Nixpkgs Security Tracker

Login with GitHub

Automatically generated suggestions

to queue a suggestion for refinement.

to remove a suggestion from the queue.

created 4 months ago
WordPress Document Management System <= 1.24 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in reifsnyderb Document Management System allows Reflected XSS. This issue affects Document Management System: from n/a through 1.24.

Affected products

dms
  • =<1.24

Matching in nixpkgs

pkgs.dms

UPnP DLNA Digital Media Server with basic video transcoding

  • nixos-unstable -

pkgs.adms

Automatic device model synthesizer

  • nixos-unstable -

pkgs.dmsdos

Linux utilities to handle dos/win95 doublespace/drivespace/stacker

pkgs.python312Packages.dmsuite

Scientific library providing a collection of spectral collocation differentiation matrices

  • nixos-unstable -

pkgs.python313Packages.dmsuite

Scientific library providing a collection of spectral collocation differentiation matrices

  • nixos-unstable -

pkgs.haskellPackages.amazonka-dms

Amazon Database Migration Service SDK

  • nixos-unstable -

pkgs.python312Packages.ndms2-client

Keenetic NDMS 2.x and 3.x client

pkgs.python313Packages.ndms2-client

Keenetic NDMS 2.x and 3.x client

pkgs.azure-cli-extensions.dms-preview

Support for new Database Migration Service scenarios

  • nixos-unstable -

pkgs.python312Packages.mypy-boto3-dms

Type annotations for boto3 dms

pkgs.python313Packages.mypy-boto3-dms

Type annotations for boto3 dms

pkgs.home-assistant-component-tests.dlna_dms

Open source home automation that puts local control and privacy first

pkgs.python312Packages.types-aiobotocore-dms

Type annotations for aiobotocore dms

  • nixos-unstable -

pkgs.python313Packages.types-aiobotocore-dms

Type annotations for aiobotocore dms

  • nixos-unstable -

pkgs.home-assistant-component-tests.keenetic_ndms2

Open source home automation that puts local control and privacy first

Package maintainers: 10

created 4 months ago
Gnome-remote-desktop: uncontrolled resource consumption due to malformed rdp pdus

A flaw was found in gnome-remote-desktop. Once gnome-remote-desktop listens for RDP connections, an unauthenticated attacker can exhaust system resources and repeatedly crash the process. There may be a resource leak after many attacks, which will also result in gnome-remote-desktop no longer being able to open files even after it is restarted via systemd.

Affected products

gnome-remote-desktop
  • *

Matching in nixpkgs

pkgs.gnome-remote-desktop

GNOME Remote Desktop server

  • nixos-unstable -

Package maintainers: 4

created 4 months ago
Hive: exposure of vcenter credentials via clusterprovision in hive / mce / acm

A flaw was found in Hive, a component of Multicluster Engine (MCE) and Advanced Cluster Management (ACM). This vulnerability causes VCenter credentials to be exposed in the ClusterProvision object after provisioning a VSphere cluster. Users with read access to ClusterProvision objects can extract sensitive credentials even if they do not have direct access to Kubernetes Secrets. This issue can lead to unauthorized VCenter access, cluster management, and privilege escalation.

Affected products

hive
  • =<1.1.16
rhacm2/cluster-backup-rhel8-operator
rhacm2/cluster-backup-rhel9-operator
multicluster-engine/multicloud-manager-rhel8

Matching in nixpkgs

pkgs.hivex

Windows registry hive extraction library

  • nixos-unstable -

pkgs.enchive

Encrypted personal archives

  • nixos-unstable -

pkgs.archiver

Easily create & extract archives, and compress & decompress files of various formats

  • nixos-unstable -

pkgs.hivemind

Process manager for Procfile-based applications

  • nixos-unstable -

pkgs.zarchive

File archive format supporting random-access reads

  • nixos-unstable -

pkgs.xarchiver

GTK frontend to 7z,zip,rar,tar,bzip2, gzip,arj, lha, rpm and deb (open and extract only)

pkgs.ytarchive

Garbage Youtube livestream downloader

  • nixos-unstable -

pkgs.disarchive

Disassemble software into data and metadata

  • nixos-unstable -

pkgs.fsarchiver

File system archiver for linux

  • nixos-unstable -

pkgs.libarchive

Multi-format archive and compression library

  • nixos-unstable -

pkgs.tg-archive

Tool for exporting Telegram group chats into static websites like mailing list archives

  • nixos-unstable -

pkgs.archivemount

Gateway between FUSE and libarchive: allows mounting of cpio, .tar.gz, .tar.bz2 archives

