NixOS / Nix
9 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-64846 | Nix: Arbitrary file truncation outside the sandbox with recursive-nix experimental feature | LOW | 2.8 | Aug 20, 2026 |
| CVE-2026-44029 | nix: absolute path traversal when unpacking archives to disk | HIGH | 7.1 | May 5, 2026 |
| CVE-2026-44028 | nix: coroutine stack-to-heap overflow via unbounded recursion in NAR directory parser | HIGH | 7.8 | May 5, 2026 |
| CVE-2026-39860 | Nix sandbox escape: file write via symlink at FOD `.tmp` copy destination | CRITICAL | 9.0 | Apr 8, 2026 |
| CVE-2025-53819 | Nix's privilege dropping to build user broke for macOS | HIGH | 7.9 | Jul 14, 2025 |
| CVE-2025-52993 | A race condition in the Nix, Lix, and Guix package managers enables changing the ownership of arbitrary files to the UID and GID of the build user (e.g., nixbl… | MEDIUM | 5.6 | Jun 27, 2025 |
| CVE-2025-52992 | The Nix, Lix, and Guix package managers fail to properly set permissions when a derivation build fails. This may allow arbitrary processes to modify the conten… | LOW | 3.2 | Jun 27, 2025 |
| CVE-2025-52991 | The Nix, Lix, and Guix package managers default to using temporary build directories in a world-readable and world-writable location. This allows standard user… | LOW | 3.2 | Jun 27, 2025 |
| CVE-2025-46416 | The Nix, Lix, and Guix package managers allow a bypass of build isolation in which a user can elevate their privileges to the build user account (e.g., nixbld… | LOW | 2.9 | Jun 27, 2025 |
| CVE-2025-46415 | A race condition in the Nix, Lix, and Guix package managers allows the removal of content from arbitrary folders. This affects Nix before 2.24.15, 2.26.4, 2.28… | LOW | 3.2 | Jun 27, 2025 |
| CVE-2024-51481 | Nix allows macOS sandbox escape via built-in builders | LOW | 1.0 | Oct 31, 2024 |
| CVE-2024-47174 | Credential leak when credentials are used with `<nix/fetchurl.nix>` | MEDIUM | 5.9 | Sep 26, 2024 |
| CVE-2024-45593 | Nix affected by unsafe NAR unpacking | CRITICAL | 9.1 | Sep 10, 2024 |
| CVE-2024-38531 | Nix sandbox escape | LOW | 3.6 | Jun 28, 2024 |
| CVE-2024-27297 | Nix Corruption of fixed-output derivations | MEDIUM | 6.3 | Mar 11, 2024 |
| CVE-2019-17365 | Nix through 2.3 allows local users to gain access to an arbitrary user's account because the parent directory of the user-profile directories is world writable. | HIGH | 7.8 | Oct 9, 2019 |
Showing 1 to 9 of 9 CVEs