CVE-2025-32050 5.9 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): HIGH created 3 months ago Libsoup: integer overflow in append_param_quoted A flaw was found in libsoup. The libsoup append_param_quoted() function may contain an overflow bug resulting in a buffer under-read. Affected products libsoup <3.6.1 * libsoup3 mingw-freetype * spice-client-win * Matching in nixpkgs pkgs.libsoup_3 HTTP client/server library for GNOME nixos-unstable ??? nixpkgs-unstable 3.6.5 pkgs.libsoup_2_4 HTTP client/server library for GNOME nixos-unstable ??? nixpkgs-unstable 2.74.3 pkgs.tests.pkg-config.defaultPkgConfigPackages."libsoup-gnome-2.4" Test whether libsoup-2.74.3 exposes pkg-config modules libsoup-gnome-2.4 nixos-unstable ??? nixpkgs-unstable Package maintainers: 6 @dasj19 Daniel Șerbănescu <daniel@serbanescu.dk> @bobby285271 Bobby Rong <rjl931189261@126.com> @lovek323 Jason O'Conal <jason@oconal.id.au> @7c6f434c Michael Raskin <7c6f434c@mail.ru> @jtojnar Jan Tojnar <jtojnar@gmail.com> @hedning Tor Hedin Brønner <torhedinbronner@gmail.com>
pkgs.tests.pkg-config.defaultPkgConfigPackages."libsoup-gnome-2.4" Test whether libsoup-2.74.3 exposes pkg-config modules libsoup-gnome-2.4 nixos-unstable ??? nixpkgs-unstable
CVE-2025-31746 6.4 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): CHANGED Confidentiality impact (C): NONE Integrity impact (I): LOW Availability impact (A): LOW created 3 months ago WordPress Clients plugin <= 1.1.4 - Broken Access Control vulnerability Missing Authorization vulnerability in Think201 Clients allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Clients: from n/a through 1.1.4. Affected products clients =<1.1.4 Matching in nixpkgs pkgs.xlsclients Utility to list client applications running on a X11 display nixos-unstable ??? nixpkgs-unstable 1.1.5 pkgs.argus-clients Clients for ARGUS nixos-unstable ??? nixpkgs-unstable 3.0.8.3 pkgs.xorg.xlsclients Utility to list client applications running on a X11 display nixos-unstable ??? nixpkgs-unstable 1.1.5 pkgs.haskellPackages.clientsession Securely store session data in a client-side cookie nixos-unstable ??? nixpkgs-unstable 0.9.3.0 pkgs.haskellPackages.wai-session-clientsession Session store based on clientsession nixos-unstable ??? nixpkgs-unstable 0.1 Package maintainers: 1 @leenaars Michiel Leenaars <ml.software@leenaa.rs>
pkgs.xlsclients Utility to list client applications running on a X11 display nixos-unstable ??? nixpkgs-unstable 1.1.5
pkgs.xorg.xlsclients Utility to list client applications running on a X11 display nixos-unstable ??? nixpkgs-unstable 1.1.5
pkgs.haskellPackages.clientsession Securely store session data in a client-side cookie nixos-unstable ??? nixpkgs-unstable 0.9.3.0
pkgs.haskellPackages.wai-session-clientsession Session store based on clientsession nixos-unstable ??? nixpkgs-unstable 0.1
CVE-2025-32051 5.9 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): HIGH created 3 months ago Libsoup: segmentation fault when parsing malformed data uri A flaw was found in libsoup. The libsoup soup_uri_decode_data_uri() function may crash when processing malformed data URI. This flaw allows an attacker to cause a denial of service (DoS). Affected products libsoup <3.6.1 libsoup3 Matching in nixpkgs pkgs.libsoup_3 HTTP client/server library for GNOME nixos-unstable ??? nixpkgs-unstable 3.6.5 pkgs.libsoup_2_4 HTTP client/server library for GNOME nixos-unstable ??? nixpkgs-unstable 2.74.3 pkgs.tests.pkg-config.defaultPkgConfigPackages."libsoup-gnome-2.4" Test whether libsoup-2.74.3 exposes pkg-config modules libsoup-gnome-2.4 nixos-unstable ??? nixpkgs-unstable Package maintainers: 6 @dasj19 Daniel Șerbănescu <daniel@serbanescu.dk> @bobby285271 Bobby Rong <rjl931189261@126.com> @lovek323 Jason O'Conal <jason@oconal.id.au> @7c6f434c Michael Raskin <7c6f434c@mail.ru> @jtojnar Jan Tojnar <jtojnar@gmail.com> @hedning Tor Hedin Brønner <torhedinbronner@gmail.com>
pkgs.tests.pkg-config.defaultPkgConfigPackages."libsoup-gnome-2.4" Test whether libsoup-2.74.3 exposes pkg-config modules libsoup-gnome-2.4 nixos-unstable ??? nixpkgs-unstable
