CVE-2025-4945 created 4 months ago Libsoup: integer overflow in cookie expiration date handling in libsoup A flaw was found in the cookie parsing logic of the libsoup HTTP library, used in GNOME applications and other software. The vulnerability arises when processing the expiration date of cookies, where a specially crafted value can trigger an integer overflow. This may result in undefined behavior, allowing an attacker to bypass cookie expiration logic, causing persistent or unintended cookie behavior. The issue stems from improper validation of large integer inputs during date arithmetic operations within the cookie parsing routines. Affected products libsoup =<3.6.5 * libsoup3 * Matching in nixpkgs pkgs.libsoup_3 HTTP client/server library for GNOME nixos-unstable - nixpkgs-unstable 3.6.5 pkgs.libsoup_2_4 HTTP client/server library for GNOME nixos-unstable - nixpkgs-unstable 2.74.3 pkgs.tests.pkg-config.defaultPkgConfigPackages."libsoup-gnome-2.4" Test whether libsoup-2.74.3 exposes pkg-config modules libsoup-gnome-2.4 nixos-unstable - nixpkgs-unstable Package maintainers: 6 @jtojnar Jan Tojnar <jtojnar@gmail.com> @hedning Tor Hedin Brønner <torhedinbronner@gmail.com> @dasj19 Daniel Șerbănescu <daniel@serbanescu.dk> @7c6f434c Michael Raskin <7c6f434c@mail.ru> @lovek323 Jason O'Conal <jason@oconal.id.au> @bobby285271 Bobby Rong <rjl931189261@126.com>
pkgs.tests.pkg-config.defaultPkgConfigPackages."libsoup-gnome-2.4" Test whether libsoup-2.74.3 exposes pkg-config modules libsoup-gnome-2.4 nixos-unstable - nixpkgs-unstable
CVE-2025-26735 created 4 months ago WordPress Grip theme <= 1.0.9 - Local File Inclusion vulnerability Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Candid themes Grip.This issue affects Grip: from n/a through 1.0.9. Affected products grip =<1.0.9 Matching in nixpkgs pkgs.grip GTK-based audio CD player/ripper nixos-unstable - nixpkgs-unstable 4.2.4 pkgs.go-grip Preview Markdown files locally before committing them nixos-unstable - nixpkgs-unstable 0.5.6 pkgs.grip-grab Fast, more lightweight ripgrep alternative for daily use cases nixos-unstable - nixpkgs-unstable 0.6.7 pkgs.regripper Open source forensic software used as a Windows Registry data extraction command line nixos-unstable - nixpkgs-unstable 0-unstable-2024-12-12 pkgs.grip-search Fast, indexed regexp search over large file trees nixos-unstable - nixpkgs-unstable 0.8 pkgs.jetbrains.datagrip Database IDE from JetBrains nixos-unstable - nixpkgs-unstable 2025.2.2 pkgs.python312Packages.grip Preview GitHub Markdown files like Readme locally before committing them nixos-unstable - nixpkgs-unstable 4.6.1 pkgs.python313Packages.grip Preview GitHub Markdown files like Readme locally before committing them nixos-unstable - nixpkgs-unstable 4.6.1 Package maintainers: 11 @heisfer Heisfer <heisfer@refract.dev> @MarcWeber Marc Weber <marco-oweber@gmx.de> @luftmensch-luftmensch Valentino Bocchetti <valentinobocchetti59@gmail.com> @tex Milan Svoboda <milan.svoboda@centrum.cz> @jamesward James Ward <james@jamesward.com> @leona-ya Leona Maroni <nix@leona.is> @theCapypara Marco Köpcke <hello@capypara.de> @thiagokokada Thiago K. Okada <thiagokokada@gmail.com> @edwtjo Edward Tjörnhammar <ed@cflags.cc> @k0ral Koral <koral@mailoo.org> @D3vil0p3r Antonio Voza <vozaanthony@gmail.com>
pkgs.go-grip Preview Markdown files locally before committing them nixos-unstable - nixpkgs-unstable 0.5.6
pkgs.grip-grab Fast, more lightweight ripgrep alternative for daily use cases nixos-unstable - nixpkgs-unstable 0.6.7
pkgs.regripper Open source forensic software used as a Windows Registry data extraction command line nixos-unstable - nixpkgs-unstable 0-unstable-2024-12-12
pkgs.grip-search Fast, indexed regexp search over large file trees nixos-unstable - nixpkgs-unstable 0.8
