Dismissed suggestions Untriaged suggestions Draft issues Published issues Automatically generated suggestions Create Draft to queue a suggestion for refinement. Dismiss to remove a suggestion from the queue. CVE-2025-1386 created 2 months, 2 weeks ago Query smuggling in ch-go library When using the ch-go library, under a specific condition when the query includes a large, uncompressed malicious external data, it is possible for an attacker in control of such data to smuggle another query packet into the connection stream. ch-go <0.65.0 pkgs.immich-go Immich client tool for bulk-uploads nixos-unstable ??? nixpkgs-unstable 0.27.0 Package maintainers: 1 @kai-tub Kai Norman Clasen CVE-2025-32618 8.5 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): CHANGED Confidentiality impact (C): HIGH Integrity impact (I): NONE Availability impact (A): LOW created 2 months, 2 weeks ago WordPress Wishlist plugin <= 1.0.43 - SQL Injection vulnerability Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PickPlugins Wishlist allows SQL Injection. This issue affects Wishlist: from n/a through 1.0.43. wishlist =<1.0.43 pkgs.wishlist Single entrypoint for multiple SSH endpoints nixos-unstable ??? nixpkgs-unstable 0.15.2 Package maintainers: 2 @caarlos0 Carlos A Becker <carlos@becker.software> @penguwin Nicolas Martin <penguwin@penguwin.eu> CVE-2025-32230 4.3 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): LOW Availability impact (A): NONE created 2 months, 2 weeks ago WordPress Tutor LMS plugin <= 3.4.0 - HTML Injection vulnerability Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Themeum Tutor LMS. This issue affects Tutor LMS: from n/a through 3.4.0. tutor =<3.4.0 pkgs.typstPackages.tutor_0_3_0 Utilities to create exams nixos-unstable ??? nixpkgs-unstable 0.3.0 pkgs.typstPackages.tutor_0_4_0 Utilities to create exams nixos-unstable ??? nixpkgs-unstable 0.4.0 pkgs.typstPackages.tutor_0_6_1 Utilities to create exams nixos-unstable ??? nixpkgs-unstable 0.6.1 pkgs.typstPackages.tutor_0_7_0 Utilities to create exams nixos-unstable ??? nixpkgs-unstable 0.7.0 pkgs.typstPackages.tutor_0_8_0 Utilities to create exams nixos-unstable ??? nixpkgs-unstable 0.8.0 pkgs.haskellPackages.timeless-tutorials Initial project template from stack nixos-unstable ??? nixpkgs-unstable 1.0.0.0 Package maintainers: 1 @cherrypiejam Gongqi Huang CVE-2025-23386 7.8 HIGH CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 2 months, 2 weeks ago gerbera: Privilege escalation from user gerbera to root because of insecure %post script A Incorrect Default Permissions vulnerability in the openSUSE Tumbleweed package gerbera allows the service user gerbera to escalate to root.,This issue affects gerbera on openSUSE Tumbleweed before 2.5.0-1.1. gerbera <2.5.0-1.1 pkgs.gerbera UPnP Media Server for 2024 nixos-unstable ??? nixpkgs-unstable 2.5.0 Package maintainers: 1 @ardumont Antoine R. Dumont <eniotna.t@gmail.com> CVE-2025-32584 7.1 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): CHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 2 months, 2 weeks ago WordPress Chat2 plugin <= 3.6.3 - CSRF to Stored XSS vulnerability Cross-Site Request Forgery (CSRF) vulnerability in Chat2 Chat2 allows Cross Site Request Forgery. This issue affects Chat2: from n/a through 3.6.3. chat2 =<3.6.3 pkgs.python312Packages.deltachat2 Client library for Delta Chat core JSON-RPC interface nixos-unstable ??? nixpkgs-unstable deltachat2-0.7.0 pkgs.python313Packages.deltachat2 Client library for Delta Chat core JSON-RPC interface nixos-unstable ??? nixpkgs-unstable deltachat2-0.7.0 Package maintainers: 1 @dotlambda Robert Schütz <rschuetz17@gmail.com> CVE-2025-31003 2.7 LOW CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): HIGH User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): NONE Availability impact (A): NONE created 2 months, 2 weeks ago WordPress Squeeze plugin <= 1.6 - Full Path Disclosure (FPD) vulnerability Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Bogdan Bendziukov Squeeze allows Retrieve Embedded Sensitive Data. This issue affects Squeeze: from n/a through 1.6. squeeze =<1.6 pkgs.squeezelite Lightweight headless squeezebox client emulator nixos-unstable ??? nixpkgs-unstable 2.0.0.1541 pkgs.squeezelite-pulse Lightweight headless squeezebox client emulator nixos-unstable ??? nixpkgs-unstable 2.0.0.1541 pkgs.postgresqlPackages.pg_squeeze PostgreSQL extension for automatic bloat cleanup nixos-unstable ??? nixpkgs-unstable 1.9.0 pkgs.python312Packages.pysqueezebox Asynchronous library to control Logitech Media Server nixos-unstable ??? nixpkgs-unstable 0.12.1 pkgs.python313Packages.pysqueezebox Asynchronous library to control Logitech Media Server nixos-unstable ??? nixpkgs-unstable 0.12.1 pkgs.postgresql13Packages.pg_squeeze PostgreSQL extension for automatic bloat cleanup nixos-unstable ??? nixpkgs-unstable 1.9.0 pkgs.postgresql14Packages.pg_squeeze PostgreSQL extension for automatic bloat cleanup nixos-unstable ??? nixpkgs-unstable 1.9.0 pkgs.postgresql15Packages.pg_squeeze PostgreSQL extension for automatic bloat cleanup nixos-unstable ??? nixpkgs-unstable 1.9.0 pkgs.postgresql16Packages.pg_squeeze PostgreSQL extension for automatic bloat cleanup nixos-unstable ??? nixpkgs-unstable 1.9.0 pkgs.postgresql18Packages.pg_squeeze PostgreSQL extension for automatic bloat cleanup nixos-unstable ??? nixpkgs-unstable 1.9.0 pkgs.home-assistant-component-tests.squeezebox Open source home automation that puts local control and privacy first nixos-unstable ??? nixpkgs-unstable 2025.9.3 Package maintainers: 5 @nyanloutre Paul Trehiou <paul@nyanlout.re> @mweinelt Martin Weinelt <hexa@darmstadt.ccc.de> @fabaff Fabian Affolter <mail@fabian-affolter.ch> @dotlambda Robert Schütz <rschuetz17@gmail.com> @adamcstephens Adam C. Stephens <happy.plan4249@valkor.net> CVE-2025-31002 9.1 CRITICAL CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): HIGH User interaction (UI): NONE Scope (S): CHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 2 months, 2 weeks ago WordPress Squeeze plugin <= 1.6 - Arbitrary File Upload vulnerability Unrestricted Upload of File with Dangerous Type vulnerability in Bogdan Bendziukov Squeeze allows Using Malicious Files. This issue affects Squeeze: from n/a through 1.6. squeeze =<1.6 pkgs.squeezelite Lightweight headless squeezebox client emulator nixos-unstable ??? nixpkgs-unstable 2.0.0.1541 pkgs.squeezelite-pulse Lightweight headless squeezebox client emulator nixos-unstable ??? nixpkgs-unstable 2.0.0.1541 pkgs.postgresqlPackages.pg_squeeze PostgreSQL extension for automatic bloat cleanup nixos-unstable ??? nixpkgs-unstable 1.9.0 pkgs.python312Packages.pysqueezebox Asynchronous library to control Logitech Media Server nixos-unstable ??? nixpkgs-unstable 0.12.1 pkgs.python313Packages.pysqueezebox Asynchronous library to control Logitech Media Server nixos-unstable ??? nixpkgs-unstable 0.12.1 pkgs.postgresql13Packages.pg_squeeze PostgreSQL extension for automatic bloat cleanup nixos-unstable ??? nixpkgs-unstable 1.9.0 pkgs.postgresql14Packages.pg_squeeze PostgreSQL extension for automatic bloat cleanup nixos-unstable ??? nixpkgs-unstable 1.9.0 pkgs.postgresql15Packages.pg_squeeze PostgreSQL extension for automatic bloat cleanup nixos-unstable ??? nixpkgs-unstable 1.9.0 pkgs.postgresql16Packages.pg_squeeze PostgreSQL extension for automatic bloat cleanup nixos-unstable ??? nixpkgs-unstable 1.9.0 pkgs.postgresql18Packages.pg_squeeze PostgreSQL extension for automatic bloat cleanup nixos-unstable ??? nixpkgs-unstable 1.9.0 pkgs.home-assistant-component-tests.squeezebox Open source home automation that puts local control and privacy first nixos-unstable ??? nixpkgs-unstable 2025.9.3 Package maintainers: 5 @nyanloutre Paul Trehiou <paul@nyanlout.re> @mweinelt Martin Weinelt <hexa@darmstadt.ccc.de> @fabaff Fabian Affolter <mail@fabian-affolter.ch> @dotlambda Robert Schütz <rschuetz17@gmail.com> @adamcstephens Adam C. Stephens <happy.plan4249@valkor.net> CVE-2025-31375 7.1 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): CHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 2 months, 2 weeks ago WordPress Scheduled plugin <= 1.0 - CSRF to Stored XSS vulnerability Cross-Site Request Forgery (CSRF) vulnerability in bhoogterp Scheduled allows Stored XSS. This issue affects Scheduled: from n/a through 1.0. scheduled =<1.0 pkgs.azure-cli-extensions.scheduled-query Microsoft Azure Command-Line Tools Scheduled_query Extension nixos-unstable ??? nixpkgs-unstable 1.0.0b1 Package maintainers: 2 @ulrikstrid Ulrik Strid <ulrik.strid@outlook.com> @katexochen Paul Meyer <katexochen0@gmail.com> CVE-2025-3416 3.7 LOW CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): LOW created 2 months, 2 weeks ago Openssl: rust-openssl use-after-free in `md::fetch` and `cipher::fetch` A flaw was found in OpenSSL's handling of the properties argument in certain functions. This vulnerability can allow use-after-free exploitation, which may result in undefined behavior or incorrect property parsing, leading to OpenSSL treating the input as an empty string. gjs polkit firefox mozjs60 openssl rpm-ostree 389-ds-base rust-bootupd rust-openssl <0.10.72 mingw-openssl kata-containers keylime-agent-rust rhtas/tuffer-rhel9 rhtas/tuftool-rhel9 389-ds:1.4/389-ds-base firefox:flatpak/firefox python3.12-cryptography redhat-ds:11/389-ds-base redhat-ds:12/389-ds-base rhtpa/rhtpa-trustification-service-rhel9 pkgs.gjs JavaScript bindings for GNOME nixos-unstable ??? nixpkgs-unstable 1.84.2 pkgs.polkit Toolkit for defining and handling the policy that allows unprivileged processes to speak to privileged processes nixos-unstable ??? nixpkgs-unstable 126 pkgs.openssl Cryptographic library that implements the SSL and TLS protocols nixos-unstable ??? nixpkgs-unstable 3.5.1 pkgs.astal.gjs Astal module for GJS nixos-unstable ??? nixpkgs-unstable 0-unstable-2025-08-29 pkgs.xulrunner Web browser built from Firefox source tree nixos-unstable ??? nixpkgs-unstable 142.0.1 pkgs.cmd-polkit Easily create polkit authentication agents by using commands nixos-unstable ??? nixpkgs-unstable 0.3.0 pkgs.firefoxpwa Tool to install, manage and use Progressive Web Apps (PWAs) in Mozilla Firefox (native component) nixos-unstable ??? nixpkgs-unstable 2.15.0 pkgs.rpm-ostree Hybrid image/package system. It uses OSTree as an image format, and uses RPM as a component model nixos-unstable ??? nixpkgs-unstable 2024.8 pkgs.openssl_1_1 Cryptographic library that implements the SSL and TLS protocols nixos-unstable ??? nixpkgs-unstable 1.1.1w pkgs.openssl_3_0 Cryptographic library that implements the SSL and TLS protocols nixos-unstable ??? nixpkgs-unstable 3.0.17 pkgs.openssl_3_5 Cryptographic library that implements the SSL and TLS protocols nixos-unstable ??? nixpkgs-unstable 3.5.1 pkgs._389-ds-base Enterprise-class Open Source LDAP server for Linux nixos-unstable ??? nixpkgs-unstable 3.1.3 pkgs.polkit_gnome Dbus session bus service that is used to bring up authentication dialogs nixos-unstable ??? nixpkgs-unstable 0.105 pkgs.tpm2-openssl OpenSSL Provider for TPM2 integration nixos-unstable ??? nixpkgs-unstable 1.3.0 pkgs.faust2firefox The faust2firefox script, part of faust functional programming language for realtime audio signal processing nixos-unstable ??? nixpkgs-unstable 2.79.3 pkgs.openssl_legacy Cryptographic library that implements the SSL and TLS protocols nixos-unstable ??? nixpkgs-unstable 3.5.1 pkgs.firefox_decrypt Tool to extract passwords from profiles of Mozilla Firefox and derivates nixos-unstable ??? nixpkgs-unstable 1.1.1 pkgs.hyprpolkitagent Polkit authentication agent written in QT/QML nixos-unstable ??? nixpkgs-unstable 0.1.3 pkgs.mate.mate-polkit Integrates polkit authentication for MATE desktop nixos-unstable ??? nixpkgs-unstable 1.28.1 pkgs.firefox-unwrapped Web browser built from Firefox source tree nixos-unstable ??? nixpkgs-unstable 142.0.1 pkgs.pcscliteWithPolkit Middleware to access a smart card using SCard API (PC/SC) nixos-unstable ??? nixpkgs-unstable 2.3.0 pkgs.firefox-sync-client Commandline-utility to list/view/edit/delete entries in a firefox-sync account nixos-unstable ??? nixpkgs-unstable 1.9.0 pkgs.libsForQt5.polkit-qt Qt wrapper around PolKit nixos-unstable ??? nixpkgs-unstable 1-0.114.0 pkgs.rubyPackages.openssl nixos-unstable ??? nixpkgs-unstable 3.3.0 pkgs.firefox-esr-unwrapped Web browser built from Firefox source tree nixos-unstable ??? nixpkgs-unstable 140.2.0esr pkgs.firefox-beta-unwrapped Web browser built from Firefox Beta Release source tree nixos-unstable ??? nixpkgs-unstable 144.0b1 pkgs.gnomeExtensions.gjs-osk A new Onscreen Keyboard built using GNOME JS nixos-unstable ??? nixpkgs-unstable 38 pkgs.kdePackages.polkit-qt-1 Qt wrapper around Polkit-1 client libraries nixos-unstable ??? nixpkgs-unstable 1-0.200.0 pkgs.php81Extensions.openssl PHP upstream extension: openssl nixos-unstable ??? nixpkgs-unstable 8.1.33 pkgs.php82Extensions.openssl PHP upstream extension: openssl nixos-unstable ??? nixpkgs-unstable 8.2.29 pkgs.php83Extensions.openssl PHP upstream extension: openssl nixos-unstable ??? nixpkgs-unstable 8.3.25 pkgs.php84Extensions.openssl PHP upstream extension: openssl nixos-unstable ??? nixpkgs-unstable 8.4.12 pkgs.haskellPackages.hopenssl FFI Bindings to OpenSSL's EVP Digest Interface nixos-unstable ??? nixpkgs-unstable 2.2.5 pkgs.rubyPackages_3_1.openssl nixos-unstable ??? nixpkgs-unstable 3.3.0 pkgs.rubyPackages_3_2.openssl nixos-unstable ??? nixpkgs-unstable 3.3.0 pkgs.rubyPackages_3_3.openssl nixos-unstable ??? nixpkgs-unstable 3.3.0 pkgs.rubyPackages_3_4.openssl nixos-unstable ??? nixpkgs-unstable 3.3.0 pkgs.bruteforce-salted-openssl Try to find the password of file encrypted with OpenSSL nixos-unstable ??? nixpkgs-unstable 1.5.0 