Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

NixOS — Vulnerabilities & Security Advisories 26

Browse all 26 CVE security advisories affecting NixOS. AI-powered Chinese analysis, POCs, and references for each vulnerability.

NixOS is a Linux distribution distinguished by its declarative configuration model and reproducible builds, primarily serving developers and system administrators seeking infrastructure stability. Its unique package management system isolates software environments, which inherently reduces dependency conflicts but introduces complexity in security auditing. Historically, vulnerabilities within the Nix ecosystem have frequently involved privilege escalation and remote code execution, often stemming from improper handling of user-supplied data in configuration files or build scripts. With 26 recorded CVEs, these flaws typically affect the package manager itself or specific packages built within the Nix store rather than the core kernel. Notable incidents have highlighted risks related to insecure temporary file creation and race conditions during package installation. While the architecture promotes integrity through cryptographic hashing, the steep learning curve can lead to misconfigurations that expose systems to unauthorized access or data leakage if not strictly managed.

Showing up to 20 recent security advisories. View all →

This page lists every published CVE security advisory associated with NixOS. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.