<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – nix (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/nix.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/nix-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – nix (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:45 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2026-44592 – Gradient is a nix-based continuous integration system. In 1.1.0, when GRADIENT_D...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44592</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44592</guid>
    <pubDate>Thu, 14 May 2026 19:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-44592</strong></p>
  <p>Gradient is a nix-based continuous integration system. In 1.1.0, when GRADIENT_DISCOVERABLE=true (the default, and the NixOS module default), anyone who can reach /proto can register as a worker without any credentials by sending a fresh, never-registered worker UUID. The resulting session has PeerAuth::Open, i.e. it sees jobs from every organisation, and can immediately NarPush/NarUploaded arbit…</p>
  <p><strong>CVSS:</strong> 9.4 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44592">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43296 – In the Linux kernel, the following vulnerability has been resolved:

octeontx2-a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43296</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43296</guid>
    <pubDate>Fri, 08 May 2026 14:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43296</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  octeontx2-af: Workaround SQM/PSE stalls by disabling sticky  NIX SQ manager sticky mode is known to cause stalls when multiple SQs share an SMQ and transmit concurrently. Additionally, PSE may deadlock on transitions between sticky and non-sticky transmissions. There is also a credit drop issue observed when certain condition cl…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-667</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43296">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44028 – An issue was discovered in Nix before 2.34.7 and Lix before 2.95.2. Unbounded re...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44028</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44028</guid>
    <pubDate>Tue, 05 May 2026 01:16:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44028</strong></p>
  <p>An issue was discovered in Nix before 2.34.7 and Lix before 2.95.2. Unbounded recursion in the NAR (Nix Archive) parser could lead to a stack-to-heap overflow when the parser is run on a coroutine stack. The stack is allocated without a guard page, which means that a stack overflow could overwrite memory on the heap and could allow arbitrary code execution as the Nix daemon (run as root in multi-…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-674</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44028">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-39860 – Nix is a package manager for Linux and other Unix systems. A bug in the fix for ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39860</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39860</guid>
    <pubDate>Wed, 08 Apr 2026 21:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-39860</strong></p>
  <p>Nix is a package manager for Linux and other Unix systems. A bug in the fix for CVE-2024-27297 allowed for arbitrary overwrites of files writable by the Nix process orchestrating the builds (typically the Nix daemon running as root in multi-user installations) by following symlinks during fixed-output derivation output registration. This affects sandboxed Linux builds - sandboxed macOS builds are…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-61</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39860">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-23838 – Tandoor Recipes is a recipe manager than can be installed with the Nix package m...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23838</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23838</guid>
    <pubDate>Mon, 19 Jan 2026 19:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-23838</strong></p>
  <p>Tandoor Recipes is a recipe manager than can be installed with the Nix package manager. Starting in version 23.05 and prior to version 26.05, when using the default configuration of Tandoor Recipes, specifically using SQLite and default `MEDIA_ROOT`, the full database file may be externally accessible, potentially on the Internet. The root cause is that the NixOS module configures the working dir…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-538</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23838">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-35055 – Newforma Info Exchange (NIX) '/UserWeb/Common/UploadBlueimp.ashx' allows an auth...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-35055</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-35055</guid>
    <pubDate>Thu, 09 Oct 2025 21:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-35055</strong></p>
  <p>Newforma Info Exchange (NIX) '/UserWeb/Common/UploadBlueimp.ashx' allows an authenticated attacker to upload an arbitrary file to any location writable by the NIX application. An attacker can upload and run a web shell or other content executable by the web server. An attacker can also delete directories.  In Newforma before 2023.1, anonymous access is enabled by default (CVE-2025-35062), allowin…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-35055">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-35050 – Newforma Info Exchange (NIX) accepts serialized .NET data via the '/remoteweb/re...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-35050</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-35050</guid>
    <pubDate>Thu, 09 Oct 2025 21:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-35050</strong></p>
  <p>Newforma Info Exchange (NIX) accepts serialized .NET data via the '/remoteweb/remote.rem' endpoint, allowing a remote, unauthenticated attacker to execute arbitrary code with 'NT AUTHORITY\NetworkService' privileges. The vulnerable endpoint is used by Newforma Project Center Server (NPCS), so a compromised NIX system can be used to attack an associated NPCS system. To mitigate this vulnerability,…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-35050">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-58270 – Cross-Site Request Forgery (CSRF) vulnerability in NIX Solutions Ltd NIX Anti-Sp...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-58270</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-58270</guid>