  • nixos-unstable -
    • nixpkgs-unstable 1b

pkgs.fuse-archive

Serve an archive or a compressed file as a read-only FUSE file system

  • nixos-unstable -

pkgs.jpeg-archive

Utilities for archiving photos for saving to long term storage or serving over the web

  • nixos-unstable -

pkgs.web-archives

Web archives reader offering the ability to browse offline millions of articles

  • nixos-unstable -

pkgs.hivelytracker

Chip music tracker based upon the AHX format

  • nixos-unstable -

pkgs.libarchive-qt

Qt based archiving solution with libarchive backend

  • nixos-unstable -

pkgs.lparchive2epub

Transform any LP from lparchive into an epub document

  • nixos-unstable -

pkgs.the-unarchiver

Unpacks archive files

  • nixos-unstable -

pkgs.git-archive-all

Archive a repository with all its submodules

  • nixos-unstable -

pkgs.internetarchive

Python and Command-Line Interface to Archive.org

  • nixos-unstable -

pkgs.autoconf-archive

Archive of autoconf m4 macros

pkgs.guile-disarchive

Disassemble software into data and metadata

  • nixos-unstable -

pkgs.mastodon-archive

Utility for backing up your Mastodon content

  • nixos-unstable -

pkgs.mlarchive2maildir

Imports mail from (pipermail) archives into a maildir

  • nixos-unstable -

pkgs.lxqt.lxqt-archiver

Archive tool for the LXQt desktop environment

  • nixos-unstable -

pkgs.libsForQt5.karchive

pkgs.php81Packages.phive

Phar Installation and Verification Environment (PHIVE)

  • nixos-unstable -

pkgs.php82Packages.phive

Phar Installation and Verification Environment (PHIVE)

  • nixos-unstable -

pkgs.php83Packages.phive

Phar Installation and Verification Environment (PHIVE)

  • nixos-unstable -

pkgs.php84Packages.phive

Phar Installation and Verification Environment (PHIVE)

  • nixos-unstable -

pkgs.kdePackages.karchive

Qt addon providing access to numerous types of archives

  • nixos-unstable -

pkgs.CuboCore.corearchiver

Archiver from the C Suite to create and extract archives

  • nixos-unstable -

pkgs.stripJavaArchivesHook

  • nixos-unstable -
    • nixpkgs-unstable

pkgs.canonicalize-jars-hook

  • nixos-unstable -
    • nixpkgs-unstable

pkgs.perlPackages.ArchiveTar

Manipulates TAR archives

  • nixos-unstable -

pkgs.perlPackages.ArchiveCpio

Module for manipulations of cpio archives

  • nixos-unstable -

pkgs.plasma5Packages.karchive

pkgs.wayback-machine-archiver

Python script to submit web pages to the Wayback Machine for archiving

  • nixos-unstable -

pkgs.kodiPackages.archive_tool

Set of common python functions to work with the Kodi archive virtual file system (vfs) binary addons

