CVE-2026-44029: Medium severity Nix Nix vulnerability
An issue was discovered in Nix before 2.34.7. Writing to arbitrary files can occur via "nix-prefetch-url --unpack" or "nix store prefetch-file --unpack" directory traversal. The fixed versions are 2.34.7, 2.33.6, 2.32.8, 2.31.5, 2.30.5, 2.29.4, and 2.28.7 (introduced in 2.24.7);
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44029?
CVE-2026-44029 is considered a high-severity vulnerability due to its potential for arbitrary file writes through directory traversal.
How do I fix CVE-2026-44029?
To fix CVE-2026-44029, upgrade to Nix versions 2.34.7, 2.33.6, 2.32.8, 2.31.5, 2.30.5, 2.29.4, or 2.28.7.
What versions are affected by CVE-2026-44029?
CVE-2026-44029 affects Nix versions from 2.24.7 to below 2.34.7.
What is the impact of CVE-2026-44029?
CVE-2026-44029 could lead to local privilege escalation by allowing attackers to write to arbitrary files.
Who is affected by CVE-2026-44029?
Users of Nix versions between 2.24.7 and 2.34.7 are affected by CVE-2026-44029.