CVE-2025-10284 9.6 CRITICAL CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): CHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 1 month ago Improper Archive Extraction in unarchive Enables RCE BBOT's unarchive module could be abused by supplying malicious archives files and when extracted can then perform an arbitrary file write, resulting in remote code execution. Affected products bbot =<2.6.1 Matching in nixpkgs pkgs.hebbot Matrix bot which can generate "This Week in X" like blog posts nixos-25.05 2.1-unstable-2024-09-20 nixpkgs-25.05-darwin 2.1-unstable-2024-09-20 nixos-25.05-small 2.1-unstable-2024-09-20 nixos-unstable 2.1-unstable-2024-09-20 nixos-unstable-small 2.1-unstable-2024-09-20 nixpkgs-unstable 2.1-unstable-2024-09-20 Package maintainers: 1 @a-kenji Alexander Kenji Berthold <aks.kenji@protonmail.com>
pkgs.hebbot Matrix bot which can generate "This Week in X" like blog posts nixos-25.05 2.1-unstable-2024-09-20 nixpkgs-25.05-darwin 2.1-unstable-2024-09-20 nixos-25.05-small 2.1-unstable-2024-09-20 nixos-unstable 2.1-unstable-2024-09-20 nixos-unstable-small 2.1-unstable-2024-09-20 nixpkgs-unstable 2.1-unstable-2024-09-20
CVE-2025-10282 4.7 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): CHANGED Confidentiality impact (C): LOW Integrity impact (I): NONE Availability impact (A): NONE created 1 month ago GitLab Domain Confusion in gitlab Leaks API Key BBOT's gitlab module could be abused to disclose a GitLab API key to an attacker controlled server with a malicious formatted git URL. Affected products bbot =<2.6.1 Matching in nixpkgs pkgs.hebbot Matrix bot which can generate "This Week in X" like blog posts nixos-25.05 2.1-unstable-2024-09-20 nixpkgs-25.05-darwin 2.1-unstable-2024-09-20 nixos-25.05-small 2.1-unstable-2024-09-20 nixos-unstable 2.1-unstable-2024-09-20 nixos-unstable-small 2.1-unstable-2024-09-20 nixpkgs-unstable 2.1-unstable-2024-09-20 Package maintainers: 1 @a-kenji Alexander Kenji Berthold <aks.kenji@protonmail.com>
pkgs.hebbot Matrix bot which can generate "This Week in X" like blog posts nixos-25.05 2.1-unstable-2024-09-20 nixpkgs-25.05-darwin 2.1-unstable-2024-09-20 nixos-25.05-small 2.1-unstable-2024-09-20 nixos-unstable 2.1-unstable-2024-09-20 nixos-unstable-small 2.1-unstable-2024-09-20 nixpkgs-unstable 2.1-unstable-2024-09-20
CVE-2025-11561 8.8 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 1 month ago Sssd: sssd default kerberos configuration allows privilege escalation on ad-joined linux systems A flaw was found in the integration of Active Directory and the System Security Services Daemon (SSSD) on Linux systems. In default configurations, SSSD does not enable the Kerberos local authentication plugin (sssd_krb5_localauth_plugin), allowing an attacker with permission to modify certain AD attributes (such as userPrincipalName or samAccountName) to impersonate privileged users. This can result in unauthorized access or privilege escalation on domain-joined Linux hosts. Affected products sssd =<2.11.1 * rhcos * Matching in nixpkgs pkgs.sssd System Security Services Daemon nixos-25.05 2.9.5 nixpkgs-25.05-darwin 2.9.5 nixos-25.05-small 2.9.5 nixos-unstable 2.9.7 nixos-unstable-small 2.9.7 nixpkgs-unstable 2.9.7 Package maintainers: 1 @illustris Harikrishnan R <me@illustris.tech>