pkgs.plasma5Packages.polkit-qt Qt wrapper around PolKit nixos-unstable ??? nixpkgs-unstable 1-0.114.0 pkgs.python312Packages.pypugjs PugJS syntax template adapter for Django, Jinja2, Mako and Tornado templates nixos-unstable ??? nixpkgs-unstable 5.12.0 pkgs.python313Packages.pypugjs PugJS syntax template adapter for Django, Jinja2, Mako and Tornado templates nixos-unstable ??? nixpkgs-unstable 5.12.0 pkgs.lomiri.lomiri-polkit-agent Policy kit agent for the Lomiri desktop nixos-unstable ??? nixpkgs-unstable 0.3 pkgs.python312Packages.pyopenssl Python wrapper around the OpenSSL library nixos-unstable ??? nixpkgs-unstable 25.1.0 pkgs.python313Packages.pyopenssl Python wrapper around the OpenSSL library nixos-unstable ??? nixpkgs-unstable 25.1.0 pkgs.firefox-devedition-unwrapped Web browser built from Firefox Developer Edition source tree nixos-unstable ??? nixpkgs-unstable 144.0b1 pkgs.python312Packages.aioopenssl TLS-capable transport using OpenSSL for asyncio nixos-unstable ??? nixpkgs-unstable 0.6.0 pkgs.python313Packages.aioopenssl TLS-capable transport using OpenSSL for asyncio nixos-unstable ??? nixpkgs-unstable 0.6.0 pkgs.luaPackages.lua-resty-openssl No summary nixos-unstable ??? nixpkgs-unstable 1.6.4-1 pkgs.kdePackages.polkit-kde-agent-1 Daemon providing a Polkit authentication UI for Plasma nixos-unstable ??? nixpkgs-unstable 1-6.4.5 pkgs.pantheon.pantheon-agent-polkit Polkit Agent for the Pantheon Desktop nixos-unstable ??? nixpkgs-unstable 8.0.1 pkgs.php81Extensions.openssl-legacy PHP upstream extension: openssl-legacy nixos-unstable ??? nixpkgs-unstable 8.1.33 pkgs.php82Extensions.openssl-legacy PHP upstream extension: openssl-legacy nixos-unstable ??? nixpkgs-unstable 8.2.29 pkgs.php83Extensions.openssl-legacy PHP upstream extension: openssl-legacy nixos-unstable ??? nixpkgs-unstable 8.3.25 pkgs.php84Extensions.openssl-legacy PHP upstream extension: openssl-legacy nixos-unstable ??? nixpkgs-unstable 8.4.12 pkgs.python312Packages.cryptography Package which provides cryptographic recipes and primitives nixos-unstable ??? nixpkgs-unstable 45.0.4 pkgs.haskellPackages.openssl-streams OpenSSL network support for io-streams nixos-unstable ??? nixpkgs-unstable 1.2.3.0 pkgs.lua51Packages.lua-resty-openssl No summary nixos-unstable ??? nixpkgs-unstable 1.6.4-1 pkgs.lua52Packages.lua-resty-openssl No summary nixos-unstable ??? nixpkgs-unstable 1.6.4-1 pkgs.lua53Packages.lua-resty-openssl No summary nixos-unstable ??? nixpkgs-unstable 1.6.4-1 pkgs.lua54Packages.lua-resty-openssl No summary nixos-unstable ??? nixpkgs-unstable 1.6.4-1 pkgs.gnomeExtensions.firefox-profiles Easily launch Firefox with your favorite profile right from the indicator menu! nixos-unstable ??? nixpkgs-unstable 4 pkgs.luajitPackages.lua-resty-openssl No summary nixos-unstable ??? nixpkgs-unstable 1.6.4-1 pkgs.haskellPackages.openssl-createkey Create OpenSSL keypairs nixos-unstable ??? nixpkgs-unstable 0.1 pkgs.python312Packages.types-pyopenssl Typing stubs for pyopenssl nixos-unstable ??? nixpkgs-unstable 24.1.0.20240722 pkgs.python313Packages.types-pyopenssl Typing stubs for pyopenssl nixos-unstable ??? nixpkgs-unstable 24.1.0.20240722 pkgs.haskellPackages.cryptonite-openssl Crypto stuff using OpenSSL cryptographic library nixos-unstable ??? nixpkgs-unstable 0.7 pkgs.haskellPackages.http-client-openssl http-client backend using the OpenSSL library nixos-unstable ??? nixpkgs-unstable 0.3.3 pkgs.chickenPackages_5.chickenEggs.openssl Bindings to the OpenSSL SSL/TLS library nixos-unstable ??? nixpkgs-unstable 2.2.6 pkgs.tests.pkg-config.defaultPkgConfigPackages.libssl Test whether openssl-3.5.1 exposes pkg-config modules libssl nixos-unstable ??? nixpkgs-unstable pkgs.tests.pkg-config.defaultPkgConfigPackages.openssl Test whether openssl-3.5.1 exposes pkg-config modules openssl nixos-unstable ??? nixpkgs-unstable pkgs.tests.pkg-config.defaultPkgConfigPackages.libcrypto Test whether openssl-3.5.1 exposes pkg-config modules libcrypto nixos-unstable ??? nixpkgs-unstable pkgs.tests.testers.hasPkgConfigModules.openssl-has-openssl Test whether openssl-3.5.1 exposes pkg-config modules openssl nixos-unstable ??? nixpkgs-unstable pkgs.vscode-extensions.firefox-devtools.vscode-firefox-debug Visual Studio Code extension for debugging web applications and browser extensions in Firefox nixos-unstable ??? nixpkgs-unstable 2.15.0 pkgs.tests.testers.hasPkgConfigModules.openssl-has-all-meta-pkgConfigModules Test whether openssl-3.5.1 exposes pkg-config modules libcrypto, libssl, openssl nixos-unstable ??? nixpkgs-unstable Package maintainers: 48 @thillux Markus Theil <theil.markus@gmail.com> @ulrikstrid Ulrik Strid <ulrik.strid@outlook.com> @aanderse Aaron Andersen <aaron@fosslib.net> @talyz Kim Lindberger <kim.lindberger@gmail.com> @piotrkwiecinski Piotr Kwiecinski <piokwiecinski+nixpkgs@gmail.com> @Ma27 Maximilian Bosch <maximilian@mbosch.me> @dotlambda Robert Schütz <rschuetz17@gmail.com> @gador Florian Brandes <florian.brandes@posteo.de> @octodi octodi <octodi@proton.me> @stv0g Steffen Vogel <post@steffenvogel.de> @peti Peter Simons <simons@cryp.to> @pmahoney Patrick Mahoney <pat@polycrystal.org> @magnetophon Bart Brouns <bart@magnetophon.nl> @jopejoe1 jopejoe1 <nixpkgs@missing.ninja> @rhendric Ryan Hendrickson @mweinelt Martin Weinelt <hexa@darmstadt.ccc.de> @ambroisie Bruno BELANYI <bruno.nixpkgs@belanyi.fr> @unode Renato Alves <alves.rjc@gmail.com> @schnusch schnusch @camillemndn Camille M. <camillemondon@free.fr> @pasqui23 pasqui23 <p3dimaria@hotmail.it> @felschr Felix Schröter <dev@felschr.com> @honnip Jung seungwoo <me@honnip.page> @SuperSandro2000 Sandro Jäckel <sandro.jaeckel@gmail.com> @ners ners <ners@gmx.ch> @lopsided98 Ben Wolsieffer <benwolsieffer@gmail.com> @hedning Tor Hedin Brønner <torhedinbronner@gmail.com> @dasj19 Daniel Șerbănescu <daniel@serbanescu.dk> @bobby285271 Bobby Rong <rjl931189261@126.com> @jtojnar Jan Tojnar <jtojnar@gmail.com> @PerchunPak Perchun Pak <nixpkgs@perchun.it> @ttuegel Thomas Tuegel <ttuegel@mailbox.org> @khaneliman Austin Horstman <khaneliman12@gmail.com> @donovanglover Donovan Glover @fufexan Fufezan Mihai <fufexan@protonmail.com> @NotAShelf NotAShelf <raf@notashelf.dev> @johnrtitor Masum Reza <masumrezarock100@gmail.com> @romildo José Romildo Malaquias <malaquias@gmail.com> @johannesloetzsch Johannes Lötzsch <github@johannesloetzsch.de> @Daru-san Daru <zadarumaka@proton.me> @ilya-fedin Ilya Fedin <fedin-ilja2010@ya.ru> @NickCao Nick Cao <nickcao@nichi.co> @K900 Ilya K. <me@0upti.me> @LunNova Luna Nova <nixpkgs-maintainer@lunnova.dev> @mjm Matt Moriarity <matt@mattmoriarity.com> @anthonyroussel Anthony Roussel <anthony@roussel.dev> @OPNA2608 Cosima Neidahl <opna2608@protonmail.com> @davidak David Kleuker <post@davidak.de> CVE-2025-3359 6.2 MEDIUM CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): HIGH created 2 months, 2 weeks ago Gnuplot: segmentation