Nixpkgs security tracker

Login with GitHub

Dismissed suggestions

These automatic suggestions were dismissed after initial triaging.

to select a suggestion for revision.

View:
Compact
Detailed
Permalink CVE-2025-54670
7.1 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): REQUIRED
  • Scope (S): CHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): LOW
  • Availability impact (A): LOW
updated 6 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored package libvoikko
  • @LeSuisse dismissed
WordPress oik Plugin <= 4.15.2 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bobbingwide oik allows Reflected XSS. This issue affects oik: from n/a through 4.15.2.

Affected products

oik
  • =<4.15.2
Ignored packages (1)

pkgs.libvoikko

Finnish language processing library

  • nixos-unstable -
Permalink CVE-2025-57890
5.9 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): HIGH
  • User interaction (UI): REQUIRED
  • Scope (S): CHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): LOW
  • Availability impact (A): LOW
updated 6 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    3 packages
    • haskellPackages.simple-sessions
    • python312Packages.langchain-azure-dynamic-sessions
    • python313Packages.langchain-azure-dynamic-sessions
  • @LeSuisse dismissed
WordPress Sessions Plugin <= 3.2.0 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pierre Lannoy Sessions allows Stored XSS. This issue affects Sessions: from n/a through 3.2.0.

Affected products

sessions
  • =<3.2.0
Ignored packages (3)
Permalink CVE-2025-58209
6.5 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): REQUIRED
  • Scope (S): CHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): LOW
  • Availability impact (A): LOW
updated 6 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    5 packages
    • haskellPackages.amazonka-elastictranscoder
    • python312Packages.mypy-boto3-elastictranscoder
    • python313Packages.mypy-boto3-elastictranscoder
    • python312Packages.types-aiobotocore-elastictranscoder
    • python313Packages.types-aiobotocore-elastictranscoder
  • @LeSuisse dismissed
WordPress Transcoder Plugin <= 1.4.0 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rtCamp Transcoder allows Stored XSS. This issue affects Transcoder: from n/a through 1.4.0.

Affected products

transcoder
  • =<1.4.0
Ignored packages (5)
Permalink CVE-2025-54724
7.1 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): REQUIRED
  • Scope (S): CHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): LOW
  • Availability impact (A): LOW
updated 6 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    2 packages
    • ligolo-ng
    • xfce.gigolo
  • @LeSuisse dismissed
WordPress Golo Theme <= 1.7.1 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uxper Golo allows Reflected XSS. This issue affects Golo: from n/a through 1.7.1.

Affected products

golo
  • =<1.7.1
Ignored packages (2)

pkgs.ligolo-ng

Tunneling/pivoting tool that uses a TUN interface

  • nixos-unstable -

pkgs.xfce.gigolo

Frontend to easily manage connections to remote filesystems

  • nixos-unstable -
Permalink CVE-2025-54725
9.8 CRITICAL
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): HIGH
updated 6 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    2 packages
    • xfce.gigolo
    • ligolo-ng
  • @LeSuisse dismissed
WordPress Golo Theme <= 1.7.0 - Broken Authentication Vulnerability

Authentication Bypass Using an Alternate Path or Channel vulnerability in uxper Golo allows Authentication Abuse. This issue affects Golo: from n/a through 1.7.0.

Affected products

golo
  • =<1.7.0
Ignored packages (2)

pkgs.ligolo-ng

Tunneling/pivoting tool that uses a TUN interface

  • nixos-unstable -

pkgs.xfce.gigolo

Frontend to easily manage connections to remote filesystems

  • nixos-unstable -
Permalink CVE-2024-3508
4.3 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): NONE
  • Integrity impact (I): NONE
  • Availability impact (A): LOW
updated 6 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    9 packages
    • bzip2
    • lbzip2
    • pbzip2
    • bzip2_1_1
    • indexed-bzip2
    • haskellPackages.bzip2-clib
    • python312Packages.indexed-bzip2
    • python313Packages.indexed-bzip2
    • tests.pkg-config.defaultPkgConfigPackages.bzip2
  • @LeSuisse dismissed
Bzip2: compressed content bomb leads to denial of service of bombastic api

A flaw was found in Bombastic, which allows authenticated users to upload compressed (bzip2 or zstd) SBOMs. The API endpoint verifies the presence of some fields and values in the JSON. To perform this verification, the uploaded file must first be decompressed.

References

Affected products

bzip2
  • ==faa7a496c5d98e0f0859dd2c623eddf82289eaa8
SBOM-Management-(Bombastic)
Ignored packages (9)

pkgs.bzip2

High-quality data compression program

  • nixos-unstable -

pkgs.lbzip2

Parallel bzip2 compression utility

  • nixos-unstable -
    • nixpkgs-unstable 2.5

pkgs.pbzip2

Parallel implementation of bzip2 for multi-core machines

  • nixos-unstable -

pkgs.bzip2_1_1

High-quality data compression program

pkgs.indexed-bzip2

Python library for parallel decompression and seeking within compressed bzip2 files

  • nixos-unstable -
Permalink CVE-2025-58806
7.1 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): REQUIRED
  • Scope (S): CHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): LOW
  • Availability impact (A): LOW
updated 6 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    6 packages
    • haskellPackages.bugsnag
    • python312Packages.bugsnag
    • python313Packages.bugsnag
    • haskellPackages.bugsnag-hs
    • haskellPackages.bugsnag-wai
    • haskellPackages.bugsnag-yesod
  • @LeSuisse dismissed
WordPress WordPress Error Monitoring by Bugsnag Plugin <= 1.6.3 - Cross Site Request Forgery (CSRF) Vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in imjoehaines WordPress Error Monitoring by Bugsnag allows Stored XSS. This issue affects WordPress Error Monitoring by Bugsnag: from n/a through 1.6.3.

Affected products

bugsnag
  • =<1.6.3
Ignored packages (6)
Permalink CVE-2025-58801
5.4 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): REQUIRED
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): NONE
  • Integrity impact (I): LOW
  • Availability impact (A): LOW
updated 6 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored package responder
  • @LeSuisse dismissed
WordPress Responder Plugin <= 4.3.8 - Cross Site Request Forgery (CSRF) Vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in KCS Responder allows Cross Site Request Forgery. This issue affects Responder: from n/a through 4.3.8.

Affected products

responder
  • =<4.3.8
Ignored packages (1)

pkgs.responder

LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server

  • nixos-unstable -
Permalink CVE-2025-58820
5.9 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): HIGH
  • User interaction (UI): REQUIRED
  • Scope (S): CHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): LOW
  • Availability impact (A): LOW
updated 6 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored package haskellPackages.data-carousel
  • @LeSuisse dismissed
WordPress Carousel Ultimate Plugin <= 1.8 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themepoints Carousel Ultimate allows Stored XSS. This issue affects Carousel Ultimate: from n/a through 1.8.

Affected products

carousel
  • =<1.8
Ignored packages (1)
Permalink CVE-2025-58822
6.5 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): REQUIRED
  • Scope (S): CHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): LOW
  • Availability impact (A): LOW
updated 6 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored package wordpressPackages.plugins.wp-mail-smtp
  • @LeSuisse dismissed
WordPress WP Mail Plugin <= 1.3 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mndpsingh287 WP Mail allows DOM-Based XSS. This issue affects WP Mail: from n/a through 1.3.

Affected products

wp-mail
  • =<1.3
Ignored packages (1)