CVE-2025-30596 6.5 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): NONE Availability impact (A): NONE created 3 months ago WordPress include-file <= 1 - Arbitrary File Download Vulnerability Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in NotFound include-file allows Path Traversal. This issue affects include-file: from n/a through 1. Affected products include-file =<1 Matching in nixpkgs pkgs.haskellPackages.include-file Inclusion of files in executables at compile-time nixos-unstable ??? nixpkgs-unstable 0.1.0.4
pkgs.haskellPackages.include-file Inclusion of files in executables at compile-time nixos-unstable ??? nixpkgs-unstable 0.1.0.4
CVE-2025-32049 7.5 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): HIGH created 3 months ago Libsoup: denial of service attack to websocket server A flaw was found in libsoup. The SoupWebsocketConnection may accept a large WebSocket message, which may cause libsoup to allocate memory and lead to a denial of service (DoS). Affected products libsoup * =<3.6.4 libsoup3 * Matching in nixpkgs pkgs.libsoup_3 HTTP client/server library for GNOME nixos-unstable ??? nixpkgs-unstable 3.6.5 pkgs.libsoup_2_4 HTTP client/server library for GNOME nixos-unstable ??? nixpkgs-unstable 2.74.3 pkgs.tests.pkg-config.defaultPkgConfigPackages."libsoup-gnome-2.4" Test whether libsoup-2.74.3 exposes pkg-config modules libsoup-gnome-2.4 nixos-unstable ??? nixpkgs-unstable Package maintainers: 6 @dasj19 Daniel Șerbănescu <daniel@serbanescu.dk> @bobby285271 Bobby Rong <rjl931189261@126.com> @lovek323 Jason O'Conal <jason@oconal.id.au> @7c6f434c Michael Raskin <7c6f434c@mail.ru> @jtojnar Jan Tojnar <jtojnar@gmail.com> @hedning Tor Hedin Brønner <torhedinbronner@gmail.com>
pkgs.tests.pkg-config.defaultPkgConfigPackages."libsoup-gnome-2.4" Test whether libsoup-2.74.3 exposes pkg-config modules libsoup-gnome-2.4 nixos-unstable ??? nixpkgs-unstable
CVE-2025-2784 7.0 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): HIGH created 3 months ago Libsoup: heap buffer over-read in `skip_insignificant_space` when sniffing content A flaw was found in libsoup. The package is vulnerable to a heap buffer over-read when sniffing content via the skip_insight_whitespace() function. Libsoup clients may read one byte out-of-bounds in response to a crafted HTTP response by an HTTP server. Affected products libsoup <3.6.5 * libsoup3 * Matching in nixpkgs pkgs.libsoup_3 HTTP client/server library for GNOME nixos-unstable ??? nixpkgs-unstable 3.6.5 pkgs.libsoup_2_4 HTTP client/server library for GNOME nixos-unstable ??? nixpkgs-unstable 2.74.3 pkgs.tests.pkg-config.defaultPkgConfigPackages."libsoup-gnome-2.4" Test whether libsoup-2.74.3 exposes pkg-config modules libsoup-gnome-2.4 nixos-unstable ??? nixpkgs-unstable Package maintainers: 6 @dasj19 Daniel Șerbănescu <daniel@serbanescu.dk> @bobby285271 Bobby Rong <rjl931189261@126.com> @lovek323 Jason O'Conal <jason@oconal.id.au> @7c6f434c Michael Raskin <7c6f434c@mail.ru> @jtojnar Jan Tojnar <jtojnar@gmail.com> @hedning Tor Hedin Brønner <torhedinbronner@gmail.com>
pkgs.tests.pkg-config.defaultPkgConfigPackages."libsoup-gnome-2.4" Test whether libsoup-2.74.3 exposes pkg-config modules libsoup-gnome-2.4 nixos-unstable ??? nixpkgs-unstable
CVE-2025-32052 6.5 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): NONE Availability impact (A): LOW created 3 months ago Libsoup: heap buffer overflow in sniff_unknown() A flaw was found in libsoup. A vulnerability in the sniff_unknown() function may lead to heap buffer over-read. Affected products libsoup <3.6.1 * libsoup3 mingw-freetype * spice-client-win * Matching in nixpkgs pkgs.libsoup_3 HTTP client/server library for GNOME nixos-unstable ??? nixpkgs-unstable 3.6.5 pkgs.libsoup_2_4 HTTP client/server library for GNOME nixos-unstable ??? nixpkgs-unstable 2.74.3 pkgs.tests.pkg-config.defaultPkgConfigPackages."libsoup-gnome-2.4" Test whether libsoup-2.74.3 exposes pkg-config modules libsoup-gnome-2.4 nixos-unstable ??? nixpkgs-unstable Package maintainers: 6 @dasj19 Daniel Șerbănescu <daniel@serbanescu.dk> @bobby285271 Bobby Rong <rjl931189261@126.com> @lovek323 Jason O'Conal <jason@oconal.id.au> @7c6f434c Michael Raskin <7c6f434c@mail.ru> @jtojnar Jan Tojnar <jtojnar@gmail.com> @hedning Tor Hedin Brønner <torhedinbronner@gmail.com>
pkgs.tests.pkg-config.defaultPkgConfigPackages."libsoup-gnome-2.4" Test whether libsoup-2.74.3 exposes pkg-config modules libsoup-gnome-2.4 nixos-unstable ??? nixpkgs-unstable