fault via io_str_init_static_internal function A flaw was found in GNUPlot. A segmentation fault via IO_str_init_static_internal may jeopardize the environment. gnuplot <6.1 pkgs.gnuplot Portable command-line driven graphing utility for many platforms nixos-unstable ??? nixpkgs-unstable 6.0.3 pkgs.gnuplot_qt Portable command-line driven graphing utility for many platforms nixos-unstable ??? nixpkgs-unstable 6.0.3 pkgs.feedgnuplot General purpose pipe-oriented plotting tool nixos-unstable ??? nixpkgs-unstable 1.61 pkgs.gnuplot_aquaterm Portable command-line driven graphing utility for many platforms nixos-unstable ??? nixpkgs-unstable 6.0.3 pkgs.haskellPackages.gnuplot 2D and 3D plots using gnuplot nixos-unstable ??? nixpkgs-unstable 0.5.7 pkgs.chickenPackages_5.chickenEggs.gnuplot-pipe A simple interface to Gnuplot nixos-unstable ??? nixpkgs-unstable 0.4.2 pkgs.vimPlugins.nvim-treesitter-parsers.gnuplot nixos-unstable ??? nixpkgs-unstable Package maintainers: 3 @thielema Henning Thielemann <nix@henning-thielemann.de> @mnacamura Mitsuhiro Nakamura <m.nacamura@gmail.com> @lovek323 Jason O'Conal <jason@oconal.id.au>
CVE-2025-1386 created 2 months, 2 weeks ago Query smuggling in ch-go library When using the ch-go library, under a specific condition when the query includes a large, uncompressed malicious external data, it is possible for an attacker in control of such data to smuggle another query packet into the connection stream. ch-go <0.65.0 pkgs.immich-go Immich client tool for bulk-uploads nixos-unstable ??? nixpkgs-unstable 0.27.0 Package maintainers: 1 @kai-tub Kai Norman Clasen
CVE-2025-32618 8.5 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): CHANGED Confidentiality impact (C): HIGH Integrity impact (I): NONE Availability impact (A): LOW created 2 months, 2 weeks ago WordPress Wishlist plugin <= 1.0.43 - SQL Injection vulnerability Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PickPlugins Wishlist allows SQL Injection. This issue affects Wishlist: from n/a through 1.0.43. wishlist =<1.0.43 pkgs.wishlist Single entrypoint for multiple SSH endpoints nixos-unstable ??? nixpkgs-unstable 0.15.2 Package maintainers: 2 @caarlos0 Carlos A Becker <carlos@becker.software> @penguwin Nicolas Martin <penguwin@penguwin.eu>
pkgs.wishlist Single entrypoint for multiple SSH endpoints nixos-unstable ??? nixpkgs-unstable 0.15.2
CVE-2025-32230 4.3 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): LOW Availability impact (A): NONE created 2 months, 2 weeks ago WordPress Tutor LMS plugin <= 3.4.0 - HTML Injection vulnerability Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Themeum Tutor LMS. This issue affects Tutor LMS: from n/a through 3.4.0. tutor =<3.4.0 pkgs.typstPackages.tutor_0_3_0 Utilities to create exams nixos-unstable ??? nixpkgs-unstable 0.3.0 pkgs.typstPackages.tutor_0_4_0 Utilities to create exams nixos-unstable ??? nixpkgs-unstable 0.4.0 pkgs.typstPackages.tutor_0_6_1 Utilities to create exams nixos-unstable ??? nixpkgs-unstable 0.6.1 pkgs.typstPackages.tutor_0_7_0 Utilities to create exams nixos-unstable ??? nixpkgs-unstable 0.7.0 pkgs.typstPackages.tutor_0_8_0 Utilities to create exams nixos-unstable ??? nixpkgs-unstable 0.8.0 pkgs.haskellPackages.timeless-tutorials Initial project template from stack nixos-unstable ??? nixpkgs-unstable 1.0.0.0 Package maintainers: 1 @cherrypiejam Gongqi Huang
pkgs.haskellPackages.timeless-tutorials Initial project template from stack nixos-unstable ??? nixpkgs-unstable 1.0.0.0
CVE-2025-23386 7.8 HIGH CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 2 months, 2 weeks ago gerbera: Privilege escalation from user gerbera to root because of insecure %post script A Incorrect Default Permissions vulnerability in the openSUSE Tumbleweed package gerbera allows the service user gerbera to escalate to root.,This issue affects gerbera on openSUSE Tumbleweed before 2.5.0-1.1. gerbera <2.5.0-1.1 pkgs.gerbera UPnP Media Server for 2024 nixos-unstable ??? nixpkgs-unstable 2.5.0 Package maintainers: 1 @ardumont Antoine R. Dumont <eniotna.t@gmail.com>
CVE-2025-32584 7.1 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): CHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 2 months, 2 weeks ago WordPress Chat2 plugin <= 3.6.3 - CSRF to Stored XSS vulnerability Cross-Site Request Forgery (CSRF) vulnerability in Chat2 Chat2 allows Cross Site Request Forgery. This issue affects Chat2: from n/a through 3.6.3. chat2 =<3.6.3 pkgs.python312Packages.deltachat2 Client library for Delta Chat core JSON-RPC interface nixos-unstable ??? nixpkgs-unstable deltachat2-0.7.0 pkgs.python313Packages.deltachat2 Client library for Delta Chat core JSON-RPC interface nixos-unstable ??? nixpkgs-unstable deltachat2-0.7.0 Package maintainers: 1 @dotlambda Robert Schütz <rschuetz17@gmail.com>
pkgs.python312Packages.deltachat2 Client library for Delta Chat core JSON-RPC interface nixos-unstable ??? nixpkgs-unstable deltachat2-0.7.0
pkgs.python313Packages.deltachat2 Client library for Delta Chat core JSON-RPC interface nixos-unstable ??? nixpkgs-unstable deltachat2-0.7.0
CVE-2025-31003 2.7 LOW CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): HIGH User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): NONE Availability impact (A): NONE created 2 months, 2 weeks ago WordPress Squeeze plugin <= 1.6 - Full Path Disclosure (FPD) vulnerability Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Bogdan Bendziukov Squeeze allows Retrieve Embedded Sensitive Data. This issue affects Squeeze: from n/a through 1.6. squeeze =<1.6 pkgs.squeezelite Lightweight headless squeezebox client emulator nixos-unstable ??? nixpkgs-unstable 2.0.0.1541 pkgs.squeezelite-pulse Lightweight headless squeezebox client emulator nixos-unstable ??? nixpkgs-unstable 2.0.0.1541 pkgs.postgresqlPackages.pg_squeeze PostgreSQL extension for automatic bloat cleanup nixos-unstable ??? nixpkgs-unstable 1.9.0 pkgs.python312Packages.pysqueezebox Asynchronous library to control Logitech Media Server nixos-unstable ??? nixpkgs-unstable 0.12.1 pkgs.python313Packages.pysqueezebox Asynchronous library to control Logitech Media Server nixos-unstable ??? nixpkgs-unstable 0.12.1 pkgs.postgresql13Packages.pg_squeeze PostgreSQL extension for automatic bloat cleanup nixos-unstable ??? nixpkgs-unstable 1.9.0 pkgs.postgresql14Packages.pg_squeeze PostgreSQL extension for automatic bloat cleanup nixos-unstable ??? nixpkgs-unstable 1.9.0 pkgs.postgresql15Packages.pg_squeeze PostgreSQL extension for automatic bloat cleanup nixos-unstable ??? nixpkgs-unstable 1.9.0 pkgs.postgresql16Packages.pg_squeeze PostgreSQL extension for automatic bloat cleanup nixos-unstable ??? nixpkgs-unstable 1.9.0 pkgs.postgresql18Packages.pg_squeeze PostgreSQL extension for automatic bloat cleanup nixos-unstable ??? nixpkgs-unstable 1.9.0 pkgs.home-assistant-component-tests.squeezebox Open source home automation that puts local control and privacy first nixos-unstable ??? nixpkgs-unstable 2025.9.3 Package maintainers: 5 @nyanloutre Paul Trehiou <paul@nyanlout.re> @mweinelt Martin Weinelt <hexa@darmstadt.ccc.de> @fabaff Fabian Affolter <mail@fabian-affolter.ch> @dotlambda Robert Schütz <rschuetz17@gmail.com> @adamcstephens Adam C. Stephens <happy.plan4249@valkor.net>
