CVE Tools

Nixos

10 CVEs tracked since 2025. Since Jan 2025, none of them reached CISA KEV.

Nixos CVEs per month

Jan 2025 to Jun 2025. Point at a month, or focus the strip and use the arrow keys.
Nixos CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2025-0150
2025-02null or fewer
2025-03null or fewer
2025-04null or fewer
2025-05null or fewer
2025-0650

Products

The products that kept showing up in Nixos's monthly top three, with their CVEs summed over those months.

  1. Nix51 month
  2. Nixos51 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Nixos.

  1. CVE-2026-64846Nix: Arbitrary file truncation outside the sandbox with recursive-nix experimental feature2.8
  2. CVE-2026-61828nixos/mysql : `services.mysql` is configured with insecure authentication by default when used with `mysql` or `percona-server`—
  3. CVE-2026-44029An issue was discovered in Nix before 2.34.7. Writing to arbitrary files can occur via "nix-prefetch-url --unpack" or "nix store prefetch-file --unpack" directory traversal. The fixed versions are ...5.3
  4. CVE-2026-44028An issue was discovered in Nix before 2.34.7 and Lix before 2.95.2. Unbounded recursion in the NAR (Nix Archive) parser could lead to a stack-to-heap overflow when the parser is run on a coroutine ...7.5
  5. CVE-2026-31431crypto: algif_aead - Revert to operating out-of-place7.8
  6. CVE-2026-39860Nix sandbox escape: file write via symlink at FOD `.tmp` copy destination9.0
  7. CVE-2026-25740Privilege escalation to the `CAP_NET_RAW` capability via the `programs.captive-browser` NixOS module—
  8. CVE-2026-25137NixOs Odoo database and filestore publicly accessible with default odoo configuration9.1
  9. CVE-2026-23838Tandoor Recipes module allows SQLite database to be externally accessible with the default settings—
  10. CVE-2025-64766NixOS has hardcoded credentials in Onlyoffice module5.3
  11. CVE-2025-54864Hydra missing authentication when triggering evaluations through GitHub and Gitea plugins7.5
  12. CVE-2025-54800Hydra persistent XSS in build metrics6.1
  13. CVE-2025-53819Nix's privilege dropping to build user broke for macOS7.9
  14. CVE-2025-52991The Nix, Lix, and Guix package managers default to using temporary build directories in a world-readable and world-writable location. This allows standard users to deceive the package manager into ...3.2
  15. CVE-2025-52993A race condition in the Nix, Lix, and Guix package managers enables changing the ownership of arbitrary files to the UID and GID of the build user (e.g., nixbld* or guixbuild*). This affects Nix be...5.6

The record

Peak rank
#175 in Jun 2025
Busiest month shown
Jan 2025, 5 CVEs
Months with a KEV entry
0 since Jan 2025
Monthly snapshots
2 since 2025
Nixos's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store