Jboss eap: wildfly-elytron has a ssrf security issue
A flaw was found in` JwtValidator.resolvePublicKey` in JBoss EAP, where the validator checks jku and sends a HTTP request. During this process, no whitelisting or other filtering behavior is performed on the destination URL address, which may result in a server-side request forgery (SSRF) vulnerability.
Affected products
- <32.0.0.Final
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
Matching in nixpkgs
pkgs.reap
Run process until all its spawned processes are dead
-
nixos-unstable -
- nixpkgs-unstable 0.3-unreleased
pkgs.leaps
Pair programming tool and library written in Golang
-
nixos-unstable -
- nixpkgs-unstable 0.9.1
pkgs.asleap
Recovers weak LEAP and PPTP passwords
-
nixos-unstable -
- nixpkgs-unstable 0-unstable-2021-06-20
pkgs.heaptrack
Heap memory profiler for Linux
-
nixos-unstable -
- nixpkgs-unstable 1.5.0-unstable-2025-07-21
pkgs.input-leap
Open-source KVM software
-
nixos-unstable -
- nixpkgs-unstable 3.0.3
pkgs.tuleap-cli
Command-line interface for the Tuleap API
-
nixos-unstable -
- nixpkgs-unstable 1.2.0
pkgs.libfreeaptx
Free Implementation of Audio Processing Technology codec (aptX)
-
nixos-unstable -
- nixpkgs-unstable 0.2.2
pkgs.sbclPackages.heap
None
-
nixos-unstable -
- nixpkgs-unstable 20181018-git
pkgs.haxePackages.heaps
GPU game framework
-
nixos-unstable -
- nixpkgs-unstable 1.9.1
pkgs.pineapple-pictures
Homebrew lightweight image viewer
-
nixos-unstable -
- nixpkgs-unstable 1.1.1
pkgs.haskellPackages.eap
Extensible Authentication Protocol (EAP)
-
nixos-unstable -
- nixpkgs-unstable 0.9.0.2
pkgs.haskellPackages.heap
Heaps in Haskell
-
nixos-unstable -
- nixpkgs-unstable 1.0.4
pkgs.reaper-sws-extension
Reaper Plugin Extension
-
nixos-unstable -
- nixpkgs-unstable 2.14.0.3
pkgs.sbclPackages.cl-heap
None
-
nixos-unstable -
- nixpkgs-unstable 0.1.6
pkgs.sbclPackages.minheap
None
-
nixos-unstable -
- nixpkgs-unstable 20160628-git
pkgs.haskellPackages.heaps
Asymptotically optimal Brodal/Okasaki heaps
-
nixos-unstable -
- nixpkgs-unstable 0.4.1
pkgs.akkuPackages.pfds-heap
Heap data structure
-
nixos-unstable -
- nixpkgs-unstable 1.0.0
pkgs.luaPackages.binaryheap
Binary heap implementation in pure Lua
-
nixos-unstable -
- nixpkgs-unstable 0.4-1
pkgs.python312Packages.deap
Novel evolutionary computation framework for rapid prototyping and testing of ideas
-
nixos-unstable -
- nixpkgs-unstable 1.4.3
pkgs.python313Packages.deap
Novel evolutionary computation framework for rapid prototyping and testing of ideas
-
nixos-unstable -
- nixpkgs-unstable 1.4.3
pkgs.gnomeExtensions.ideapad
Lenovo IdeaPad goodies for Gnome Shell
-
nixos-unstable -
- nixpkgs-unstable 20
pkgs.haskellPackages.heapsize
Determine the size of runtime data structures
-
nixos-unstable -
- nixpkgs-unstable 0.3.0.1
pkgs.lua51Packages.binaryheap
Binary heap implementation in pure Lua
-
nixos-unstable -
- nixpkgs-unstable 0.4-1
pkgs.lua52Packages.binaryheap
Binary heap implementation in pure Lua
-
nixos-unstable -
- nixpkgs-unstable 0.4-1
pkgs.lua53Packages.binaryheap
Binary heap implementation in pure Lua
-
nixos-unstable -
- nixpkgs-unstable 0.4-1
pkgs.lua54Packages.binaryheap
Binary heap implementation in pure Lua
-
nixos-unstable -
- nixpkgs-unstable 0.4-1
pkgs.python312Packages.pyeapi
Client for Arista eAPI
-
nixos-unstable -
- nixpkgs-unstable 1.0.4
pkgs.python313Packages.pyeapi
Client for Arista eAPI
-
nixos-unstable -
- nixpkgs-unstable 1.0.4
pkgs.reaper-reapack-extension
Package manager for REAPER
-
nixos-unstable -
- nixpkgs-unstable 1.2.5
pkgs.luajitPackages.binaryheap
Binary heap implementation in pure Lua
-
nixos-unstable -
- nixpkgs-unstable 0.4-1
pkgs.python312Packages.coreapi
Python client library for Core API
-
nixos-unstable -
- nixpkgs-unstable 2.3.3
pkgs.haskellPackages.cheapskate