    <pubDate>Mon, 22 Sep 2025 19:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-58270</strong></p>
  <p>Cross-Site Request Forgery (CSRF) vulnerability in NIX Solutions Ltd NIX Anti-Spam Light nix-anti-spam-light allows Cross Site Request Forgery.This issue affects NIX Anti-Spam Light: from n/a through <= 0.0.4.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58270">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-54864 – Hydra is a continuous integration service for Nix based projects. Prior to commi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54864</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54864</guid>
    <pubDate>Tue, 12 Aug 2025 16:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-54864</strong></p>
  <p>Hydra is a continuous integration service for Nix based projects. Prior to commit f7bda02, /api/push-github and /api/push-gitea are called by the corresponding forge without HTTP Basic authentication. Both forges do however feature HMAC signing with a secret key. Triggering an evaluation can be very taxing on the infrastructure when large evaluations are done, introducing potential denial of serv…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54864">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-53819 – Nix is a package manager for Linux and other Unix systems. Builds with Nix 2.30...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53819</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53819</guid>
    <pubDate>Mon, 14 Jul 2025 21:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-53819</strong></p>
  <p>Nix is a package manager for Linux and other Unix systems. Builds with Nix 2.30.0 on macOS were executed with elevated privileges (root), instead of the build users. The fix was applied to Nix 2.30.1. No known workarounds are available.</p>
  <p><strong>CVSS:</strong> 7.9 · <strong>CWE:</strong> CWE-271</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53819">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-52432 – Deserialization of Untrusted Data vulnerability in NIX Solutions Ltd NIX Anti-Sp...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52432</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52432</guid>
    <pubDate>Mon, 18 Nov 2024 15:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-52432</strong></p>
  <p>Deserialization of Untrusted Data vulnerability in NIX Solutions Ltd NIX Anti-Spam Light nix-anti-spam-light allows Object Injection.This issue affects NIX Anti-Spam Light: from n/a through <= 0.0.4.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52432">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-45593 – Nix is a package manager for Linux and other Unix systems. A bug in Nix 2.24 pri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-45593</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-45593</guid>
    <pubDate>Tue, 10 Sep 2024 16:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-45593</strong></p>
  <p>Nix is a package manager for Linux and other Unix systems. A bug in Nix 2.24 prior to 2.24.6 allows a substituter or malicious user to craft a NAR that, when unpacked by Nix, causes Nix to write to arbitrary file system locations to which the Nix process has access. This will be with root permissions when using the Nix daemon. This issue is fixed in Nix 2.24.6.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45593">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-45049 – Hydra is a Continuous Integration service for Nix based projects. It is possible...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-45049</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-45049</guid>
    <pubDate>Tue, 27 Aug 2024 21:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-45049</strong></p>
  <p>Hydra is a Continuous Integration service for Nix based projects. It is possible to trigger evaluations in Hydra without any authentication. Depending on the size of evaluations, this can impact the availability of systems. The problem can be fixed by applying https://github.com/NixOS/hydra/commit/f73043378907c2c7e44f633ad764c8bdd1c947d5 to any Hydra package. Users are advised to upgrade. Users u…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45049">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-45707 – An issue was discovered in the nix crate 0.16.0 and later before 0.20.2, 0.21.x ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-45707</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-45707</guid>
    <pubDate>Mon, 27 Dec 2021 00:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-45707</strong></p>
  <p>An issue was discovered in the nix crate 0.16.0 and later before 0.20.2, 0.21.x before 0.21.2, and 0.22.x before 0.22.2 for Rust. unistd::getgrouplist has an out-of-bounds write if a user is in more than 16 /etc/groups groups.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-45707">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-17365 – Nix through 2.3 allows local users to gain access to an arbitrary user's account...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-17365</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-17365</guid>
    <pubDate>Wed, 09 Oct 2019 22:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-17365</strong></p>
  <p>Nix through 2.3 allows local users to gain access to an arbitrary user's account because the parent directory of the user-profile directories is world writable.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-17365">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-3222 – syscheck/seechanges.c in OSSEC 2.7 through 2.8.1 on NIX systems allows local use...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-3222</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-3222</guid>
    <pubDate>Thu, 07 Sep 2017 20:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-3222</strong></p>
  <p>syscheck/seechanges.c in OSSEC 2.7 through 2.8.1 on NIX systems allows local users to execute arbitrary code as root.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-3222">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2015-8557 – The FontManager._get_nix_font_path function in formatters/img.py in Pygments 1.2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-8557</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-8557</guid>
    <pubDate>Fri, 08 Jan 2016 20:59:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2015-8557</strong></p>
  <p>The FontManager._get_nix_font_path function in formatters/img.py in Pygments 1.2.2 through 2.0.2 allows remote attackers to execute arbitrary commands via shell metacharacters in a font name.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-8557">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