  • nixos-unstable -

pkgs.haskellPackages.libarchive

Haskell interface to libarchive

pkgs.perl538Packages.ArchiveTar

Manipulates TAR archives

  • nixos-unstable -

pkgs.perl540Packages.ArchiveTar

Manipulates TAR archives

  • nixos-unstable -

pkgs.xfce.thunar-archive-plugin

Thunar plugin providing file context menus for archives

  • nixos-unstable -

pkgs.haskellPackages.archive-sig

Backpack signature for archive libraries

pkgs.haskellPackages.archive-tar

Common interface using the tar package

pkgs.haskellPackages.zip-archive

Library for creating and modifying zip archives

pkgs.kodiPackages.vfs-libarchive

LibArchive Virtual Filesystem add-on for Kodi

  • nixos-unstable -

pkgs.perl538Packages.ArchiveCpio

Module for manipulations of cpio archives

  • nixos-unstable -

pkgs.perl540Packages.ArchiveCpio

Module for manipulations of cpio archives

  • nixos-unstable -

pkgs.perlPackages.ArchiveAnyLite

Simple CPAN package extractor

  • nixos-unstable -

pkgs.perlPackages.ArchiveExtract

Generic archive extracting mechanism

  • nixos-unstable -

pkgs.terraform-providers.archive

  • nixos-unstable -

pkgs.perlPackages.ArchiveZip_1_53

Provide an interface to ZIP archive files

  • nixos-unstable -

pkgs.rubyPackages.jekyll-archives

  • nixos-unstable -

pkgs.perl538Packages.ArchiveAnyLite

Simple CPAN package extractor

  • nixos-unstable -

pkgs.perl538Packages.ArchiveExtract

Generic archive extracting mechanism

  • nixos-unstable -

pkgs.perl540Packages.ArchiveAnyLite

Simple CPAN package extractor

  • nixos-unstable -

pkgs.perl540Packages.ArchiveExtract

Generic archive extracting mechanism

  • nixos-unstable -

pkgs.perlPackages.ArchiveLibarchive

Modern Perl bindings to libarchive

  • nixos-unstable -

pkgs.perlPackages.ArchiveTarWrapper

API wrapper around the 'tar' utility

  • nixos-unstable -

pkgs.python312Packages.libarchive-c

Python interface to libarchive

  • nixos-unstable -

pkgs.python313Packages.libarchive-c

Python interface to libarchive

  • nixos-unstable -

pkgs.perl538Packages.ArchiveZip_1_53

Provide an interface to ZIP archive files

  • nixos-unstable -

pkgs.perl540Packages.ArchiveZip_1_53

Provide an interface to ZIP archive files

  • nixos-unstable -

pkgs.perlPackages.NetCoverArtArchive

Query the coverartarchive.org

  • nixos-unstable -

pkgs.python312Packages.craft-archives

Library for handling archives/repositories in Canonical craft applications

  • nixos-unstable -

pkgs.python312Packages.handy-archives

Some handy archive helpers for Python

  • nixos-unstable -

pkgs.python313Packages.craft-archives

Library for handling archives/repositories in Canonical craft applications

  • nixos-unstable -

pkgs.python313Packages.handy-archives

Some handy archive helpers for Python

  • nixos-unstable -

pkgs.rubyPackages_3_1.jekyll-archives

  • nixos-unstable -

pkgs.rubyPackages_3_2.jekyll-archives

  • nixos-unstable -

pkgs.rubyPackages_3_3.jekyll-archives

  • nixos-unstable -

pkgs.rubyPackages_3_4.jekyll-archives

  • nixos-unstable -

pkgs.perl538Packages.ArchiveLibarchive

Modern Perl bindings to libarchive

  • nixos-unstable -

pkgs.perl538Packages.ArchiveTarWrapper

API wrapper around the 'tar' utility

  • nixos-unstable -

pkgs.perl540Packages.ArchiveLibarchive

Modern Perl bindings to libarchive

  • nixos-unstable -

pkgs.perl540Packages.ArchiveTarWrapper

API wrapper around the 'tar' utility

  • nixos-unstable -

pkgs.python312Packages.dissect-archive

Dissect module implementing parsers for various archive and backup formats

  • nixos-unstable -

pkgs.python312Packages.internetarchive

Python and Command-Line Interface to Archive.org

  • nixos-unstable -

pkgs.python313Packages.dissect-archive

Dissect module implementing parsers for various archive and backup formats

  • nixos-unstable -

pkgs.python313Packages.internetarchive

Python and Command-Line Interface to Archive.org

  • nixos-unstable -

pkgs.haskellPackages.archive-libarchive

Common interface using libarchive

pkgs.haskellPackages.libarchive-conduit

Read many archive formats with libarchive and conduit

pkgs.perl538Packages.NetCoverArtArchive

Query the coverartarchive.org

  • nixos-unstable -

pkgs.perl540Packages.NetCoverArtArchive

Query the coverartarchive.org

  • nixos-unstable -

pkgs.perlPackages.ArchiveLibarchivePeek

Peek into archives without extracting them

  • nixos-unstable -

pkgs.perlPackages.TestArchiveLibarchive

Testing tools for Archive::Libarchive

  • nixos-unstable -

pkgs.home-assistant-component-tests.hive

Open source home automation that puts local control and privacy first

pkgs.python312Packages.nskeyedunarchiver

Unserializes plist data into a usable Python dict

  • nixos-unstable -

pkgs.python313Packages.nskeyedunarchiver

Unserializes plist data into a usable Python dict

  • nixos-unstable -

pkgs.python312Packages.pyhive-integration

Python library to interface with the Hive API

  • nixos-unstable -

pkgs.python313Packages.pyhive-integration

Python library to interface with the Hive API

  • nixos-unstable -

pkgs.perl538Packages.ArchiveLibarchivePeek

Peek into archives without extracting them

  • nixos-unstable -

pkgs.perl538Packages.TestArchiveLibarchive

Testing tools for Archive::Libarchive

  • nixos-unstable -

pkgs.perl540Packages.ArchiveLibarchivePeek

Peek into archives without extracting them

  • nixos-unstable -

pkgs.perl540Packages.TestArchiveLibarchive

Testing tools for Archive::Libarchive

  • nixos-unstable -

pkgs.perlPackages.ArchiveLibarchiveExtract

Archive extracting mechanism (using libarchive)