Experimental markdown processor
-
nixos-unstable -
- nixpkgs-unstable 0.1.1.2
pkgs.perlPackages.HeapFibonacci
Perl extensions for keeping data partially sorted
-
nixos-unstable -
- nixpkgs-unstable 0.80
pkgs.python312Packages.heapdict
Heap with decrease-key and increase-key operations
-
nixos-unstable -
- nixpkgs-unstable 1.0.1
pkgs.python313Packages.heapdict
Heap with decrease-key and increase-key operations
-
nixos-unstable -
- nixpkgs-unstable 1.0.1
pkgs.sbclPackages.binomial-heap
None
-
nixos-unstable -
- nixpkgs-unstable 20130420-git
pkgs.python312Packages.jaydebeapi
Use JDBC database drivers from Python 2/3 or Jython with a DB-API
-
nixos-unstable -
- nixpkgs-unstable 1.2.3
pkgs.python313Packages.jaydebeapi
Use JDBC database drivers from Python 2/3 or Jython with a DB-API
-
nixos-unstable -
- nixpkgs-unstable 1.2.3
pkgs.haskellPackages.ghc-heap-view
Extract the heap representation of Haskell values and thunks
-
nixos-unstable -
- nixpkgs-unstable 0.6.4.1
pkgs.haskellPackages.meldable-heap
Asymptotically optimal, Coq-verified meldable heaps, AKA priority queues
-
nixos-unstable -
- nixpkgs-unstable 2.0.3
pkgs.perl538Packages.HeapFibonacci
Perl extensions for keeping data partially sorted
-
nixos-unstable -
- nixpkgs-unstable 0.80
pkgs.perl540Packages.HeapFibonacci
Perl extensions for keeping data partially sorted
-
nixos-unstable -
- nixpkgs-unstable 0.80
pkgs.python312Packages.pynamecheap
Namecheap API client in Python
-
nixos-unstable -
- nixpkgs-unstable 0.0.3
pkgs.python313Packages.pynamecheap
Namecheap API client in Python
-
nixos-unstable -
- nixpkgs-unstable 0.0.3
pkgs.terraform-providers.namecheap
None
-
nixos-unstable -
- nixpkgs-unstable 2.2.0
pkgs.python312Packages.tami4edgeapi
Python API client for Tami4 Edge / Edge+ devices
-
nixos-unstable -
- nixpkgs-unstable tami4edgeapi-3.0
pkgs.python313Packages.tami4edgeapi
Python API client for Tami4 Edge / Edge+ devices
-
nixos-unstable -
- nixpkgs-unstable tami4edgeapi-3.0
pkgs.python312Packages.aioesphomeapi
Python Client for ESPHome native API
-
nixos-unstable -
- nixpkgs-unstable 39.0.1
pkgs.python313Packages.aioesphomeapi
Python Client for ESPHome native API
-
nixos-unstable -
- nixpkgs-unstable 39.0.1
pkgs.gnomeExtensions.ideapad-controls
Control Lenovo IdeaPad laptops options: Conservation Mode, Camera Lock, Fn Lock, Touchpad Lock, USB charging
-
nixos-unstable -
- nixpkgs-unstable 3
pkgs.haskellPackages.cheapskate-lucid
Use cheapskate with Lucid
-
nixos-unstable -
- nixpkgs-unstable 0.1.0.0
pkgs.gnomeExtensions.transcodeappsearch
Searching apps both direct and transcoded name (English, Russian, Ukrainian langs)
-
nixos-unstable -
- nixpkgs-unstable 19
pkgs.rubyPackages.jekyll-theme-leap-day
None
-
nixos-unstable -
- nixpkgs-unstable 0.1.1
pkgs.azure-cli-extensions.healthcareapis
Microsoft Azure Command-Line Tools HealthcareApisManagementClient Extension
-
nixos-unstable -
- nixpkgs-unstable 1.0.1
pkgs.haskellPackages.leapseconds-announced
Leap seconds announced at library release time
-
nixos-unstable -
- nixpkgs-unstable 2017.1.0.1
pkgs.rubyPackages_3_1.jekyll-theme-leap-day
None
-
nixos-unstable -
- nixpkgs-unstable 0.1.1
pkgs.rubyPackages_3_2.jekyll-theme-leap-day
None
-
nixos-unstable -
- nixpkgs-unstable 0.1.1
pkgs.rubyPackages_3_3.jekyll-theme-leap-day
None
-
nixos-unstable -
- nixpkgs-unstable 0.1.1
pkgs.rubyPackages_3_4.jekyll-theme-leap-day
None
-
nixos-unstable -
- nixpkgs-unstable 0.1.1
pkgs.home-assistant-component-tests.spaceapi
Open source home automation that puts local control and privacy first
-
nixos-unstable -
- nixpkgs-unstable 2025.9.3
pkgs.kubernetes-helmPlugins.helm-mapkubeapis
Helm plugin which maps deprecated or removed Kubernetes APIs in a release to supported APIs
-
nixos-unstable -
- nixpkgs-unstable 0.6.1
pkgs.chickenPackages_5.chickenEggs.binary-heap
Binary heap.
