⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Automatically generated suggestions

Create Draft to queue a suggestion for refinement.

Dismiss to remove a suggestion from the queue.

CVE-2025-6017
5.5 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): NONE
  • Availability impact (A): NONE
created 1 month ago
Rhacm: users with clusterreader role can see credentials from managed-clusters

A flaw was found in Red Hat Advanced Cluster Management through versions 2.10, before 2.10.7, 2.11, before 2.11.4, and 2.12, before 2.12.4. This vulnerability allows an unprivileged user to view confidential managed cluster credentials through the UI. This information should only be accessible to authorized users and may result in the loss of confidentiality of administrative information, which could be leaked to unauthorized actors.

ocm
<0.16.0
rhacm2/console-rhel8

pkgs.ocm

CLI for the Red Hat OpenShift Cluster Manager

pkgs.procmail

Mail processing and filtering utility

pkgs.neocmakelsp

CMake lsp based on tower-lsp and treesitter

pkgs.rocmPackages.hsakmt

Platform runtime for ROCm

pkgs.rocmPackages.rocm-smi

System management interface for AMD GPUs supported by ROCm

pkgs.rocmPackages.rocmPath

pkgs.rocmPackages.rocminfo

ROCm Application for Reporting System Info

pkgs.rocmPackages_6.hsakmt

Platform runtime for ROCm

pkgs.rocmPackages.rocm-core

Utility for getting the ROCm release version

pkgs.rocmPackages.rocm-cmake

CMake modules for common build tasks for the ROCm stack

pkgs.rocmPackages.rocm-comgr

APIs for compiling and inspecting AMDGPU code objects

pkgs.rocmPackages.rocm-tests

  • nixos-unstable ???
    • nixpkgs-unstable

pkgs.rocmPackages_6.rocm-smi

System management interface for AMD GPUs supported by ROCm

pkgs.rocmPackages_6.rocmPath

pkgs.rocmPackages_6.rocminfo

ROCm Application for Reporting System Info

pkgs.python312Packages.aiocmd

Asyncio-based automatic CLI creation tool using prompt-toolkit
  • nixos-unstable ???
    • nixpkgs-unstable

pkgs.python313Packages.aiocmd

Asyncio-based automatic CLI creation tool using prompt-toolkit
  • nixos-unstable ???
    • nixpkgs-unstable