pkgs.sssd System Security Services Daemon nixos-25.05 2.9.5 nixpkgs-25.05-darwin 2.9.5 nixos-25.05-small 2.9.5 nixos-unstable 2.9.7 nixos-unstable-small 2.9.7 nixpkgs-unstable 2.9.7
CVE-2025-10281 4.7 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): CHANGED Confidentiality impact (C): LOW Integrity impact (I): NONE Availability impact (A): NONE created 1 month ago Insecure URL Handling in git_clone Leading to Leaked API Key BBOT's git_clone module could be abused to disclose a GitHub API key to an attacker controlled server with a malicious formatted git URL. Affected products bbot =<2.6.1 Matching in nixpkgs pkgs.hebbot Matrix bot which can generate "This Week in X" like blog posts nixos-25.05 2.1-unstable-2024-09-20 nixpkgs-25.05-darwin 2.1-unstable-2024-09-20 nixos-25.05-small 2.1-unstable-2024-09-20 nixos-unstable 2.1-unstable-2024-09-20 nixos-unstable-small 2.1-unstable-2024-09-20 nixpkgs-unstable 2.1-unstable-2024-09-20 Package maintainers: 1 @a-kenji Alexander Kenji Berthold <aks.kenji@protonmail.com>
pkgs.hebbot Matrix bot which can generate "This Week in X" like blog posts nixos-25.05 2.1-unstable-2024-09-20 nixpkgs-25.05-darwin 2.1-unstable-2024-09-20 nixos-25.05-small 2.1-unstable-2024-09-20 nixos-unstable 2.1-unstable-2024-09-20 nixos-unstable-small 2.1-unstable-2024-09-20 nixpkgs-unstable 2.1-unstable-2024-09-20
CVE-2025-53881 created 1 month ago SUSE-specific logrotate configuration allows escalation from mail user/group to root A UNIX Symbolic Link (Symlink) Following vulnerability in logrotate config in the exim package allowed privilege escalation from mail user/group to root.This issue affects Tumbleweed: from ? before 4.98.2-lp156.248.1. Affected products exim <4.98.2-lp156.248.1 Matching in nixpkgs pkgs.exim Mail transfer agent (MTA) nixos-25.05 4.98.2 nixpkgs-25.05-darwin 4.98.2 nixos-25.05-small 4.98.2 nixos-unstable 4.98.2 nixos-unstable-small 4.98.2 nixpkgs-unstable 4.98.2 Package maintainers: 4 @helsinki-Jo Joachim Ernst <joachim.ernst@helsinki-systems.de> @dasJ Janne Heß <janne@hess.ooo> @4z3 Tomislav Viljetić <tv@krebsco.de> @Conni2461 Simon Hauser <simon-hauser@outlook.com>
pkgs.exim Mail transfer agent (MTA) nixos-25.05 4.98.2 nixpkgs-25.05-darwin 4.98.2 nixos-25.05-small 4.98.2 nixos-unstable 4.98.2 nixos-unstable-small 4.98.2 nixpkgs-unstable 4.98.2
CVE-2024-3049 7.4 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): NONE created 1 month ago Booth: specially crafted hash can lead to invalid hmac being accepted by booth server A flaw was found in Booth, a cluster ticket manager. If a specially-crafted hash is passed to gcry_md_get_algo_dlen(), it may allow an invalid HMAC to be accepted by the Booth server. Affected products booth ==1.0-283.1 * Matching in nixpkgs pkgs.libsForQt5.booth Camera application nixos-25.05 1.1.3 nixpkgs-25.05-darwin 1.1.3 nixos-25.05-small 1.1.3 pkgs.plasma5Packages.booth Camera application nixos-25.05 1.1.3 nixpkgs-25.05-darwin 1.1.3 nixos-25.05-small 1.1.3
pkgs.libsForQt5.booth Camera application nixos-25.05 1.1.3 nixpkgs-25.05-darwin 1.1.3 nixos-25.05-small 1.1.3
pkgs.plasma5Packages.booth Camera application nixos-25.05 1.1.3 nixpkgs-25.05-darwin 1.1.3 nixos-25.05-small 1.1.3
