CVE-2024-47174Improper Authentication in NIX

Severity
5.9MEDIUMNVD
EPSS
0.1%
top 73.39%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 26
Latest updateJul 14

Description

Nix is a package manager for Linux and other Unix systems. Starting in version 1.11 and prior to versions 2.18.8 and 2.24.8, `` did not verify TLS certificates on HTTPS connections. This could lead to connection details such as full URLs or credentials leaking in case of a man-in-the-middle (MITM) attack. `` is also known as the builtin derivation builder `builtin:fetchurl`. It's not to be confused with the evaluation-time function `builtins.fetchurl`, which was not affected by this issue. A use

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages4 packages

debiandebian/nix< nix 2.24.8+dfsg-1 (forky)
Debiannixos/nix< 2.24.8+dfsg-1+1
Ubuntunixos/nix< 2.6.0+dfsg-3ubuntu0.1~esm1+1
CVEListV5nixos/nix>= 1.11, < 2.18.8, >= 2.24.0, < 2.24.8+1

🔴Vulnerability Details

2
OSV
nix vulnerabilities2025-07-14
OSV
CVE-2024-47174: Nix is a package manager for Linux and other Unix systems2024-09-26

📋Vendor Advisories

2
Ubuntu
Nix vulnerabilities2025-07-14
Debian
CVE-2024-47174: nix - Nix is a package manager for Linux and other Unix systems. Starting in version 1...2024
CVE-2024-47174 — Improper Authentication in Debian NIX | cvebase