pkgs.python312Packages.grip Preview GitHub Markdown files like Readme locally before committing them nixos-unstable - nixpkgs-unstable 4.6.1
pkgs.python313Packages.grip Preview GitHub Markdown files like Readme locally before committing them nixos-unstable - nixpkgs-unstable 4.6.1
CVE-2025-4948 created 4 months ago Libsoup: integer underflow in soup_multipart_new_from_message() leading to denial of service in libsoup A flaw was found in the soup_multipart_new_from_message() function of the libsoup HTTP library, which is commonly used by GNOME and other applications to handle web communications. The issue occurs when the library processes specially crafted multipart messages. Due to improper validation, an internal calculation can go wrong, leading to an integer underflow. This can cause the program to access invalid memory and crash. As a result, any application or server using libsoup could be forced to exit unexpectedly, creating a denial-of-service (DoS) risk. Affected products libsoup =<3.6.5 * libsoup3 * Matching in nixpkgs pkgs.libsoup_3 HTTP client/server library for GNOME nixos-unstable - nixpkgs-unstable 3.6.5 pkgs.libsoup_2_4 HTTP client/server library for GNOME nixos-unstable - nixpkgs-unstable 2.74.3 pkgs.tests.pkg-config.defaultPkgConfigPackages."libsoup-gnome-2.4" Test whether libsoup-2.74.3 exposes pkg-config modules libsoup-gnome-2.4 nixos-unstable - nixpkgs-unstable Package maintainers: 6 @jtojnar Jan Tojnar <jtojnar@gmail.com> @hedning Tor Hedin Brønner <torhedinbronner@gmail.com> @dasj19 Daniel Șerbănescu <daniel@serbanescu.dk> @7c6f434c Michael Raskin <7c6f434c@mail.ru> @lovek323 Jason O'Conal <jason@oconal.id.au> @bobby285271 Bobby Rong <rjl931189261@126.com>
pkgs.tests.pkg-config.defaultPkgConfigPackages."libsoup-gnome-2.4" Test whether libsoup-2.74.3 exposes pkg-config modules libsoup-gnome-2.4 nixos-unstable - nixpkgs-unstable
CVE-2025-31063 created 4 months ago WordPress Wishlist <= 2.1.0 - Broken Access Control Vulnerability Missing Authorization vulnerability in redqteam Wishlist allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Wishlist: from n/a through 2.1.0. Affected products wishlist =<2.1.0 Matching in nixpkgs pkgs.wishlist Single entrypoint for multiple SSH endpoints nixos-unstable - nixpkgs-unstable 0.15.2 Package maintainers: 2 @caarlos0 Carlos A Becker <carlos@becker.software> @penguwin Nicolas Martin <penguwin@penguwin.eu>
CVE-2025-4476 created 4 months ago Libsoup: null pointer dereference in libsoup may lead to denial of service A denial-of-service vulnerability has been identified in the libsoup HTTP client library. This flaw can be triggered when a libsoup client receives a 401 (Unauthorized) HTTP response containing a specifically crafted domain parameter within the WWW-Authenticate header. Processing this malformed header can lead to a crash of the client application using libsoup. An attacker could exploit this by setting up a malicious HTTP server. If a user's application using the vulnerable libsoup library connects to this malicious server, it could result in a denial-of-service. Successful exploitation requires tricking a user's client application into connecting to the attacker's malicious server. Affected products libsoup <3.6.6 libsoup3 Matching in nixpkgs pkgs.libsoup_3 HTTP client/server library for GNOME nixos-unstable - nixpkgs-unstable 3.6.5 pkgs.libsoup_2_4 HTTP client/server library for GNOME nixos-unstable - nixpkgs-unstable 2.74.3 pkgs.tests.pkg-config.defaultPkgConfigPackages."libsoup-gnome-2.4" Test whether libsoup-2.74.3 exposes pkg-config modules libsoup-gnome-2.4 nixos-unstable - nixpkgs-unstable Package maintainers: 6 @jtojnar Jan Tojnar <jtojnar@gmail.com> @hedning Tor Hedin Brønner <torhedinbronner@gmail.com> @dasj19 Daniel Șerbănescu <daniel@serbanescu.dk> @7c6f434c Michael Raskin <7c6f434c@mail.ru> @lovek323 Jason O'Conal <jason@oconal.id.au> @bobby285271 Bobby Rong <rjl931189261@126.com>