CVE-2025-54831 7.5 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): NONE Availability impact (A): NONE created 1 month ago Apache Airflow: Connection sensitive details exposed to users with READ permissions Apache Airflow 3 introduced a change to the handling of sensitive information in Connections. The intent was to restrict access to sensitive connection fields to Connection Editing Users, effectively applying a "write-only" model for sensitive values. In Airflow 3.0.3, this model was unintentionally violated: sensitive connection information could be viewed by users with READ permissions through both the API and the UI. This behavior also bypassed the `AIRFLOW__CORE__HIDE_SENSITIVE_VAR_CONN_FIELDS` configuration option. This issue does not affect Airflow 2.x, where exposing sensitive information to connection editors was the intended and documented behavior. Users of Airflow 3.0.3 are advised to upgrade Airflow to >=3.0.4. Affected products apache-airflow ==3.0.3 Matching in nixpkgs pkgs.apache-airflow Programmatically author, schedule and monitor data pipelines nixos-25.05 2.7.3 nixpkgs-25.05-darwin 2.7.3 nixos-25.05-small 2.7.3 nixos-unstable 2.7.3 nixos-unstable-small 2.7.3 nixpkgs-unstable 2.7.3 Package maintainers: 3 @bhipple Benjamin Hipple <bhipple@protonmail.com> @gbpdt Graham Bennett <nix@pdtpartners.com> @ingenieroariel Ariel Nunez <ariel@nunez.co>
pkgs.apache-airflow Programmatically author, schedule and monitor data pipelines nixos-25.05 2.7.3 nixpkgs-25.05-darwin 2.7.3 nixos-25.05-small 2.7.3 nixos-unstable 2.7.3 nixos-unstable-small 2.7.3 nixpkgs-unstable 2.7.3
CVE-2025-11021 7.5 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): NONE Availability impact (A): NONE created 1 month ago Libsoup: out-of-bounds read in cookie date handling of libsoup http library A flaw was found in the cookie date handling logic of the libsoup HTTP library, widely used by GNOME and other applications for web communication. When processing cookies with specially crafted expiration dates, the library may perform an out-of-bounds memory read. This flaw could result in unintended disclosure of memory contents, potentially exposing sensitive information from the process using libsoup. Affected products libsoup =<3.6.5 * libsoup3 * Matching in nixpkgs pkgs.libsoup_3 HTTP client/server library for GNOME nixos-25.05 3.6.5 nixpkgs-25.05-darwin 3.6.5 nixos-25.05-small 3.6.5 nixos-unstable 3.6.5 nixos-unstable-small 3.6.5 nixpkgs-unstable 3.6.5 pkgs.libsoup_2_4 HTTP client/server library for GNOME nixos-25.05 2.74.3 nixpkgs-25.05-darwin 2.74.3 nixos-25.05-small 2.74.3 nixos-unstable 2.74.3 nixos-unstable-small 2.74.3 nixpkgs-unstable 2.74.3 pkgs.tests.pkg-config.defaultPkgConfigPackages."libsoup-gnome-2.4" Test whether libsoup-2.74.3 exposes pkg-config modules libsoup-gnome-2.4 nixos-25.05 ??? nixpkgs-25.05-darwin nixos-25.05-small nixos-unstable ??? nixos-unstable-small nixpkgs-unstable Package maintainers: 6 @dasj19 Daniel Șerbănescu <daniel@serbanescu.dk> @bobby285271 Bobby Rong <rjl931189261@126.com> @lovek323 Jason O'Conal <jason@oconal.id.au> @7c6f434c Michael Raskin <7c6f434c@mail.ru> @hedning Tor Hedin Brønner <torhedinbronner@gmail.com> @jtojnar Jan Tojnar <jtojnar@gmail.com>
pkgs.libsoup_3 HTTP client/server library for GNOME nixos-25.05 3.6.5 nixpkgs-25.05-darwin 3.6.5 nixos-25.05-small 3.6.5 nixos-unstable 3.6.5 nixos-unstable-small 3.6.5 nixpkgs-unstable 3.6.5
