable ??? nixpkgs-unstable 1.8.0 pkgs.podman-bootc Streamlining podman+bootc interactions nixos-unstable ??? nixpkgs-unstable 0.1.2 pkgs.podman-compose Implementation of docker-compose with podman backend nixos-unstable ??? nixpkgs-unstable 1.5.0 pkgs.podman-desktop Graphical tool for developing on containers and Kubernetes nixos-unstable ??? nixpkgs-unstable 1.21.0 pkgs.nomad-driver-podman Podman task driver for Nomad nixos-unstable ??? nixpkgs-unstable 0.6.3 pkgs.python312Packages.podman Python bindings for Podman's RESTful API nixos-unstable ??? nixpkgs-unstable 5.6.0 pkgs.python313Packages.podman Python bindings for Podman's RESTful API nixos-unstable ??? nixpkgs-unstable 5.6.0 Package maintainers: 8 @fabaff Fabian Affolter <mail@fabian-affolter.ch> @booxter Ihar Hrachyshka <ihar.hrachyshka@gmail.com> @cpcloud Phillip Cloud @vdemeester Vincent Demeester <vincent@sbr.pm> @saschagrunert Sascha Grunert <mail@saschagrunert.de> @evan-goode Evan Goode <mail@evangoo.de> @sikmir Nikolay Korotkiy <sikmir@disroot.org> @aaronjheng Aaron Jheng <wentworth@outlook.com>
CVE-2025-58993 7.6 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): HIGH User interaction (UI): NONE Scope (S): CHANGED Confidentiality impact (C): HIGH Integrity impact (I): NONE Availability impact (A): LOW created 1 month, 1 week ago WordPress Tutor LMS Plugin <= 3.7.4 - SQL Injection Vulnerability Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS allows SQL Injection. This issue affects Tutor LMS: from n/a through 3.7.4. tutor =<3.7.4 pkgs.typstPackages.tutor_0_3_0 Utilities to create exams nixos-unstable ??? nixpkgs-unstable 0.3.0 pkgs.typstPackages.tutor_0_4_0 Utilities to create exams nixos-unstable ??? nixpkgs-unstable 0.4.0 pkgs.typstPackages.tutor_0_6_1 Utilities to create exams nixos-unstable ??? nixpkgs-unstable 0.6.1 pkgs.typstPackages.tutor_0_7_0 Utilities to create exams nixos-unstable ??? nixpkgs-unstable 0.7.0 pkgs.typstPackages.tutor_0_8_0 Utilities to create exams nixos-unstable ??? nixpkgs-unstable 0.8.0 pkgs.haskellPackages.timeless-tutorials Initial project template from stack nixos-unstable ??? nixpkgs-unstable 1.0.0.0 Package maintainers: 1 @cherrypiejam Gongqi Huang
pkgs.haskellPackages.timeless-tutorials Initial project template from stack nixos-unstable ??? nixpkgs-unstable 1.0.0.0
CVE-2025-8277 3.1 LOW CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): LOW created 1 month, 1 week ago Libssh: memory exhaustion via repeated key exchange in libssh A flaw was found in libssh's handling of key exchange (KEX) processes when a client repeatedly sends incorrect KEX guesses. The library fails to free memory during these rekey operations, which can gradually exhaust system memory. This issue can lead to crashes on the client side, particularly when using libgcrypt, which impacts application stability and availability. rhcos libssh libssh2 pkgs.libssh SSH client library nixos-unstable ??? nixpkgs-unstable 0.11.2 pkgs.libssh2 Client-side C library implementing the SSH2 protocol nixos-unstable ??? nixpkgs-unstable 1.11.1 pkgs.haskellPackages.libssh libssh bindings nixos-unstable ??? nixpkgs-unstable 0.1.0.0 pkgs.python312Packages.ansible-pylibssh Python bindings to client functionality of libssh specific to Ansible use case nixos-unstable ??? nixpkgs-unstable 1.2.2 pkgs.python313Packages.ansible-pylibssh Python bindings to client functionality of libssh specific to Ansible use case nixos-unstable ??? nixpkgs-unstable 1.2.2 pkgs.tests.pkg-config.defaultPkgConfigPackages.libssh2 Test whether libssh2-1.11.1 exposes pkg-config modules libssh2 nixos-unstable ??? nixpkgs-unstable libssh2 Package maintainers: 3 @geluk Johan Geluk <johan+nix@geluk.io> @svanderburg Sander van der Burg <s.vanderburg@tudelft.nl> @SuperSandro2000 Sandro Jäckel <sandro.jaeckel@gmail.com>
pkgs.libssh2 Client-side C library implementing the SSH2 protocol nixos-unstable ??? nixpkgs-unstable 1.11.1
pkgs.python312Packages.ansible-pylibssh Python bindings to client functionality of libssh specific to Ansible use case nixos-unstable ??? nixpkgs-unstable 1.2.2