pkgs.squeezelite Lightweight headless squeezebox client emulator nixos-unstable ??? nixpkgs-unstable 2.0.0.1541
pkgs.squeezelite-pulse Lightweight headless squeezebox client emulator nixos-unstable ??? nixpkgs-unstable 2.0.0.1541
pkgs.postgresqlPackages.pg_squeeze PostgreSQL extension for automatic bloat cleanup nixos-unstable ??? nixpkgs-unstable 1.9.0
pkgs.python312Packages.pysqueezebox Asynchronous library to control Logitech Media Server nixos-unstable ??? nixpkgs-unstable 0.12.1
pkgs.python313Packages.pysqueezebox Asynchronous library to control Logitech Media Server nixos-unstable ??? nixpkgs-unstable 0.12.1
pkgs.postgresql13Packages.pg_squeeze PostgreSQL extension for automatic bloat cleanup nixos-unstable ??? nixpkgs-unstable 1.9.0
pkgs.postgresql14Packages.pg_squeeze PostgreSQL extension for automatic bloat cleanup nixos-unstable ??? nixpkgs-unstable 1.9.0
pkgs.postgresql15Packages.pg_squeeze PostgreSQL extension for automatic bloat cleanup nixos-unstable ??? nixpkgs-unstable 1.9.0
pkgs.postgresql16Packages.pg_squeeze PostgreSQL extension for automatic bloat cleanup nixos-unstable ??? nixpkgs-unstable 1.9.0
pkgs.postgresql18Packages.pg_squeeze PostgreSQL extension for automatic bloat cleanup nixos-unstable ??? nixpkgs-unstable 1.9.0
pkgs.home-assistant-component-tests.squeezebox Open source home automation that puts local control and privacy first nixos-unstable ??? nixpkgs-unstable 2025.9.3
CVE-2025-31002 9.1 CRITICAL CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): HIGH User interaction (UI): NONE Scope (S): CHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 2 months, 2 weeks ago WordPress Squeeze plugin <= 1.6 - Arbitrary File Upload vulnerability Unrestricted Upload of File with Dangerous Type vulnerability in Bogdan Bendziukov Squeeze allows Using Malicious Files. This issue affects Squeeze: from n/a through 1.6. squeeze =<1.6 pkgs.squeezelite Lightweight headless squeezebox client emulator nixos-unstable ??? nixpkgs-unstable 2.0.0.1541 pkgs.squeezelite-pulse Lightweight headless squeezebox client emulator nixos-unstable ??? nixpkgs-unstable 2.0.0.1541 pkgs.postgresqlPackages.pg_squeeze PostgreSQL extension for automatic bloat cleanup nixos-unstable ??? nixpkgs-unstable 1.9.0 pkgs.python312Packages.pysqueezebox Asynchronous library to control Logitech Media Server nixos-unstable ??? nixpkgs-unstable 0.12.1 pkgs.python313Packages.pysqueezebox Asynchronous library to control Logitech Media Server nixos-unstable ??? nixpkgs-unstable 0.12.1 pkgs.postgresql13Packages.pg_squeeze PostgreSQL extension for automatic bloat cleanup nixos-unstable ??? nixpkgs-unstable 1.9.0 pkgs.postgresql14Packages.pg_squeeze PostgreSQL extension for automatic bloat cleanup nixos-unstable ??? nixpkgs-unstable 1.9.0 pkgs.postgresql15Packages.pg_squeeze PostgreSQL extension for automatic bloat cleanup nixos-unstable ??? nixpkgs-unstable 1.9.0 pkgs.postgresql16Packages.pg_squeeze PostgreSQL extension for automatic bloat cleanup nixos-unstable ??? nixpkgs-unstable 1.9.0 pkgs.postgresql18Packages.pg_squeeze PostgreSQL extension for automatic bloat cleanup nixos-unstable ??? nixpkgs-unstable 1.9.0 pkgs.home-assistant-component-tests.squeezebox Open source home automation that puts local control and privacy first nixos-unstable ??? nixpkgs-unstable 2025.9.3 Package maintainers: 5 @nyanloutre Paul Trehiou <paul@nyanlout.re> @mweinelt Martin Weinelt <hexa@darmstadt.ccc.de> @fabaff Fabian Affolter <mail@fabian-affolter.ch> @dotlambda Robert Schütz <rschuetz17@gmail.com> @adamcstephens Adam C. Stephens <happy.plan4249@valkor.net>
pkgs.squeezelite Lightweight headless squeezebox client emulator nixos-unstable ??? nixpkgs-unstable 2.0.0.1541
pkgs.squeezelite-pulse Lightweight headless squeezebox client emulator nixos-unstable ??? nixpkgs-unstable 2.0.0.1541
pkgs.postgresqlPackages.pg_squeeze PostgreSQL extension for automatic bloat cleanup nixos-unstable ??? nixpkgs-unstable 1.9.0
pkgs.python312Packages.pysqueezebox Asynchronous library to control Logitech Media Server nixos-unstable ??? nixpkgs-unstable 0.12.1
pkgs.python313Packages.pysqueezebox Asynchronous library to control Logitech Media Server nixos-unstable ??? nixpkgs-unstable 0.12.1
pkgs.postgresql13Packages.pg_squeeze PostgreSQL extension for automatic bloat cleanup nixos-unstable ??? nixpkgs-unstable 1.9.0
pkgs.postgresql14Packages.pg_squeeze PostgreSQL extension for automatic bloat cleanup nixos-unstable ??? nixpkgs-unstable 1.9.0
pkgs.postgresql15Packages.pg_squeeze PostgreSQL extension for automatic bloat cleanup nixos-unstable ??? nixpkgs-unstable 1.9.0
pkgs.postgresql16Packages.pg_squeeze PostgreSQL extension for automatic bloat cleanup nixos-unstable ??? nixpkgs-unstable 1.9.0
pkgs.postgresql18Packages.pg_squeeze PostgreSQL extension for automatic bloat cleanup nixos-unstable ??? nixpkgs-unstable 1.9.0
pkgs.home-assistant-component-tests.squeezebox Open source home automation that puts local control and privacy first nixos-unstable ??? nixpkgs-unstable 2025.9.3
CVE-2025-31375 7.1 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): CHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 2 months, 2 weeks ago WordPress Scheduled plugin <= 1.0 - CSRF to Stored XSS vulnerability Cross-Site Request Forgery (CSRF) vulnerability in bhoogterp Scheduled allows Stored XSS. This issue affects Scheduled: from n/a through 1.0. scheduled =<1.0 pkgs.azure-cli-extensions.scheduled-query Microsoft Azure Command-Line Tools Scheduled_query Extension nixos-unstable ??? nixpkgs-unstable 1.0.0b1 Package maintainers: 2 @ulrikstrid Ulrik Strid <ulrik.strid@outlook.com> @katexochen Paul Meyer <katexochen0@gmail.com>
pkgs.azure-cli-extensions.scheduled-query Microsoft Azure Command-Line Tools Scheduled_query Extension nixos-unstable ??? nixpkgs-unstable 1.0.0b1