pkgs.libsoup_2_4 HTTP client/server library for GNOME nixos-25.05 2.74.3 nixpkgs-25.05-darwin 2.74.3 nixos-25.05-small 2.74.3 nixos-unstable 2.74.3 nixos-unstable-small 2.74.3 nixpkgs-unstable 2.74.3
pkgs.tests.pkg-config.defaultPkgConfigPackages."libsoup-gnome-2.4" Test whether libsoup-2.74.3 exposes pkg-config modules libsoup-gnome-2.4 nixos-25.05 ??? nixpkgs-25.05-darwin nixos-25.05-small nixos-unstable ??? nixos-unstable-small nixpkgs-unstable
CVE-2025-10911 5.5 MEDIUM CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): HIGH created 1 month ago Libxslt: use-after-free with key data stored cross-rvt A use-after-free vulnerability was found in libxslt while parsing xsl nodes that may lead to the dereference of expired pointers and application crash. Affected products rhcos libxslt =<1.1.43 Matching in nixpkgs pkgs.libxslt C library and tools to do XSL transformations nixos-25.05 1.1.43 nixpkgs-25.05-darwin 1.1.43 nixos-25.05-small 1.1.43 nixos-unstable 1.1.43 nixos-unstable-small 1.1.43 nixpkgs-unstable 1.1.43 pkgs.python312Packages.libxslt C library and tools to do XSL transformations nixos-25.05 1.1.43 nixpkgs-25.05-darwin 1.1.43 nixos-25.05-small 1.1.43 nixos-unstable 1.1.43 nixos-unstable-small 1.1.43 nixpkgs-unstable 1.1.43 pkgs.python313Packages.libxslt C library and tools to do XSL transformations nixos-25.05 1.1.43 nixpkgs-25.05-darwin 1.1.43 nixos-25.05-small 1.1.43 nixos-unstable 1.1.43 nixos-unstable-small 1.1.43 nixpkgs-unstable 1.1.43 Package maintainers: 1 @jtojnar Jan Tojnar <jtojnar@gmail.com>
pkgs.libxslt C library and tools to do XSL transformations nixos-25.05 1.1.43 nixpkgs-25.05-darwin 1.1.43 nixos-25.05-small 1.1.43 nixos-unstable 1.1.43 nixos-unstable-small 1.1.43 nixpkgs-unstable 1.1.43
pkgs.python312Packages.libxslt C library and tools to do XSL transformations nixos-25.05 1.1.43 nixpkgs-25.05-darwin 1.1.43 nixos-25.05-small 1.1.43 nixos-unstable 1.1.43 nixos-unstable-small 1.1.43 nixpkgs-unstable 1.1.43
pkgs.python313Packages.libxslt C library and tools to do XSL transformations nixos-25.05 1.1.43 nixpkgs-25.05-darwin 1.1.43 nixos-25.05-small 1.1.43 nixos-unstable 1.1.43 nixos-unstable-small 1.1.43 nixpkgs-unstable 1.1.43
CVE-2025-60018 4.8 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): NONE Availability impact (A): LOW created 1 month ago Glib-networking: out of bound reads on glib-networking through tls/openssl/gtlscertificate-openssl.c via "g_tls_certificate_openssl_get_property()" glib-networking's OpenSSL backend fails to properly check the return value of a call to BIO_write(), resulting in an out of bounds read. Affected products glib-networking <2.80.2 Matching in nixpkgs pkgs.glib-networking Network-related giomodules for glib nixos-25.05 2.80.1 nixpkgs-25.05-darwin 2.80.1 nixos-25.05-small 2.80.1 nixos-unstable 2.80.1 nixos-unstable-small 2.80.1 nixpkgs-unstable 2.80.1 Package maintainers: 4 @dasj19 Daniel Șerbănescu <daniel@serbanescu.dk> @hedning Tor Hedin Brønner <torhedinbronner@gmail.com> @jtojnar Jan Tojnar <jtojnar@gmail.com> @bobby285271 Bobby Rong <rjl931189261@126.com>
pkgs.glib-networking Network-related giomodules for glib nixos-25.05 2.80.1 nixpkgs-25.05-darwin 2.80.1 nixos-25.05-small 2.80.1 nixos-unstable 2.80.1 nixos-unstable-small 2.80.1 nixpkgs-unstable 2.80.1