pkgs.rocmPackages_6.rocm-core

Utility for getting the ROCm release version

pkgs.rocmPackages.llvm.rocmcxx

  • nixos-unstable ???
    • nixpkgs-unstable

pkgs.rocmPackages.rocmlir-rock

MLIR-based convolution and GEMM kernel generator

pkgs.rocmPackages_6.rocm-cmake

CMake modules for common build tasks for the ROCm stack

pkgs.rocmPackages_6.rocm-comgr

APIs for compiling and inspecting AMDGPU code objects

pkgs.rocmPackages_6.rocm-tests

  • nixos-unstable ???
    • nixpkgs-unstable

pkgs.rocmPackages.rocm-docs-core

ROCm Documentation Python package for ReadTheDocs build standardization

pkgs.rocmPackages_6.llvm.rocmcxx

  • nixos-unstable ???
    • nixpkgs-unstable

pkgs.rocmPackages_6.rocm-runtime

Platform runtime for ROCm

pkgs.rocmPackages_6.rocmlir-rock

MLIR-based convolution and GEMM kernel generator

pkgs.rocmPackages.rocm-device-libs

Set of AMD-specific device-side language runtime libraries

pkgs.rocmPackages_6.rocm-docs-core

ROCm Documentation Python package for ReadTheDocs build standardization

pkgs.rocmPackages_6.rocm-device-libs

Set of AMD-specific device-side language runtime libraries

pkgs.rocmPackages_6.rocm-merged-llvm

  • nixos-unstable ???
    • nixpkgs-unstable

pkgs.python312Packages.procmon-parser

Parser to process monitor file formats

pkgs.python313Packages.procmon-parser

Parser to process monitor file formats

pkgs.rocmPackages.rocm-bandwidth-test

Bandwidth test for AMD GPUs supported by ROCm

pkgs.python312Packages.djangocms-alias

Lean enterprise content management powered by Django

pkgs.python313Packages.djangocms-alias

Lean enterprise content management powered by Django

pkgs.rocmPackages.llvm.rocm-merged-llvm

  • nixos-unstable ???
    • nixpkgs-unstable

pkgs.rocmPackages_6.rocm-bandwidth-test

Bandwidth test for AMD GPUs supported by ROCm

pkgs.rocmPackages_6.llvm.rocm-merged-llvm

  • nixos-unstable ???
    • nixpkgs-unstable

pkgs.python312Packages.djangocms-admin-style

Django Theme tailored to the needs of django CMS

pkgs.python313Packages.djangocms-admin-style

Django Theme tailored to the needs of django CMS

pkgs.python312Packages.djangocms-text-ckeditor

Text Plugin for django CMS using CKEditor 4

pkgs.python313Packages.djangocms-text-ckeditor

Text Plugin for django CMS using CKEditor 4
Package maintainers: 13
CVE-2025-9959
7.6 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): REQUIRED
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): HIGH
  • Availability impact (A): LOW
created 1 month ago
Sandbox escape in smolagents Local Python execution environment via dunder attributes

Incomplete validation of dunder attributes allows an attacker to escape from the Local Python execution environment sandbox, enforced by smolagents. The attack requires a Prompt Injection in order to trick the agent to create malicious code.

smolagents
<1.21.0

pkgs.python312Packages.smolagents

Barebones library for agents

pkgs.python313Packages.smolagents

Barebones library for agents
Package maintainers: 1
CVE-2025-9901
5.9 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): HIGH
  • Privileges required (PR): NONE
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): NONE
  • Availability impact (A): NONE
created 1 month ago
Libsoup: improper handling of http vary header in libsoup caching

A flaw was found in libsoup’s caching mechanism, SoupCache, where the HTTP Vary header is ignored when evaluating cached responses. This header ensures that responses vary appropriately based on request headers such as language or authentication. Without this check, cached content can be incorrectly reused across different requests, potentially exposing sensitive user information. While the issue is unlikely to affect everyday desktop use, it could result in confidentiality breaches in proxy or multi-user environments.

libsoup
libsoup3

pkgs.libsoup_3

HTTP client/server library for GNOME

pkgs.libsoup_2_4

HTTP client/server library for GNOME

pkgs.tests.pkg-config.defaultPkgConfigPackages."libsoup-gnome-2.4"

Test whether libsoup-2.74.3 exposes pkg-config modules libsoup-gnome-2.4
  • nixos-unstable ???
    • nixpkgs-unstable
Package maintainers: 6
CVE-2025-7039
3.7 LOW
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): HIGH
  • Privileges required (PR): NONE
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): NONE
  • Integrity impact (I): LOW
  • Availability impact (A): NONE
created 1 month ago
Glib: buffer under-read on glib through glib/gfileutils.c via get_tmp_file()

A flaw was found in glib. An integer overflow during temporary file creation leads to an out-of-bounds memory access, allowing an attacker to potentially perform path traversal or access private temporary file content by creating symbolic links. This vulnerability allows a local attacker to manipulate file paths and access unauthorized data. The core issue stems from insufficient validation of file path lengths during temporary file operations.

bootc
glib2
loupe
librsvg2
rpm-ostree
mingw-glib2
glycin-loaders

pkgs.bootc

Boot and upgrade via container images

pkgs.loupe

Simple image viewer application written with GTK4 and Rust

pkgs.rpm-ostree

Hybrid image/package system. It uses OSTree as an image format, and uses RPM as a component model

pkgs.podman-bootc

Streamlining podman+bootc interactions

pkgs.mlxbf-bootctl

Control BlueField boot partitions

pkgs.glycin-loaders

Glycin loaders for several formats

pkgs.systemd-bootchart

Boot performance graphing tool from systemd
Package maintainers: 10
CVE-2024-3508
4.3 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): NONE
  • Integrity impact (I): NONE
  • Availability impact (A): LOW
created 1 month ago
Bzip2: compressed content bomb leads to denial of service of bombastic api

A flaw was found in Bombastic, which allows authenticated users to upload compressed (bzip2 or zstd) SBOMs. The API endpoint verifies the presence of some fields and values in the JSON. To perform this verification, the uploaded file must first be decompressed.

bzip2
==faa7a496c5d98e0f0859dd2c623eddf82289eaa8
SBOM-Management-(Bombastic)

pkgs.bzip2

High-quality data compression program

pkgs.lbzip2

Parallel bzip2 compression utility

pkgs.pbzip2

Parallel implementation of bzip2 for multi-core machines

pkgs.bzip2_1_1

High-quality data compression program

pkgs.indexed-bzip2

Python library for parallel decompression and seeking within compressed bzip2 files

pkgs.haskellPackages.bzip2-clib

bzip2 C sources

pkgs.python312Packages.indexed-bzip2

Python library for parallel decompression and seeking within compressed bzip2 files

pkgs.python313Packages.indexed-bzip2

Python library for parallel decompression and seeking within compressed bzip2 files

pkgs.tests.pkg-config.defaultPkgConfigPackages.bzip2

Test whether bzip2-1.0.8 exposes pkg-config modules bzip2
Package maintainers: 2
CVE-2025-40927
7.3 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): LOW
  • Availability impact (A): LOW
created 1 month ago
CGI::Simple versions 1.281 and earlier for Perl has a HTTP response splitting flaw