-
nixos-unstable -
- nixpkgs-unstable 2.2
-
nixos-unstable -
- nixpkgs-unstable 0.4
pkgs.python312Packages.googleapis-common-protos
Common protobufs used in Google APIs
-
nixos-unstable -
- nixpkgs-unstable 3.31.3
pkgs.python313Packages.googleapis-common-protos
Common protobufs used in Google APIs
-
nixos-unstable -
- nixpkgs-unstable 3.31.3
pkgs.home-assistant-component-tests.namecheapdns
Open source home automation that puts local control and privacy first
-
nixos-unstable -
- nixpkgs-unstable 2025.9.3
pkgs.typstPackages.cyberschool-errorteaplate_0_1_3
This is a template originaly made for the Cyberschool of Rennes, a Cybersecurity school
-
nixos-unstable -
- nixpkgs-unstable 0.1.3
pkgs.typstPackages.cyberschool-errorteaplate_0_1_4
This is a template originaly made for the Cyberschool of Rennes, a Cybersecurity school
-
nixos-unstable -
- nixpkgs-unstable 0.1.4
pkgs.typstPackages.cyberschool-errorteaplate_0_1_5
This is a template originaly made for the Cyberschool of Rennes, a Cybersecurity school
-
nixos-unstable -
- nixpkgs-unstable 0.1.5
Package maintainers
-
@fabaff Fabian Affolter <mail@fabian-affolter.ch>
-
@pyrox0 Pyrox <pyrox@pyrox.dev>
-
@ulrikstrid Ulrik Strid <ulrik.strid@outlook.com>
-
@katexochen Paul Meyer <katexochen0@gmail.com>
-
@honnip Jung seungwoo <me@honnip.page>
-
@t4ccer Tomasz Maciosowski <t4ccer@gmail.com>
-
@mweinelt Martin Weinelt <hexa@darmstadt.ccc.de>
-
@dotlambda Robert Schütz <rschuetz17@gmail.com>
-
@phryneas Lenz Weber <mail@lenzw.de>
-
@KoviRobi Kovacsics Robert <kovirobi@gmail.com>
-
@shymega Dom Rodriguez
-
@Twey James ‘Twey’ Kay <twey@twey.co.uk>
-
@qknight Joachim Schiele <js@lastlog.de>
-
@Kranzes Ilan Joselevich <personal@ilanjoselevich.com>
-
@vcunat Vladimír Čunát <v@cunat.cz>
-
@wineee Lu Hongxu <lhongxu@outlook.com>
-
@GetPsyched Priyanshu Tripathi <nixos@getpsyched.dev>
-
@PsyanticY Psyanticy <iuns@outlook.fr>
-
@sarahec Sarah Clark <seclark@nextquestion.net>
-
@teh Tom Hunger <tehunger@gmail.com>
-
@astro Astro <astro@spaceboyz.net>
-
@JamieMagee Jamie Magee <jamie.magee@gmail.com>
-
@leahneukirchen Leah Neukirchen <leah@vuxu.org>
-
@atinba Atin Bainada
-
@ilian ilian <nixos@ilian.dev>
-
@viraptor Stanisław Pitucha <nix@viraptor.info>
-
@orivej Orivej Desh <orivej@gmx.fr>
-
@uniquepointer uniquepointer <uniquepointer@mailbox.org>
-
@pancaek paneku
-
@hraban Hraban Luyat <hraban@0brg.net>
-
@lukego Luke Gorrie <luke@snabb.co>
-
@Uthar Kasper Gałkowski <galkowskikasper@gmail.com>
-
@7c6f434c Michael Raskin <7c6f434c@mail.ru>
-
@nagy Daniel Nagy <danielnagy@posteo.de>
-
@LeSuisse Thomas Gerbet <thomas@gerbet.me>
-
@cherrypiejam Gongqi Huang