pkgs.python313Packages.ansible-pylibssh Python bindings to client functionality of libssh specific to Ansible use case nixos-unstable ??? nixpkgs-unstable 1.2.2
pkgs.tests.pkg-config.defaultPkgConfigPackages.libssh2 Test whether libssh2-1.11.1 exposes pkg-config modules libssh2 nixos-unstable ??? nixpkgs-unstable libssh2
CVE-2025-40928 7.5 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): HIGH created 1 month, 1 week ago JSON::XS before version 4.04 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other unspecified impact JSON::XS before version 4.04 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other unspecified impact JSON-XS <4.04 pkgs.perlPackages.JSONXS JSON serialising/deserialising, done correctly and fast nixos-unstable ??? nixpkgs-unstable 4.03 pkgs.perl538Packages.JSONXS JSON serialising/deserialising, done correctly and fast nixos-unstable ??? nixpkgs-unstable 4.03 pkgs.perl540Packages.JSONXS JSON serialising/deserialising, done correctly and fast nixos-unstable ??? nixpkgs-unstable 4.03 pkgs.perlPackages.CpanelJSONXS CPanel fork of JSON::XS, fast and correct serializing nixos-unstable ??? nixpkgs-unstable 4.37 pkgs.perl538Packages.CpanelJSONXS CPanel fork of JSON::XS, fast and correct serializing nixos-unstable ??? nixpkgs-unstable 4.37 pkgs.perl540Packages.CpanelJSONXS CPanel fork of JSON::XS, fast and correct serializing nixos-unstable ??? nixpkgs-unstable 4.37 pkgs.perlPackages.JSONXSVersionOneAndTwo Support versions 1 and 2 of JSON::XS nixos-unstable ??? nixpkgs-unstable 0.31 pkgs.perl538Packages.JSONXSVersionOneAndTwo Support versions 1 and 2 of JSON::XS nixos-unstable ??? nixpkgs-unstable 0.31 pkgs.perl540Packages.JSONXSVersionOneAndTwo Support versions 1 and 2 of JSON::XS nixos-unstable ??? nixpkgs-unstable 0.31
pkgs.perlPackages.JSONXS JSON serialising/deserialising, done correctly and fast nixos-unstable ??? nixpkgs-unstable 4.03
pkgs.perl538Packages.JSONXS JSON serialising/deserialising, done correctly and fast nixos-unstable ??? nixpkgs-unstable 4.03
pkgs.perl540Packages.JSONXS JSON serialising/deserialising, done correctly and fast nixos-unstable ??? nixpkgs-unstable 4.03
pkgs.perlPackages.CpanelJSONXS CPanel fork of JSON::XS, fast and correct serializing nixos-unstable ??? nixpkgs-unstable 4.37
pkgs.perl538Packages.CpanelJSONXS CPanel fork of JSON::XS, fast and correct serializing nixos-unstable ??? nixpkgs-unstable 4.37
pkgs.perl540Packages.CpanelJSONXS CPanel fork of JSON::XS, fast and correct serializing nixos-unstable ??? nixpkgs-unstable 4.37
pkgs.perlPackages.JSONXSVersionOneAndTwo Support versions 1 and 2 of JSON::XS nixos-unstable ??? nixpkgs-unstable 0.31
pkgs.perl538Packages.JSONXSVersionOneAndTwo Support versions 1 and 2 of JSON::XS nixos-unstable ??? nixpkgs-unstable 0.31
pkgs.perl540Packages.JSONXSVersionOneAndTwo Support versions 1 and 2 of JSON::XS nixos-unstable ??? nixpkgs-unstable 0.31
CVE-2025-40929 5.6 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 1 month, 1 week ago Cpanel::JSON::XS before version 4.40 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other unspecified impact Cpanel::JSON::XS before version 4.40 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other unspecified impact Cpanel-JSON-XS <4.40 pkgs.perlPackages.CpanelJSONXS CPanel fork of JSON::XS, fast and correct serializing nixos-unstable ??? nixpkgs-unstable 4.37 pkgs.perl538Packages.CpanelJSONXS CPanel fork of JSON::XS, fast and correct serializing nixos-unstable ??? nixpkgs-unstable 4.37 pkgs.perl540Packages.CpanelJSONXS CPanel fork of JSON::XS, fast and correct serializing nixos-unstable ??? nixpkgs-unstable 4.37
pkgs.perlPackages.CpanelJSONXS CPanel fork of JSON::XS, fast and correct serializing nixos-unstable ??? nixpkgs-unstable 4.37
pkgs.perl538Packages.CpanelJSONXS CPanel fork of JSON::XS, fast and correct serializing nixos-unstable ??? nixpkgs-unstable 4.37
pkgs.perl540Packages.CpanelJSONXS CPanel fork of JSON::XS, fast and correct serializing nixos-unstable ??? nixpkgs-unstable 4.37
