CVE-2026-44029
EUVD-2026-2716605.05.2026, 01:16
An issue was discovered in Nix before 2.34.7. Writing to arbitrary files can occur via "nix-prefetch-url --unpack" or "nix store prefetch-file --unpack" directory traversal. The fixed versions are 2.34.7, 2.33.6, 2.32.8, 2.31.5, 2.30.5, 2.29.4, and 2.28.7 (introduced in 2.24.7);Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| nixos | nix | 2.24.7 ≤ 𝑥 < 2.28.7 | CNA |
| nixos | nix | 2.29.0 ≤ 𝑥 < 2.29.4 | CNA |
| nixos | nix | 2.30.0 ≤ 𝑥 < 2.30.5 | CNA |
| nixos | nix | 2.31.0 ≤ 𝑥 < 2.31.5 | CNA |
| nixos | nix | 2.32.0 ≤ 𝑥 < 2.32.8 | CNA |
| nixos | nix | 2.33.0 ≤ 𝑥 < 2.33.6 | CNA |
| nixos | nix | 2.34.0 ≤ 𝑥 < 2.34.7 | CNA |
Debian Releases