pkgs.tests.pkg-config.defaultPkgConfigPackages."libsoup-gnome-2.4" Test whether libsoup-2.74.3 exposes pkg-config modules libsoup-gnome-2.4 nixos-unstable - nixpkgs-unstable
CVE-2025-31062 created 4 months ago WordPress Wishlist <= 2.1.0 - Sensitive Data Exposure Vulnerability Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in redqteam Wishlist allows Retrieve Embedded Sensitive Data. This issue affects Wishlist: from n/a through 2.1.0. Affected products wishlist =<2.1.0 Matching in nixpkgs pkgs.wishlist Single entrypoint for multiple SSH endpoints nixos-unstable - nixpkgs-unstable 0.15.2 Package maintainers: 2 @caarlos0 Carlos A Becker <carlos@becker.software> @penguwin Nicolas Martin <penguwin@penguwin.eu>
CVE-2025-31639 created 4 months ago WordPress Spare <= 1.7 - Cross Site Request Forgery (CSRF) Vulnerability Cross-Site Request Forgery (CSRF) vulnerability in themeton Spare allows Cross Site Request Forgery. This issue affects Spare: from n/a through 1.7. Affected products spare =<1.7 Matching in nixpkgs pkgs.asciiquarium-transparent Aquarium/sea animation in ASCII art (with option of transparent background) nixos-unstable - nixpkgs-unstable 1.4 pkgs.materia-theme-transparent Transparent Material Design theme for GNOME/GTK based desktop environments nixos-unstable - nixpkgs-unstable 0-unstable-2021-03-22 pkgs.gnomeExtensions.transparent-top-bar Bring back the transparent top bar when free-floating in GNOME Shell 3.32. nixos-unstable - nixpkgs-unstable 24 pkgs.gnomeExtensions.transparent-window-moving Makes the window semi-transparent when moving or resizing nixos-unstable - nixpkgs-unstable 19 pkgs.sway-contrib.inactive-windows-transparency It makes inactive sway windows transparent nixos-unstable - nixpkgs-unstable 0-unstable-2024-03-19 pkgs.gnomeExtensions.transparent-top-bar-adjustable-transparency Fork of: https://github.com/zhanghai/gnome-shell-extension-transparent-top-bar nixos-unstable - nixpkgs-unstable 24 Package maintainers: 4 @quantenzitrone quantenzitrone <nix@dev.quantenzitrone.eu> @honnip Jung seungwoo <me@honnip.page> @CorbinWunderlich Corbin Wunderlich <corbin@wcopy.net> @evils Evils <evils.devils@protonmail.com>
pkgs.asciiquarium-transparent Aquarium/sea animation in ASCII art (with option of transparent background) nixos-unstable - nixpkgs-unstable 1.4
pkgs.materia-theme-transparent Transparent Material Design theme for GNOME/GTK based desktop environments nixos-unstable - nixpkgs-unstable 0-unstable-2021-03-22
pkgs.gnomeExtensions.transparent-top-bar Bring back the transparent top bar when free-floating in GNOME Shell 3.32. nixos-unstable - nixpkgs-unstable 24
pkgs.gnomeExtensions.transparent-window-moving Makes the window semi-transparent when moving or resizing nixos-unstable - nixpkgs-unstable 19
pkgs.sway-contrib.inactive-windows-transparency It makes inactive sway windows transparent nixos-unstable - nixpkgs-unstable 0-unstable-2024-03-19
pkgs.gnomeExtensions.transparent-top-bar-adjustable-transparency Fork of: https://github.com/zhanghai/gnome-shell-extension-transparent-top-bar nixos-unstable - nixpkgs-unstable 24