CGI::Simple versions before 1.282 for Perl has a HTTP response splitting flaw This vulnerability is a confirmed HTTP response splitting flaw in CGI::Simple that allows HTTP response header injection, which can be used for reflected XSS or open redirect under certain conditions. Although some validation exists, it can be bypassed using URL-encoded values, allowing an attacker to inject untrusted content into the response via query parameters. As a result, an attacker can inject a line break (e.g. %0A) into the parameter value, causing the server to split the HTTP response and inject arbitrary headers or even an HTML/JavaScript body, leading to reflected cross-site scripting (XSS), open redirect or other attacks. The issue documented in CVE-2010-4410 https://www.cve.org/CVERecord?id=CVE-2010-4410 is related but the fix was incomplete. Impact By injecting %0A (newline) into a query string parameter, an attacker can: * Break the current HTTP header * Inject a new header or entire body * Deliver a script payload that is reflected in the server’s response That can lead to the following attacks: * reflected XSS * open redirect * cache poisoning * header manipulation

CGI-Simple
<1.282

pkgs.perlPackages.CGISimple

Simple totally OO CGI interface that is CGI.pm compliant

pkgs.perl538Packages.CGISimple

Simple totally OO CGI interface that is CGI.pm compliant

pkgs.perl540Packages.CGISimple

Simple totally OO CGI interface that is CGI.pm compliant
CVE-2025-54725
9.8 CRITICAL
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): HIGH
created 1 month ago
WordPress Golo Theme <= 1.7.0 - Broken Authentication Vulnerability

Authentication Bypass Using an Alternate Path or Channel vulnerability in uxper Golo allows Authentication Abuse. This issue affects Golo: from n/a through 1.7.0.

golo
=<1.7.0

pkgs.ligolo-ng

Tunneling/pivoting tool that uses a TUN interface

pkgs.xfce.gigolo

Frontend to easily manage connections to remote filesystems
Package maintainers: 3
CVE-2025-8067
8.5 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): NONE
  • Scope (S): CHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): LOW
  • Availability impact (A): HIGH
created 1 month ago
Udisks: out-of-bounds read in udisks daemon

A flaw was found in the Udisks daemon, where it allows unprivileged users to create loop devices using the D-BUS system. This is achieved via the loop device handler, which handles requests sent through the D-BUS interface. As two of the parameters of this handle, it receives the file descriptor list and index specifying the file where the loop device should be backed. The function itself validates the index value to ensure it isn't bigger than the maximum value allowed. However, it fails to validate the lower bound, allowing the index parameter to be a negative value. Under these circumstances, an attacker can cause the UDisks daemon to crash or perform a local privilege escalation by gaining access to files owned by privileged users.

udisks
udisks2
*

pkgs.udisks2

Daemon, tools and libraries to access and manipulate disks, storage devices and technologies
Package maintainers: 2
CVE-2025-54724
7.1 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): REQUIRED
  • Scope (S): CHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): LOW
  • Availability impact (A): LOW
created 1 month ago
WordPress Golo Theme <= 1.7.1 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uxper Golo allows Reflected XSS. This issue affects Golo: from n/a through 1.7.1.

golo
=<1.7.1

pkgs.ligolo-ng

Tunneling/pivoting tool that uses a TUN interface

pkgs.xfce.gigolo

Frontend to easily manage connections to remote filesystems
Package maintainers: 3
CVE-2025-58209
6.5 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): REQUIRED
  • Scope (S): CHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): LOW
  • Availability impact (A): LOW
created 1 month ago
WordPress Transcoder Plugin <= 1.4.0 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rtCamp Transcoder allows Stored XSS. This issue affects Transcoder: from n/a through 1.4.0.

transcoder
=<1.4.0

pkgs.haskellPackages.amazonka-elastictranscoder

Amazon Elastic Transcoder SDK

pkgs.python312Packages.types-aiobotocore-elastictranscoder

Type annotations for aiobotocore elastictranscoder

pkgs.python313Packages.types-aiobotocore-elastictranscoder

Type annotations for aiobotocore elastictranscoder
Package maintainers: 2