Get Nix CVEs
Retrieve the open nixpkgs security issues as CVE records, each with the nixpkgs attribute it names, the maintainers, the linked pull requests and whether one of them has merged.
Data Source
This endpoint returns CVEs only from nixpkgs security issues on GitHub. For combined stats across all ecosystems, use the /api/v1/stats endpoint.
Endpoint
GET /api/v1/nix/cvesThe path is under /nix/. An earlier edition of this page named /api/v1/nix-cves, which has never answered.
Response
data is the array itself; the counts sit beside it under stats.
json
{
"success": true,
"count": 100,
"data": [
{
"nixpkgsId": "NIXPKGS-2026-2780",
"cveId": "CVE-2026-100505",
"cveIds": ["CVE-2026-100505"],
"status": "open",
"summary": "Ghidra 11.2 through 12.1.4 Heap Out-of-Bounds Read via StringManager",
"affectedPackages": ["Ghidra"],
"nixpkgsAttribute": "pkgs.Ghidra",
"currentVersion": "11.2",
"fixedVersion": "",
"severity": "medium",
"cvssScore": 4.4,
"publishedAt": "2026-09-27T21:21:37Z",
"updatedAt": "2026-09-27T21:21:37Z",
"maintainers": ["vringar", "tbaldwin-dev", "roblabla", "ck3d", "Mic92"],
"assignees": [],
"githubIssue": "https://github.com/NixOS/nixpkgs/issues/567656",
"githubIssueNumber": 567656,
"linkedPRs": [],
"hasPR": false,
"hasOpenPR": false,
"hasMergedPR": false,
"trackerUrl": "https://tracker.security.nixos.org/issues/NIXPKGS-2026-2780",
"nvdUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-100505"
}
],
"stats": {
"total": 100,
"byPackage": { "Ghidra": 1, "suricata": 2 },
"bySeverity": { "critical": 10, "high": 50, "medium": 32, "low": 7, "unknown": 1 },
"withPR": 12,
"withFix": 32,
"assigned": 2
},
"source": "github",
"timestamp": "2026-09-28T01:02:44.801Z"
}Response Fields
| Field | Type | Description |
|---|---|---|
count | number | Records in data |
data[].nixpkgsId | string|null | The NixOS security review's own id for the issue, when it filed one |
data[].cveId | string | The primary CVE identifier |
data[].cveIds | string[] | Every CVE the issue names |
data[].status | string | open or closed |
data[].summary | string | The issue title, or the CVE summary |
data[].affectedPackages | string[] | Package names as the issue states them |
data[].nixpkgsAttribute | string|null | The nixpkgs attribute, when the issue names one |
data[].currentVersion | string | The version the issue reports as affected |
data[].fixedVersion | string | The version that fixes it; empty when unknown |
data[].severity | string | critical, high, medium, low or unknown |
data[].cvssScore | number | Present when the severity was enriched from NVD |
data[].publishedAt, updatedAt | string | ISO 8601 timestamps of the issue |
data[].maintainers | string[] | The nixpkgs maintainers of the attribute |
data[].assignees | string[] | GitHub usernames assigned to the issue |
data[].githubIssue, githubIssueNumber | string, number | The issue |
data[].linkedPRs | array | Pull requests linked to the issue: number, title, state, url |
data[].hasPR, hasOpenPR, hasMergedPR | boolean | Whether any linked pull request exists, is open or has merged |
data[].trackerUrl | string|null | The issue on the NixOS security review site |
data[].nvdUrl | string | The CVE on NVD |
stats.total | number | Open issues counted |
stats.byPackage | object | Count per package name |
stats.bySeverity | object | Count per severity |
stats.withPR, withFix, assigned | number | Issues with a linked PR, a known fixed version, an assignee |
source | string | Where the list came from on this request |
Example
bash
curl https://api.vulnpatch.dev/api/v1/nix/cvesCode Examples
javascript
async function getNixCVEs() {
const response = await fetch('https://api.vulnpatch.dev/api/v1/nix/cves');
const { data, stats } = await response.json();
const withOpenPRs = data.filter(cve => cve.hasOpenPR);
console.log(`${stats.total} open, ${withOpenPRs.length} with an open PR`);
for (const cve of withOpenPRs) {
console.log(`${cve.cveId}: ${cve.linkedPRs.length} PRs`);
}
}python
import requests
body = requests.get('https://api.vulnpatch.dev/api/v1/nix/cves').json()
# Unassigned issues with a known fixed version
unassigned_fixable = [
cve for cve in body['data']
if cve['fixedVersion'] and not cve['assignees']
]
print(f"Unassigned with a known fix: {len(unassigned_fixable)}")
for cve in unassigned_fixable[:5]:
print(f" {cve['cveId']} -> {cve['fixedVersion']}")Caching
Answers are cached for an hour; the X-Cache header says whether you received a cached one. A GitHub failure answers 500 with success: false rather than an empty list.
Related Endpoints
- Nix Stats - the counts alone
- Get Issues - the issues as GitHub reports them, open and closed
- NixOS channels and builds - where a fix stands per channel