CVE-2025-58822 6.5 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): REQUIRED Scope (S): CHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 1 month, 1 week ago WordPress WP Mail Plugin <= 1.3 - Cross Site Scripting (XSS) Vulnerability Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mndpsingh287 WP Mail allows DOM-Based XSS. This issue affects WP Mail: from n/a through 1.3. wp-mail =<1.3 pkgs.wordpressPackages.plugins.wp-mail-smtp nixos-unstable ??? nixpkgs-unstable 4.4.0
CVE-2025-58806 7.1 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): CHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 1 month, 1 week ago WordPress WordPress Error Monitoring by Bugsnag Plugin <= 1.6.3 - Cross Site Request Forgery (CSRF) Vulnerability Cross-Site Request Forgery (CSRF) vulnerability in imjoehaines WordPress Error Monitoring by Bugsnag allows Stored XSS. This issue affects WordPress Error Monitoring by Bugsnag: from n/a through 1.6.3. bugsnag =<1.6.3 pkgs.haskellPackages.bugsnag Bugsnag error reporter for Haskell nixos-unstable ??? nixpkgs-unstable 1.1.0.2 pkgs.python312Packages.bugsnag Automatic error monitoring for Python applications nixos-unstable ??? nixpkgs-unstable 4.8.0 pkgs.python313Packages.bugsnag Automatic error monitoring for Python applications nixos-unstable ??? nixpkgs-unstable 4.8.0 pkgs.haskellPackages.bugsnag-hs A Bugsnag client for Haskell nixos-unstable ??? nixpkgs-unstable 0.2.0.12 pkgs.haskellPackages.bugsnag-wai WAI integration for Bugsnag error reporting for Haskell nixos-unstable ??? nixpkgs-unstable 1.0.1.1 pkgs.haskellPackages.bugsnag-yesod Yesod integration for Bugsnag error reporting for Haskell nixos-unstable ??? nixpkgs-unstable 1.0.1.0
pkgs.haskellPackages.bugsnag Bugsnag error reporter for Haskell nixos-unstable ??? nixpkgs-unstable 1.1.0.2
pkgs.python312Packages.bugsnag Automatic error monitoring for Python applications nixos-unstable ??? nixpkgs-unstable 4.8.0
pkgs.python313Packages.bugsnag Automatic error monitoring for Python applications nixos-unstable ??? nixpkgs-unstable 4.8.0
pkgs.haskellPackages.bugsnag-hs A Bugsnag client for Haskell nixos-unstable ??? nixpkgs-unstable 0.2.0.12
pkgs.haskellPackages.bugsnag-wai WAI integration for Bugsnag error reporting for Haskell nixos-unstable ??? nixpkgs-unstable 1.0.1.1
pkgs.haskellPackages.bugsnag-yesod Yesod integration for Bugsnag error reporting for Haskell nixos-unstable ??? nixpkgs-unstable 1.0.1.0
CVE-2025-10044 4.3 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): LOW Availability impact (A): NONE created 1 month, 1 week ago Keycloak: keycloak error_description injection on error pages A flaw was found in Keycloak. Keycloak’s account console and other pages accept arbitrary text in the error_description query parameter. This text is directly rendered in error pages without validation or sanitization. While HTML encoding prevents XSS, an attacker can craft URLs with misleading messages (e.g., fake support phone numbers or URLs), which are displayed within the trusted Keycloak UI. This creates a phishing vector, potentially tricking users into contacting malicious actors. keycloak pkgs.keycloak Identity and access management for modern applications and services nixos-unstable ??? nixpkgs-unstable 26.3.4 pkgs.terraform-providers.keycloak nixos-unstable ??? nixpkgs-unstable 5.4.0 pkgs.python312Packages.python-keycloak Provides access to the Keycloak API nixos-unstable ??? nixpkgs-unstable 4.0.0 pkgs.python313Packages.python-keycloak Provides access to the Keycloak API nixos-unstable ??? nixpkgs-unstable 4.0.0 Package maintainers: 4 @talyz Kim Lindberger <kim.lindberger@gmail.com> @ngerstle Nicholas Gerstle <ngerstle@gmail.com> @leona-ya Leona Maroni <nix@leona.is> @NickCao Nick Cao <nickcao@nichi.co>
pkgs.keycloak Identity and access management for modern applications and services nixos-unstable ??? nixpkgs-unstable 26.3.4
pkgs.python312Packages.python-keycloak Provides access to the Keycloak API nixos-unstable ??? nixpkgs-unstable 4.0.0