  • nixos-unstable -

pkgs.perl538Packages.ArchiveLibarchiveExtract

Archive extracting mechanism (using libarchive)

  • nixos-unstable -

pkgs.perl540Packages.ArchiveLibarchiveExtract

Archive extracting mechanism (using libarchive)

  • nixos-unstable -

pkgs.python312Packages.extractcode-libarchive

ScanCode Toolkit plugin to provide pre-built binary libraries and utilities and their locations

pkgs.python313Packages.extractcode-libarchive

ScanCode Toolkit plugin to provide pre-built binary libraries and utilities and their locations

pkgs.haskellPackages.amazonka-kinesis-video-archived-media

Amazon Kinesis Video Streams Archived Media SDK

  • nixos-unstable -

pkgs.python312Packages.types-aiobotocore-kinesis-video-archived-media

Type annotations for aiobotocore kinesis-video-archived-media

  • nixos-unstable -

pkgs.python313Packages.types-aiobotocore-kinesis-video-archived-media

Type annotations for aiobotocore kinesis-video-archived-media

  • nixos-unstable -

Package maintainers: 49

created 4 months ago
Libsoup: off-by-one out-of-bounds read in find_boundary() in soup-multipart.c

A vulnerability was found in the libsoup package. This flaw stems from its failure to correctly verify the termination of multipart HTTP messages. This can allow a remote attacker to send a specially crafted multipart HTTP body, causing the libsoup-consuming server to read beyond its allocated memory boundaries (out-of-bounds read).

Affected products

libsoup
  • =<3.6.5
libsoup3

Matching in nixpkgs

pkgs.libsoup_3

HTTP client/server library for GNOME

  • nixos-unstable -

pkgs.libsoup_2_4

HTTP client/server library for GNOME

  • nixos-unstable -

pkgs.tests.pkg-config.defaultPkgConfigPackages."libsoup-gnome-2.4"

Test whether libsoup-2.74.3 exposes pkg-config modules libsoup-gnome-2.4

  • nixos-unstable -
    • nixpkgs-unstable

Package maintainers: 6

created 4 months ago
Qemu: denial of service via improper synchronization in qemu nbd server during socket closure

A flaw was found in the QEMU NBD Server. This vulnerability allows a denial of service (DoS) attack via improper synchronization during socket closure when a client keeps a socket open as the server is taken offline.

Affected products

qemu
  • ==9.0.0
  • ==7.2.0
  • ==8.2.0
rhcos
  • *
qemu-kvm
  • *
virt:rhel
  • *
qemu-kvm-ma
virt-devel:rhel
  • *
virt:av/qemu-kvm
virt:8.2/qemu-kvm
virt:rhel/qemu-kvm
virt-devel:av/qemu-kvm
virt-devel:8.2/qemu-kvm
virt-devel:rhel/qemu-kvm

Matching in nixpkgs

pkgs.qemu

Generic and open source machine emulator and virtualizer

  • nixos-unstable -

pkgs.qemu_kvm

Generic and open source machine emulator and virtualizer

  • nixos-unstable -

pkgs.qemu_xen

Generic and open source machine emulator and virtualizer

  • nixos-unstable -

pkgs.qemu-user

QEMU User space emulator - launch executables compiled for one CPU on another CPU

  • nixos-unstable -

pkgs.qemu_full

Generic and open source machine emulator and virtualizer

  • nixos-unstable -

pkgs.qemu_test

Generic and open source machine emulator and virtualizer

  • nixos-unstable -

pkgs.qemu-utils

Generic and open source machine emulator and virtualizer

  • nixos-unstable -

pkgs.qemu-python-utils

Python tooling used by the QEMU project to build, configure, and test QEMU

pkgs.armTrustedFirmwareQemu

Reference implementation of secure world software for ARMv8-A

  • nixos-unstable -

pkgs.python312Packages.qemu

Python tooling used by the QEMU project to build, configure, and test QEMU

pkgs.python313Packages.qemu

Python tooling used by the QEMU project to build, configure, and test QEMU

pkgs.python312Packages.qemu-qmp

Asyncio library for communicating with QEMU Monitor Protocol (“QMP”) servers

  • nixos-unstable -

pkgs.python313Packages.qemu-qmp

Asyncio library for communicating with QEMU Monitor Protocol (“QMP”) servers

  • nixos-unstable -

Package maintainers: 11

created 4 months ago
Org.keycloak/keycloak-services: jwt token cache exhaustion leading to denial of service (dos) in keycloak

A flaw was found in Keycloak. When the configuration uses JWT tokens for authentication, the tokens are cached until expiration. If a client uses JWT tokens with an excessively long expiration time, for example, 24 or 48 hours, the cache can grow indefinitely, leading to an OutOfMemoryError. This issue could result in a denial of service condition, preventing legitimate users from accessing the system.