CVE-2025-3416 3.7 LOW CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): LOW created 2 months, 2 weeks ago Openssl: rust-openssl use-after-free in `md::fetch` and `cipher::fetch` A flaw was found in OpenSSL's handling of the properties argument in certain functions. This vulnerability can allow use-after-free exploitation, which may result in undefined behavior or incorrect property parsing, leading to OpenSSL treating the input as an empty string. gjs polkit firefox mozjs60 openssl rpm-ostree 389-ds-base rust-bootupd rust-openssl <0.10.72 mingw-openssl kata-containers keylime-agent-rust rhtas/tuffer-rhel9 rhtas/tuftool-rhel9 389-ds:1.4/389-ds-base firefox:flatpak/firefox python3.12-cryptography redhat-ds:11/389-ds-base redhat-ds:12/389-ds-base rhtpa/rhtpa-trustification-service-rhel9 pkgs.gjs JavaScript bindings for GNOME nixos-unstable ??? nixpkgs-unstable 1.84.2 pkgs.polkit Toolkit for defining and handling the policy that allows unprivileged processes to speak to privileged processes nixos-unstable ??? nixpkgs-unstable 126 pkgs.openssl Cryptographic library that implements the SSL and TLS protocols nixos-unstable ??? nixpkgs-unstable 3.5.1 pkgs.astal.gjs Astal module for GJS nixos-unstable ??? nixpkgs-unstable 0-unstable-2025-08-29 pkgs.xulrunner Web browser built from Firefox source tree nixos-unstable ??? nixpkgs-unstable 142.0.1 pkgs.cmd-polkit Easily create polkit authentication agents by using commands nixos-unstable ??? nixpkgs-unstable 0.3.0 pkgs.firefoxpwa Tool to install, manage and use Progressive Web Apps (PWAs) in Mozilla Firefox (native component) nixos-unstable ??? nixpkgs-unstable 2.15.0 pkgs.rpm-ostree Hybrid image/package system. It uses OSTree as an image format, and uses RPM as a component model nixos-unstable ??? nixpkgs-unstable 2024.8 pkgs.openssl_1_1 Cryptographic library that implements the SSL and TLS protocols nixos-unstable ??? nixpkgs-unstable 1.1.1w pkgs.openssl_3_0 Cryptographic library that implements the SSL and TLS protocols nixos-unstable ??? nixpkgs-unstable 3.0.17 pkgs.openssl_3_5 Cryptographic library that implements the SSL and TLS protocols nixos-unstable ??? nixpkgs-unstable 3.5.1 pkgs._389-ds-base Enterprise-class Open Source LDAP server for Linux nixos-unstable ??? nixpkgs-unstable 3.1.3 pkgs.polkit_gnome Dbus session bus service that is used to bring up authentication dialogs nixos-unstable ??? nixpkgs-unstable 0.105 pkgs.tpm2-openssl OpenSSL Provider for TPM2 integration nixos-unstable ??? nixpkgs-unstable 1.3.0 pkgs.faust2firefox The faust2firefox script, part of faust functional programming language for realtime audio signal processing nixos-unstable ??? nixpkgs-unstable 2.79.3 pkgs.openssl_legacy Cryptographic library that implements the SSL and TLS protocols nixos-unstable ??? nixpkgs-unstable 3.5.1 pkgs.firefox_decrypt Tool to extract passwords from profiles of Mozilla Firefox and derivates nixos-unstable ??? nixpkgs-unstable 1.1.1 pkgs.hyprpolkitagent Polkit authentication agent written in QT/QML nixos-unstable ??? nixpkgs-unstable 0.1.3 pkgs.mate.mate-polkit Integrates polkit authentication for MATE desktop nixos-unstable ??? nixpkgs-unstable 1.28.1 pkgs.firefox-unwrapped Web browser built from Firefox source tree nixos-unstable ??? nixpkgs-unstable 142.0.1 pkgs.pcscliteWithPolkit Middleware to access a smart card using SCard API (PC/SC) nixos-unstable ??? nixpkgs-unstable 2.3.0 pkgs.firefox-sync-client Commandline-utility to list/view/edit/delete entries in a firefox-sync account nixos-unstable ??? nixpkgs-unstable 1.9.0 pkgs.libsForQt5.polkit-qt Qt wrapper around PolKit nixos-unstable ??? nixpkgs-unstable 1-0.114.0 pkgs.rubyPackages.openssl nixos-unstable ??? nixpkgs-unstable 3.3.0 pkgs.firefox-esr-unwrapped Web browser built from Firefox source tree nixos-unstable ??? nixpkgs-unstable 140.2.0esr pkgs.firefox-beta-unwrapped Web browser built from Firefox Beta Release source tree nixos-unstable ??? nixpkgs-unstable 144.0b1 pkgs.gnomeExtensions.gjs-osk A new Onscreen Keyboard built using GNOME JS nixos-unstable ??? nixpkgs-unstable 38 pkgs.kdePackages.polkit-qt-1 Qt wrapper around Polkit-1 client libraries nixos-unstable ??? nixpkgs-unstable 1-0.200.0 pkgs.php81Extensions.openssl PHP upstream extension: openssl nixos-unstable ??? nixpkgs-unstable 8.1.33 pkgs.php82Extensions.openssl PHP upstream extension: openssl nixos-unstable ??? nixpkgs-unstable 8.2.29 pkgs.php83Extensions.openssl PHP upstream extension: openssl nixos-unstable ??? nixpkgs-unstable 8.3.25 pkgs.php84Extensions.openssl PHP upstream extension: openssl nixos-unstable ??? nixpkgs-unstable 8.4.12 pkgs.haskellPackages.hopenssl FFI Bindings to OpenSSL's EVP Digest Interface nixos-unstable ??? nixpkgs-unstable 2.2.5 pkgs.rubyPackages_3_1.openssl nixos-unstable ??? nixpkgs-unstable 3.3.0 pkgs.rubyPackages_3_2.openssl nixos-unstable ??? nixpkgs-unstable 3.3.0 pkgs.rubyPackages_3_3.openssl nixos-unstable ??? nixpkgs-unstable 3.3.0 pkgs.rubyPackages_3_4.openssl nixos-unstable ??? nixpkgs-unstable 3.3.0 pkgs.bruteforce-salted-openssl Try to find the password of file encrypted with OpenSSL nixos-unstable ??? nixpkgs-unstable 1.5.0 pkgs.plasma5Packages.polkit-qt Qt wrapper around PolKit nixos-unstable ??? nixpkgs-unstable 1-0.114.0 pkgs.python312Packages.pypugjs PugJS syntax template adapter for Django, Jinja2, Mako and Tornado templates nixos-unstable ??? nixpkgs-unstable 5.12.0 pkgs.python313Packages.pypugjs PugJS syntax template adapter for Django, Jinja2, Mako and Tornado templates nixos-unstable ??? nixpkgs-unstable 5.12.0 pkgs.lomiri.lomiri-polkit-agent Policy kit agent for the Lomiri desktop nixos-unstable ??? nixpkgs-unstable 0.3 pkgs.python312Packages.pyopenssl Python wrapper around the OpenSSL library nixos-unstable ??? nixpkgs-unstable 25.1.0 pkgs.python313Packages.pyopenssl Python wrapper around the OpenSSL library nixos-unstable ??? nixpkgs-unstable 25.1.0 pkgs.firefox-devedition-unwrapped Web browser built from Firefox Developer Edition source tree nixos-unstable ??? nixpkgs-unstable 144.0b1 pkgs.python312Packages.aioopenssl TLS-capable transport using OpenSSL for asyncio nixos-unstable ??? nixpkgs-unstable 0.6.0 pkgs.python313Packages.aioopenssl TLS-capable transport using OpenSSL for asyncio nixos-unstable ??? nixpkgs-unstable 0.6.0 pkgs.luaPackages.lua-resty-openssl No summary nixos-unstable ??? nixpkgs-unstable 1.6.4-1 pkgs.kdePackages.polkit-kde-agent-1 Daemon providing a Polkit authentication UI for Plasma nixos-unstable ??? nixpkgs-unstable 1-6.4.5 pkgs.pantheon.pantheon-agent-polkit Polkit Agent for the Pantheon Desktop nixos-unstable ??? nixpkgs-unstable 8.0.1 pkgs.php81Extensions.openssl-legacy PHP upstream extension: openssl-legacy nixos-unstable ??? nixpkgs-unstable 8.1.33 pkgs.php82Extensions.openssl-legacy PHP upstream extension: openssl-legacy nixos-unstable ??? nixpkgs-unstable 8.2.29 pkgs.php83Extensions.openssl-legacy PHP upstream extension: openssl-legacy nixos-unstable ??? nixpkgs-unstable 8.3.25 pkgs.php84Extensions.openssl-legacy PHP upstream extension: openssl-legacy nixos-unstable ??? nixpkgs-unstable 8.4.12 pkgs.python312Packages.cryptography Package which provides cryptographic recipes and primitives nixos-unstable ??? nixpkgs-unstable 45.0.4 pkgs.haskellPackages.openssl-streams OpenSSL network support for io-streams nixos-unstable ??? nixpkgs-unstable 1.2.3.0 pkgs.lua51Packages.lua-resty-openssl No summary nixos-unstable ??? nixpkgs-unstable 1.6.4-1 pkgs.lua52Packages.lua-resty-openssl No summary nixos-unstable ??? nixpkgs-unstable 1.6.4-1 pkgs.lua53Packages.lua-resty-openssl No summary nixos-unstable ??? nixpkgs-unstable 1.6.4-1 pkgs.lua54Packages.lua-resty-openssl No summary nixos-unstable ??? nixpkgs-unstable 1.6.4-1 pkgs.gnomeExtensions.firefox-profiles Easily launch Firefox with your favorite profile right from the indicator menu! nixos-unstable ??? nixpkgs-unstable 4 pkgs.luajitPackages.lua-resty-openssl No summary nixos-unstable ??? nixpkgs-unstable 1.6.4-1 pkgs.haskellPackages.openssl-createkey Create OpenSSL keypairs nixos-unstable ??? nixpkgs-unstable 0.1 pkgs.python312Packages.types-pyopenssl Typing stubs for pyopenssl nixos-unstable ??? nixpkgs-unstable 24.1.0.20240722 pkgs.python313Packages.types-pyopenssl Typing stubs for pyopenssl nixos-unstable ??? nixpkgs-unstable 24.1.0.20240722 pkgs.haskellPackages.cryptonite-openssl Crypto stuff using OpenSSL cryptographic library nixos-unstable ??? nixpkgs-unstable 0.7 pkgs.haskellPackages.http-client-openssl http-client backend using the OpenSSL library nixos-unstable ??? nixpkgs-unstable 0.3.3 pkgs.chickenPackages_5.chickenEggs.openssl Bindings to the OpenSSL SSL/TLS library nixos-unstable ??? nixpkgs-unstable 2.2.6 pkgs.tests.pkg-config.defaultPkgConfigPackages.libssl Test whether openssl-3.5.1 exposes pkg-config modules libssl nixos-unstable ??? nixpkgs-unstable pkgs.tests.pkg-config.defaultPkgConfigPackages.openssl Test whether openssl-3.5.1 exposes pkg-config modules openssl nixos-unstable ??? nixpkgs-unstable pkgs.tests.pkg-config.defaultPkgConfigPackages.libcrypto Test whether openssl-3.5.1 exposes pkg-config modules libcrypto nixos-unstable ??? nixpkgs-unstable pkgs.tests.testers.hasPkgConfigModules.openssl-has-openssl Test whether openssl-3.5.1 exposes pkg-config modules openssl nixos-unstable ??? nixpkgs-unstable pkgs.vscode-extensions.firefox-devtools.vscode-firefox-debug Visual Studio Code extension for debugging web applications and browser extensions in Firefox nixos-unstable ??? nixpkgs-unstable 2.15.0 pkgs.tests.testers.hasPkgConfigModules.openssl-has-all-meta-pkgConfigModules Test whether openssl-3.5.1 exposes pkg-config modules libcrypto, libssl, openssl nixos-unstable ??? nixpkgs-unstable Package maintainers: 48 @thillux Markus Theil <theil.markus@gmail.com> @ulrikstrid Ulrik Strid <ulrik.strid@outlook.com> @aanderse Aaron Andersen <aaron@fosslib.net> @talyz Kim Lindberger <kim.lindberger@gmail.com> @piotrkwiecinski Piotr Kwiecinski <piokwiecinski+nixpkgs@gmail.com> @Ma27 Maximilian Bosch <maximilian@mbosch.me> @dotlambda Robert Schütz <rschuetz17@gmail.com> @gador Florian Brandes <florian.brandes@posteo.de> @octodi octodi <octodi@proton.me> @stv0g Steffen Vogel <post@steffenvogel.de> @peti Peter Simons <simons@cryp.to> @pmahoney Patrick Mahoney <pat@polycrystal.org> @magnetophon Bart Brouns <bart@magnetophon.nl> @jopejoe1 jopejoe1 <nixpkgs@missing.ninja> @rhendric Ryan Hendrickson @mweinelt Martin Weinelt <hexa@darmstadt.ccc.de> @ambroisie Bruno BELANYI <bruno.nixpkgs@belanyi.fr> @unode Renato Alves <alves.rjc@gmail.com> @schnusch schnusch @camillemndn Camille M. <camillemondon@free.fr> @pasqui23 pasqui23 <p3dimaria@hotmail.it> @felschr Felix Schröter <dev@felschr.com> @honnip Jung seungwoo <me@honnip.page> @SuperSandro2000 Sandro Jäckel <sandro.jaeckel@gmail.com> @ners ners <ners@gmx.ch> @lopsided98 Ben Wolsieffer <benwolsieffer@gmail.com> @hedning Tor Hedin Brønner <torhedinbronner@gmail.com> @dasj19 Daniel Șerbănescu <daniel@serbanescu.dk> @bobby285271 Bobby Rong <rjl931189261@126.com> @jtojnar Jan Tojnar <jtojnar@gmail.com> @PerchunPak Perchun Pak <nixpkgs@perchun.it> @ttuegel Thomas Tuegel <ttuegel@mailbox.org> @khaneliman Austin Horstman <khaneliman12@gmail.com> @donovanglover Donovan Glover @fufexan Fufezan Mihai <fufexan@protonmail.com> @NotAShelf NotAShelf <raf@notashelf.dev> @johnrtitor Masum Reza <masumrezarock100@gmail.com> @romildo José Romildo Malaquias <malaquias@gmail.com> @johannesloetzsch Johannes Lötzsch <github@johannesloetzsch.de> @Daru-san Daru <zadarumaka@proton.me> @ilya-fedin Ilya Fedin <fedin-ilja2010@ya.ru> @NickCao Nick Cao <nickcao@nichi.co> @K900 Ilya K. <me@0upti.me> @LunNova Luna Nova <nixpkgs-maintainer@lunnova.dev> @mjm Matt Moriarity <matt@mattmoriarity.com> @anthonyroussel Anthony Roussel <anthony@roussel.dev> @OPNA2608 Cosima Neidahl <opna2608@protonmail.com> @davidak David Kleuker <post@davidak.de>
pkgs.polkit Toolkit for defining and handling the policy that allows unprivileged processes to speak to privileged processes nixos-unstable ??? nixpkgs-unstable 126
pkgs.openssl Cryptographic library that implements the SSL and TLS protocols nixos-unstable ??? nixpkgs-unstable 3.5.1
pkgs.xulrunner Web browser built from Firefox source tree nixos-unstable ??? nixpkgs-unstable 142.0.1
pkgs.cmd-polkit Easily create polkit authentication agents by using commands nixos-unstable ??? nixpkgs-unstable 0.3.0
pkgs.firefoxpwa Tool to install, manage and use Progressive Web Apps (PWAs) in Mozilla Firefox (native component) nixos-unstable ??? nixpkgs-unstable 2.15.0
pkgs.rpm-ostree Hybrid image/package system. It uses OSTree as an image format, and uses RPM as a component model nixos-unstable ??? nixpkgs-unstable 2024.8
pkgs.openssl_1_1 Cryptographic library that implements the SSL and TLS protocols nixos-unstable ??? nixpkgs-unstable 1.1.1w
pkgs.openssl_3_0 Cryptographic library that implements the SSL and TLS protocols nixos-unstable ??? nixpkgs-unstable 3.0.17
pkgs.openssl_3_5 Cryptographic library that implements the SSL and TLS protocols nixos-unstable ??? nixpkgs-unstable 3.5.1
pkgs._389-ds-base Enterprise-class Open Source LDAP server for Linux nixos-unstable ??? nixpkgs-unstable 3.1.3
pkgs.polkit_gnome Dbus session bus service that is used to bring up authentication dialogs nixos-unstable ??? nixpkgs-unstable 0.105
pkgs.faust2firefox The faust2firefox script, part of faust functional programming language for realtime audio signal processing nixos-unstable ??? nixpkgs-unstable 2.79.3
pkgs.openssl_legacy Cryptographic library that implements the SSL and TLS protocols nixos-unstable ??? nixpkgs-unstable 3.5.1
pkgs.firefox_decrypt Tool to extract passwords from profiles of Mozilla Firefox and derivates nixos-unstable ??? nixpkgs-unstable 1.1.1
pkgs.hyprpolkitagent Polkit authentication agent written in QT/QML nixos-unstable ??? nixpkgs-unstable 0.1.3
pkgs.mate.mate-polkit Integrates polkit authentication for MATE desktop nixos-unstable ??? nixpkgs-unstable 1.28.1
pkgs.firefox-unwrapped Web browser built from Firefox source tree nixos-unstable ??? nixpkgs-unstable 142.0.1
pkgs.pcscliteWithPolkit Middleware to access a smart card using SCard API (PC/SC) nixos-unstable ??? nixpkgs-unstable 2.3.0
pkgs.firefox-sync-client Commandline-utility to list/view/edit/delete entries in a firefox-sync account nixos-unstable ??? nixpkgs-unstable 1.9.0
pkgs.firefox-esr-unwrapped Web browser built from Firefox source tree nixos-unstable ??? nixpkgs-unstable 140.2.0esr
