CVE-2026-44029: Nixos Nix
Medium severity, CVSS 5.3. EPSS: 0.8% chance of exploitation in the next 30 days.
An issue was discovered in Nix before 2.34.7. Writing to arbitrary files can occur via "nix-prefetch-url --unpack" or "nix store prefetch-file --unpack" directory traversal. The fixed versions are 2.34.7, 2.33.6, 2.32.8, 2.31.5, 2.30.5, 2.29.4, and 2.28.7 (introduced in 2.24.7);
Affected products
- Nixos Nix: from 2.24.7, before 2.28.7 (fixed in 2.28.7); from 2.29.0, before 2.29.4 (fixed in 2.29.4); from 2.30.0, before 2.30.5 (fixed in 2.30.5); from 2.31.0, before 2.31.5 (fixed in 2.31.5); from 2.32.0, before 2.32.8 (fixed in 2.32.8); from 2.33.0, before 2.33.6 (fixed in 2.33.6); …
Published 2026-05-05. Last modified 2026-06-17.