CVE-2025-40907 created 4 months ago FCGI versions 0.44 through 0.82, for Perl, include a vulnerable version of the FastCGI fcgi2 (aka fcgi) library FCGI versions 0.44 through 0.82, for Perl, include a vulnerable version of the FastCGI fcgi2 (aka fcgi) library. The included FastCGI library is affected by CVE-2025-23016, causing an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC socket. This occurs in ReadParams in fcgiapp.c. Affected products FCGI =<0.82 Matching in nixpkgs pkgs.perlPackages.FCGI Fast CGI module nixos-unstable - nixpkgs-unstable 0.82 pkgs.perl538Packages.FCGI Fast CGI module nixos-unstable - nixpkgs-unstable 0.82 pkgs.perl540Packages.FCGI Fast CGI module nixos-unstable - nixpkgs-unstable 0.82 pkgs.perlPackages.FCGIClient Client library for fastcgi protocol nixos-unstable - nixpkgs-unstable 0.09 pkgs.perl538Packages.FCGIClient Client library for fastcgi protocol nixos-unstable - nixpkgs-unstable 0.09 pkgs.perl540Packages.FCGIClient Client library for fastcgi protocol nixos-unstable - nixpkgs-unstable 0.09 pkgs.perlPackages.FCGIProcManager Perl-based FastCGI process manager nixos-unstable - nixpkgs-unstable 0.28 pkgs.perl538Packages.FCGIProcManager Perl-based FastCGI process manager nixos-unstable - nixpkgs-unstable 0.28 pkgs.perl540Packages.FCGIProcManager Perl-based FastCGI process manager nixos-unstable - nixpkgs-unstable 0.28
pkgs.perlPackages.FCGIClient Client library for fastcgi protocol nixos-unstable - nixpkgs-unstable 0.09
pkgs.perl538Packages.FCGIClient Client library for fastcgi protocol nixos-unstable - nixpkgs-unstable 0.09
pkgs.perl540Packages.FCGIClient Client library for fastcgi protocol nixos-unstable - nixpkgs-unstable 0.09
pkgs.perlPackages.FCGIProcManager Perl-based FastCGI process manager nixos-unstable - nixpkgs-unstable 0.28
pkgs.perl538Packages.FCGIProcManager Perl-based FastCGI process manager nixos-unstable - nixpkgs-unstable 0.28
pkgs.perl540Packages.FCGIProcManager Perl-based FastCGI process manager nixos-unstable - nixpkgs-unstable 0.28
CVE-2025-40906 created 4 months ago BSON::XS versions 0.8.4 and earlier for Perl includes a bundled libbson 1.1.7, which has several vulnerabilities BSON::XS versions 0.8.4 and earlier for Perl includes a bundled libbson 1.1.7, which has several vulnerabilities. Those include CVE-2017-14227, CVE-2018-16790, CVE-2023-0437, CVE-2024-6381, CVE-2024-6383, and CVE-2025-0755. BSON-XS was the official Perl XS implementation of MongoDB's BSON serialization, but this distribution has reached its end of life as of August 13, 2020 and is no longer supported. Affected products BSON-XS =<0.8.4 Matching in nixpkgs pkgs.perlPackages.BSONXS XS implementation of MongoDB's BSON serialization (EOL) nixos-unstable - nixpkgs-unstable 0.8.4 pkgs.perl538Packages.BSONXS XS implementation of MongoDB's BSON serialization (EOL) nixos-unstable - nixpkgs-unstable 0.8.4 pkgs.perl540Packages.BSONXS XS implementation of MongoDB's BSON serialization (EOL) nixos-unstable - nixpkgs-unstable 0.8.4
pkgs.perlPackages.BSONXS XS implementation of MongoDB's BSON serialization (EOL) nixos-unstable - nixpkgs-unstable 0.8.4
pkgs.perl538Packages.BSONXS XS implementation of MongoDB's BSON serialization (EOL) nixos-unstable - nixpkgs-unstable 0.8.4
pkgs.perl540Packages.BSONXS XS implementation of MongoDB's BSON serialization (EOL) nixos-unstable - nixpkgs-unstable 0.8.4
CVE-2025-4478 created 4 months ago Gnome-remote-desktop: unauthenticated rdp packet causes segfault in gnome-remote-desktop leading to denial of service A flaw was found in the gnome-remote-desktop used by Anaconda's remote install feature, where a crafted RDP packet could trigger a segmentation fault. This issue causes the service to crash and remain defunct, resulting in a denial of service. It occurs pre-boot and is likely due to a NULL pointer dereference. Rebooting is required to recover the system. Affected products freerdp <3.16.0 * gnome-remote-desktop Matching in nixpkgs pkgs.gnome-remote-desktop GNOME Remote Desktop server nixos-unstable - nixpkgs-unstable 48.1 Package maintainers: 4 @hedning Tor Hedin Brønner <torhedinbronner@gmail.com> @jtojnar Jan Tojnar <jtojnar@gmail.com> @dasj19 Daniel Șerbănescu <daniel@serbanescu.dk> @bobby285271 Bobby Rong <rjl931189261@126.com>