CVE-2025-3155 6.5 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): NONE Availability impact (A): NONE created 3 months ago Yelp: arbitrary file read A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an external environment. Affected products yelp <42.2-8 * yelp-xsl * Matching in nixpkgs pkgs.yelp Help viewer for GNOME nixos-unstable ??? nixpkgs-unstable 42.3 pkgs.yelp-xsl Yelp's universal stylesheets for Mallard and DocBook nixos-unstable ??? nixpkgs-unstable 42.4 pkgs.yelp-tools Small programs that help you create, edit, manage, and publish your Mallard or DocBook documentation nixos-unstable ??? nixpkgs-unstable 42.1 Package maintainers: 4 @hedning Tor Hedin Brønner <torhedinbronner@gmail.com> @jtojnar Jan Tojnar <jtojnar@gmail.com> @dasj19 Daniel Șerbănescu <daniel@serbanescu.dk> @bobby285271 Bobby Rong <rjl931189261@126.com>
pkgs.yelp-xsl Yelp's universal stylesheets for Mallard and DocBook nixos-unstable ??? nixpkgs-unstable 42.4
pkgs.yelp-tools Small programs that help you create, edit, manage, and publish your Mallard or DocBook documentation nixos-unstable ??? nixpkgs-unstable 42.1
CVE-2025-32053 6.5 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): NONE Availability impact (A): LOW created 3 months ago Libsoup: heap buffer overflows in sniff_feed_or_html() and skip_insignificant_space() A flaw was found in libsoup. A vulnerability in sniff_feed_or_html() and skip_insignificant_space() functions may lead to a heap buffer over-read. Affected products libsoup <3.6.1 * libsoup3 mingw-freetype * spice-client-win * Matching in nixpkgs pkgs.libsoup_3 HTTP client/server library for GNOME nixos-unstable ??? nixpkgs-unstable 3.6.5 pkgs.libsoup_2_4 HTTP client/server library for GNOME nixos-unstable ??? nixpkgs-unstable 2.74.3 pkgs.tests.pkg-config.defaultPkgConfigPackages."libsoup-gnome-2.4" Test whether libsoup-2.74.3 exposes pkg-config modules libsoup-gnome-2.4 nixos-unstable ??? nixpkgs-unstable Package maintainers: 6 @dasj19 Daniel Șerbănescu <daniel@serbanescu.dk> @bobby285271 Bobby Rong <rjl931189261@126.com> @lovek323 Jason O'Conal <jason@oconal.id.au> @7c6f434c Michael Raskin <7c6f434c@mail.ru> @jtojnar Jan Tojnar <jtojnar@gmail.com> @hedning Tor Hedin Brønner <torhedinbronner@gmail.com>
pkgs.tests.pkg-config.defaultPkgConfigPackages."libsoup-gnome-2.4" Test whether libsoup-2.74.3 exposes pkg-config modules libsoup-gnome-2.4 nixos-unstable ??? nixpkgs-unstable
CVE-2008-0888 created 3 months ago The NEEDBITS macro in the inflate_dynamic function in inflate.c for … The NEEDBITS macro in the inflate_dynamic function in inflate.c for unzip can be invoked using invalid buffers, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger a free of uninitialized or previously-freed data. Affected products unzip <6.0 Matching in nixpkgs pkgs.unzip Extraction utility for archives compressed in .zip format nixos-unstable ??? nixpkgs-unstable 6.0 pkgs.runzip Tool to convert filename encoding inside a ZIP archive nixos-unstable ??? nixpkgs-unstable 1.4 pkgs.ripunzip Tool to unzip files in parallel nixos-unstable ??? nixpkgs-unstable 2.0.3 pkgs.unzipNLS Extraction utility for archives compressed in .zip format nixos-unstable ??? nixpkgs-unstable 6.0 pkgs.haskellPackages.unzip-traversable Unzip functions for general Traversable containers nixos-unstable ??? nixpkgs-unstable 0.1.1 pkgs.haskellPackages.wai-middleware-gunzip WAI middleware to unzip request bodies nixos-unstable ??? nixpkgs-unstable 0.0.2 Package maintainers: 3 @RossComputerGuy Tristan Ross <tristan.ross@midstall.com> @7c6f434c Michael Raskin <7c6f434c@mail.ru> @LeSuisse Thomas Gerbet <thomas@gerbet.me>
pkgs.unzip Extraction utility for archives compressed in .zip format nixos-unstable ??? nixpkgs-unstable 6.0
pkgs.runzip Tool to convert filename encoding inside a ZIP archive nixos-unstable ??? nixpkgs-unstable 1.4
pkgs.unzipNLS Extraction utility for archives compressed in .zip format nixos-unstable ??? nixpkgs-unstable 6.0
pkgs.haskellPackages.unzip-traversable Unzip functions for general Traversable containers nixos-unstable ??? nixpkgs-unstable 0.1.1
pkgs.haskellPackages.wai-middleware-gunzip WAI middleware to unzip request bodies nixos-unstable ??? nixpkgs-unstable 0.0.2