Affected products

keycloak
  • <26.0.11
  • <26.1.5
keycloak-services
rhbk/keycloak-rhel9
  • *
keycloak-rhel9-container
  • *
rhbk/keycloak-rhel9-operator
  • *
rhbk/keycloak-operator-bundle
  • *
keycloak-rhel9-operator-container
  • *
keycloak-rhel9-operator-bundle-container
  • *

Matching in nixpkgs

pkgs.keycloak

Identity and access management for modern applications and services

  • nixos-unstable -

pkgs.terraform-providers.keycloak

  • nixos-unstable -

pkgs.python312Packages.python-keycloak

Provides access to the Keycloak API

  • nixos-unstable -

pkgs.python313Packages.python-keycloak

Provides access to the Keycloak API

  • nixos-unstable -

Package maintainers: 4

created 4 months ago
Denial of service via crafted TCP exchange

In some circumstances, when DNSdist is configured to allow an unlimited number of queries on a single, incoming TCP connection from a client, an attacker can cause a denial of service by crafting a TCP exchange that triggers an exhaustion of the stack and a crash of DNSdist, causing a denial of service. The remedy is: upgrade to the patched 1.9.10 version. A workaround is to restrict the maximum number of queries on incoming TCP connections to a safe value, like 50, via the setMaxTCPQueriesPerConnection setting. We would like to thank Renaud Allard for bringing this issue to our attention.

Affected products

dnsdist
  • ==1.9.10

Matching in nixpkgs

pkgs.dnsdist

DNS Loadbalancer

  • nixos-unstable -

Package maintainers: 1

created 4 months ago
WordPress Tiger theme <= 2.0 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jocoxdesign Tiger tiger allows Reflected XSS.This issue affects Tiger: from n/a through 2.0.

Affected products

tiger
  • =<2.0

Matching in nixpkgs

pkgs.libtiger

Rendering library for Kate streams using Pango and Cairo

  • nixos-unstable -

pkgs.tigervnc

Fork of tightVNC, made in cooperation with VirtualGL

  • nixos-unstable -

pkgs.wiredtiger

  • nixos-unstable -

pkgs.tigerbeetle

Financial accounting database designed to be distributed and fast

pkgs.tigerjython

Simple development environment for programming in Python

  • nixos-unstable -

pkgs.tree-sitter-grammars.tree-sitter-tiger

  • nixos-unstable -

pkgs.chickenPackages_5.chickenEggs.tiger-hash

Tiger/192 Message Digest

  • nixos-unstable -

pkgs.vimPlugins.nvim-treesitter-parsers.tiger

  • nixos-unstable -
    • nixpkgs-unstable

pkgs.python312Packages.tree-sitter-grammars.tree-sitter-tiger

Python bindings for tree-sitter-tiger

  • nixos-unstable -

pkgs.python313Packages.tree-sitter-grammars.tree-sitter-tiger

Python bindings for tree-sitter-tiger

  • nixos-unstable -

Package maintainers: 8

created 4 months ago
WordPress ghostwriter theme <= 1.4 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bruno Cavalcante Ghostwriter allows Reflected XSS.This issue affects Ghostwriter: from n/a through 1.4.

Affected products

ghostwriter
  • =<1.4

Matching in nixpkgs

pkgs.kdePackages.ghostwriter

Text editor for Markdown

created 4 months ago
WordPress Bulk theme <= 1.0.11 - Broken Access Control vulnerability

Missing Authorization vulnerability in Themes4WP Bulk allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Bulk: from n/a through 1.0.11.

Affected products

bulk
  • =<1.0.11

Matching in nixpkgs

pkgs.bulky

Bulk rename app

  • nixos-unstable -

pkgs.bulk_extractor

Digital forensics tool for extracting information from file systems

  • nixos-unstable -

pkgs.python312Packages.rebulk

Advanced string matching from simple patterns

  • nixos-unstable -

pkgs.python313Packages.rebulk

Advanced string matching from simple patterns

  • nixos-unstable -

Package maintainers: 3