pkgs.python313Packages.python-keycloak Provides access to the Keycloak API nixos-unstable ??? nixpkgs-unstable 4.0.0
CVE-2025-58820 5.9 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): HIGH User interaction (UI): REQUIRED Scope (S): CHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 1 month, 1 week ago WordPress Carousel Ultimate Plugin <= 1.8 - Cross Site Scripting (XSS) Vulnerability Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themepoints Carousel Ultimate allows Stored XSS. This issue affects Carousel Ultimate: from n/a through 1.8. carousel =<1.8 pkgs.haskellPackages.data-carousel A rotating sequence data structure nixos-unstable ??? nixpkgs-unstable 0.1.0.0
pkgs.haskellPackages.data-carousel A rotating sequence data structure nixos-unstable ??? nixpkgs-unstable 0.1.0.0
CVE-2025-58801 5.4 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): LOW Availability impact (A): LOW created 1 month, 1 week ago WordPress Responder Plugin <= 4.3.8 - Cross Site Request Forgery (CSRF) Vulnerability Cross-Site Request Forgery (CSRF) vulnerability in KCS Responder allows Cross Site Request Forgery. This issue affects Responder: from n/a through 4.3.8. responder =<4.3.8 pkgs.responder LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server nixos-unstable ??? nixpkgs-unstable 3.1.7.0 Package maintainers: 1 @fabaff Fabian Affolter <mail@fabian-affolter.ch>
pkgs.responder LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server nixos-unstable ??? nixpkgs-unstable 3.1.7.0
CVE-2025-9566 8.1 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): HIGH Availability impact (A): HIGH created 1 month, 1 week ago Podman: podman kube play command may overwrite host files There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file container a Secrete or a ConfigMap volume mount and such volume contains a symbolic link to a host file path. In a successful attack, the attacker can only control the target file to be overwritten but not the content to be written into the file. Binary-Affected: podman Upstream-version-introduced: v4.0.0 Upstream-version-fixed: v5.6.1 rhcos podman * devspaces/udi-rhel9 container-tools:rhel8 * devspaces/udi-base-rhel9 container-tools:rhel8/podman pkgs.podman Program for managing pods, containers and container images nixos-unstable ??? nixpkgs-unstable 5.6.1 pkgs.podman-tui Podman Terminal UI nixos-unstable ??? nixpkgs-unstable 1.8.0 pkgs.podman-bootc Streamlining podman+bootc interactions nixos-unstable ??? nixpkgs-unstable 0.1.2 pkgs.podman-compose Implementation of docker-compose with podman backend nixos-unstable ??? nixpkgs-unstable 1.5.0 pkgs.podman-desktop Graphical tool for developing on containers and Kubernetes nixos-unstable ??? nixpkgs-unstable 1.21.0 pkgs.nomad-driver-podman Podman task driver for Nomad nixos-unstable ??? nixpkgs-unstable 0.6.3 pkgs.python312Packages.podman Python bindings for Podman's RESTful API nixos-unstable ??? nixpkgs-unstable 5.6.0 pkgs.python313Packages.podman Python bindings for Podman's RESTful API nixos-unstable ??? nixpkgs-unstable 5.6.0 Package maintainers: 8 @fabaff Fabian Affolter <mail@fabian-affolter.ch> @booxter Ihar Hrachyshka <ihar.hrachyshka@gmail.com> @cpcloud Phillip Cloud @vdemeester Vincent Demeester <vincent@sbr.pm> @saschagrunert Sascha Grunert <mail@saschagrunert.de> @evan-goode Evan Goode <mail@evangoo.de> @sikmir Nikolay Korotkiy <sikmir@disroot.org> @aaronjheng Aaron Jheng <wentworth@outlook.com>
pkgs.podman Program for managing pods, containers and container images nixos-unstable ??? nixpkgs-unstable 5.6.1
pkgs.podman-compose Implementation of docker-compose with podman backend nixos-unstable ??? nixpkgs-unstable 1.5.0
pkgs.podman-desktop Graphical tool for developing on containers and Kubernetes nixos-unstable ??? nixpkgs-unstable 1.21.0
pkgs.python312Packages.podman Python bindings for Podman's RESTful API nixos-unstable ??? nixpkgs-unstable 5.6.0
pkgs.python313Packages.podman Python bindings for Podman's RESTful API nixos-unstable ??? nixpkgs-unstable 5.6.0