pkgs.firefox-beta-unwrapped Web browser built from Firefox Beta Release source tree nixos-unstable ??? nixpkgs-unstable 144.0b1
pkgs.gnomeExtensions.gjs-osk A new Onscreen Keyboard built using GNOME JS nixos-unstable ??? nixpkgs-unstable 38
pkgs.kdePackages.polkit-qt-1 Qt wrapper around Polkit-1 client libraries nixos-unstable ??? nixpkgs-unstable 1-0.200.0
pkgs.php81Extensions.openssl PHP upstream extension: openssl nixos-unstable ??? nixpkgs-unstable 8.1.33
pkgs.php82Extensions.openssl PHP upstream extension: openssl nixos-unstable ??? nixpkgs-unstable 8.2.29
pkgs.php83Extensions.openssl PHP upstream extension: openssl nixos-unstable ??? nixpkgs-unstable 8.3.25
pkgs.php84Extensions.openssl PHP upstream extension: openssl nixos-unstable ??? nixpkgs-unstable 8.4.12
pkgs.haskellPackages.hopenssl FFI Bindings to OpenSSL's EVP Digest Interface nixos-unstable ??? nixpkgs-unstable 2.2.5
pkgs.bruteforce-salted-openssl Try to find the password of file encrypted with OpenSSL nixos-unstable ??? nixpkgs-unstable 1.5.0
pkgs.plasma5Packages.polkit-qt Qt wrapper around PolKit nixos-unstable ??? nixpkgs-unstable 1-0.114.0
pkgs.python312Packages.pypugjs PugJS syntax template adapter for Django, Jinja2, Mako and Tornado templates nixos-unstable ??? nixpkgs-unstable 5.12.0
pkgs.python313Packages.pypugjs PugJS syntax template adapter for Django, Jinja2, Mako and Tornado templates nixos-unstable ??? nixpkgs-unstable 5.12.0
pkgs.lomiri.lomiri-polkit-agent Policy kit agent for the Lomiri desktop nixos-unstable ??? nixpkgs-unstable 0.3
pkgs.python312Packages.pyopenssl Python wrapper around the OpenSSL library nixos-unstable ??? nixpkgs-unstable 25.1.0
pkgs.python313Packages.pyopenssl Python wrapper around the OpenSSL library nixos-unstable ??? nixpkgs-unstable 25.1.0
pkgs.firefox-devedition-unwrapped Web browser built from Firefox Developer Edition source tree nixos-unstable ??? nixpkgs-unstable 144.0b1
pkgs.python312Packages.aioopenssl TLS-capable transport using OpenSSL for asyncio nixos-unstable ??? nixpkgs-unstable 0.6.0
pkgs.python313Packages.aioopenssl TLS-capable transport using OpenSSL for asyncio nixos-unstable ??? nixpkgs-unstable 0.6.0
pkgs.kdePackages.polkit-kde-agent-1 Daemon providing a Polkit authentication UI for Plasma nixos-unstable ??? nixpkgs-unstable 1-6.4.5
pkgs.pantheon.pantheon-agent-polkit Polkit Agent for the Pantheon Desktop nixos-unstable ??? nixpkgs-unstable 8.0.1
pkgs.php81Extensions.openssl-legacy PHP upstream extension: openssl-legacy nixos-unstable ??? nixpkgs-unstable 8.1.33
pkgs.php82Extensions.openssl-legacy PHP upstream extension: openssl-legacy nixos-unstable ??? nixpkgs-unstable 8.2.29
pkgs.php83Extensions.openssl-legacy PHP upstream extension: openssl-legacy nixos-unstable ??? nixpkgs-unstable 8.3.25
pkgs.php84Extensions.openssl-legacy PHP upstream extension: openssl-legacy nixos-unstable ??? nixpkgs-unstable 8.4.12
pkgs.python312Packages.cryptography Package which provides cryptographic recipes and primitives nixos-unstable ??? nixpkgs-unstable 45.0.4
pkgs.haskellPackages.openssl-streams OpenSSL network support for io-streams nixos-unstable ??? nixpkgs-unstable 1.2.3.0
pkgs.gnomeExtensions.firefox-profiles Easily launch Firefox with your favorite profile right from the indicator menu! nixos-unstable ??? nixpkgs-unstable 4
pkgs.haskellPackages.openssl-createkey Create OpenSSL keypairs nixos-unstable ??? nixpkgs-unstable 0.1
pkgs.python312Packages.types-pyopenssl Typing stubs for pyopenssl nixos-unstable ??? nixpkgs-unstable 24.1.0.20240722
pkgs.python313Packages.types-pyopenssl Typing stubs for pyopenssl nixos-unstable ??? nixpkgs-unstable 24.1.0.20240722
pkgs.haskellPackages.cryptonite-openssl Crypto stuff using OpenSSL cryptographic library nixos-unstable ??? nixpkgs-unstable 0.7
pkgs.haskellPackages.http-client-openssl http-client backend using the OpenSSL library nixos-unstable ??? nixpkgs-unstable 0.3.3
pkgs.chickenPackages_5.chickenEggs.openssl Bindings to the OpenSSL SSL/TLS library nixos-unstable ??? nixpkgs-unstable 2.2.6
pkgs.tests.pkg-config.defaultPkgConfigPackages.libssl Test whether openssl-3.5.1 exposes pkg-config modules libssl nixos-unstable ??? nixpkgs-unstable
pkgs.tests.pkg-config.defaultPkgConfigPackages.openssl Test whether openssl-3.5.1 exposes pkg-config modules openssl nixos-unstable ??? nixpkgs-unstable
pkgs.tests.pkg-config.defaultPkgConfigPackages.libcrypto Test whether openssl-3.5.1 exposes pkg-config modules libcrypto nixos-unstable ??? nixpkgs-unstable
pkgs.tests.testers.hasPkgConfigModules.openssl-has-openssl Test whether openssl-3.5.1 exposes pkg-config modules openssl nixos-unstable ??? nixpkgs-unstable
pkgs.vscode-extensions.firefox-devtools.vscode-firefox-debug Visual Studio Code extension for debugging web applications and browser extensions in Firefox nixos-unstable ??? nixpkgs-unstable 2.15.0
pkgs.tests.testers.hasPkgConfigModules.openssl-has-all-meta-pkgConfigModules Test whether openssl-3.5.1 exposes pkg-config modules libcrypto, libssl, openssl nixos-unstable ??? nixpkgs-unstable
CVE-2025-3359 6.2 MEDIUM CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): HIGH created 2 months, 2 weeks ago Gnuplot: segmentation fault via io_str_init_static_internal function A flaw was found in GNUPlot. A segmentation fault via IO_str_init_static_internal may jeopardize the environment. gnuplot <6.1 pkgs.gnuplot Portable command-line driven graphing utility for many platforms nixos-unstable ??? nixpkgs-unstable 6.0.3 pkgs.gnuplot_qt Portable command-line driven graphing utility for many platforms nixos-unstable ??? nixpkgs-unstable 6.0.3 pkgs.feedgnuplot General purpose pipe-oriented plotting tool nixos-unstable ??? nixpkgs-unstable 1.61 pkgs.gnuplot_aquaterm Portable command-line driven graphing utility for many platforms nixos-unstable ??? nixpkgs-unstable 6.0.3 pkgs.haskellPackages.gnuplot 2D and 3D plots using gnuplot nixos-unstable ??? nixpkgs-unstable 0.5.7 pkgs.chickenPackages_5.chickenEggs.gnuplot-pipe A simple interface to Gnuplot nixos-unstable ??? nixpkgs-unstable 0.4.2 pkgs.vimPlugins.nvim-treesitter-parsers.gnuplot nixos-unstable ??? nixpkgs-unstable Package maintainers: 3 @thielema Henning Thielemann <nix@henning-thielemann.de> @mnacamura Mitsuhiro Nakamura <m.nacamura@gmail.com> @lovek323 Jason O'Conal <jason@oconal.id.au>
pkgs.gnuplot Portable command-line driven graphing utility for many platforms nixos-unstable ??? nixpkgs-unstable 6.0.3
pkgs.gnuplot_qt Portable command-line driven graphing utility for many platforms nixos-unstable ??? nixpkgs-unstable 6.0.3
pkgs.feedgnuplot General purpose pipe-oriented plotting tool nixos-unstable ??? nixpkgs-unstable 1.61
pkgs.gnuplot_aquaterm Portable command-line driven graphing utility for many platforms nixos-unstable ??? nixpkgs-unstable 6.0.3
pkgs.chickenPackages_5.chickenEggs.gnuplot-pipe A simple interface to Gnuplot nixos-unstable ??? nixpkgs-unstable 0.4.2