Skip to content

Get Nix CVEs ​

Retrieve the open nixpkgs security issues as CVE records, each with the nixpkgs attribute it names, the maintainers, the linked pull requests and whether one of them has merged.

Data Source

This endpoint returns CVEs only from nixpkgs security issues on GitHub. For combined stats across all ecosystems, use the /api/v1/stats endpoint.

Endpoint ​

GET /api/v1/nix/cves

The path is under /nix/. An earlier edition of this page named /api/v1/nix-cves, which has never answered.

Response ​

data is the array itself; the counts sit beside it under stats.

json
{
  "success": true,
  "count": 100,
  "data": [
    {
      "nixpkgsId": "NIXPKGS-2026-2780",
      "cveId": "CVE-2026-100505",
      "cveIds": ["CVE-2026-100505"],
      "status": "open",
      "summary": "Ghidra 11.2 through 12.1.4 Heap Out-of-Bounds Read via StringManager",
      "affectedPackages": ["Ghidra"],
      "nixpkgsAttribute": "pkgs.Ghidra",
      "currentVersion": "11.2",
      "fixedVersion": "",
      "severity": "medium",
      "cvssScore": 4.4,
      "publishedAt": "2026-09-27T21:21:37Z",
      "updatedAt": "2026-09-27T21:21:37Z",
      "maintainers": ["vringar", "tbaldwin-dev", "roblabla", "ck3d", "Mic92"],
      "assignees": [],
      "githubIssue": "https://github.com/NixOS/nixpkgs/issues/567656",
      "githubIssueNumber": 567656,
      "linkedPRs": [],
      "hasPR": false,
      "hasOpenPR": false,
      "hasMergedPR": false,
      "trackerUrl": "https://tracker.security.nixos.org/issues/NIXPKGS-2026-2780",
      "nvdUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-100505"
    }
  ],
  "stats": {
    "total": 100,
    "byPackage": { "Ghidra": 1, "suricata": 2 },
    "bySeverity": { "critical": 10, "high": 50, "medium": 32, "low": 7, "unknown": 1 },
    "withPR": 12,
    "withFix": 32,
    "assigned": 2
  },
  "source": "github",
  "timestamp": "2026-09-28T01:02:44.801Z"
}

Response Fields ​

FieldTypeDescription
countnumberRecords in data
data[].nixpkgsIdstring|nullThe NixOS security review's own id for the issue, when it filed one
data[].cveIdstringThe primary CVE identifier
data[].cveIdsstring[]Every CVE the issue names
data[].statusstringopen or closed
data[].summarystringThe issue title, or the CVE summary
data[].affectedPackagesstring[]Package names as the issue states them
data[].nixpkgsAttributestring|nullThe nixpkgs attribute, when the issue names one
data[].currentVersionstringThe version the issue reports as affected
data[].fixedVersionstringThe version that fixes it; empty when unknown
data[].severitystringcritical, high, medium, low or unknown
data[].cvssScorenumberPresent when the severity was enriched from NVD
data[].publishedAt, updatedAtstringISO 8601 timestamps of the issue
data[].maintainersstring[]The nixpkgs maintainers of the attribute
data[].assigneesstring[]GitHub usernames assigned to the issue
data[].githubIssue, githubIssueNumberstring, numberThe issue
data[].linkedPRsarrayPull requests linked to the issue: number, title, state, url
data[].hasPR, hasOpenPR, hasMergedPRbooleanWhether any linked pull request exists, is open or has merged
data[].trackerUrlstring|nullThe issue on the NixOS security review site
data[].nvdUrlstringThe CVE on NVD
stats.totalnumberOpen issues counted
stats.byPackageobjectCount per package name
stats.bySeverityobjectCount per severity
stats.withPR, withFix, assignednumberIssues with a linked PR, a known fixed version, an assignee
sourcestringWhere the list came from on this request

Example ​

bash
curl https://api.vulnpatch.dev/api/v1/nix/cves

Code Examples ​

javascript
async function getNixCVEs() {
  const response = await fetch('https://api.vulnpatch.dev/api/v1/nix/cves');
  const { data, stats } = await response.json();

  const withOpenPRs = data.filter(cve => cve.hasOpenPR);
  console.log(`${stats.total} open, ${withOpenPRs.length} with an open PR`);

  for (const cve of withOpenPRs) {
    console.log(`${cve.cveId}: ${cve.linkedPRs.length} PRs`);
  }
}
python
import requests

body = requests.get('https://api.vulnpatch.dev/api/v1/nix/cves').json()

# Unassigned issues with a known fixed version
unassigned_fixable = [
    cve for cve in body['data']
    if cve['fixedVersion'] and not cve['assignees']
]

print(f"Unassigned with a known fix: {len(unassigned_fixable)}")
for cve in unassigned_fixable[:5]:
    print(f"  {cve['cveId']} -> {cve['fixedVersion']}")

Caching ​

Answers are cached for an hour; the X-Cache header says whether you received a cached one. A GitHub failure answers 500 with success: false rather than an empty list.