New CVEs likely affecting nixpkgs
CVE records queued for mapping to nixpkgs attributes. The list is a bounded, non-exhaustive set of corroborated project matches; it does not establish that a package is vulnerable. When a nixpkgs security issue is filed later, the entry records how many hours elapsed after our mapping.
GET /api/v1/nix/ahead
GET /api/v1/nix/ahead?tracked=no
GET /api/v1/nix/ahead?inRange=1The same list is on cve.vulnpatch.dev/signal.
How it is built
Every five minutes the delta poll reads CVE records from the CVE Program and queues those with affected products. The same poll maps queued records. It reads every KV queue page (up to 20 pages), processes oldest records first, and raises its per-run mapping limit from 6 toward 18 when there is a backlog. Each run also has a 35-second mapping budget. Queue records have a three-day TTL; a surge can still cause incomplete coverage. coverage.queue exposes the observed backlog, age, and whether the scan was complete. Failure after three attempts is counted in coverage.processing.failed and retained for 30 days for audit, not silently classified as a non-match. The list itself keeps at most 400 entries for 30 days. KV expiration does not emit a reliable count of expired keys, so no expired-count claim is made; expiresWithin24h warns when observed keys approach expiration.
For each queued record:
- The record's affected products go through the package mapper, which asks the search.nixos.org package index and a complete copy of Repology. A product the CNA wrote as "Name (identifier)" is also looked up by the identifier.
- Each package found is checked against the record: it is listed only when a reference in the record names the package homepage's repository or site, or the homepage names the record's vendor and product. Names are shared: nixpkgs
rancheris the Rancher command-line tool, not the Rancher server a CVE was about. A match by name alone is counted innameOnlySkippedand not listed; the CVE dossier keeps it as an unverified discovery lead, with no version comparison. Generic words such asgatewayare recorded as ignored identity evidence, not treated as a project match. - Only after project identity is corroborated is each channel's version compared with the record's affected ranges (text constraints, version and lessThan ranges, status changes within a range, and the kernel's per-series form). See
versionVerdictin Agent Support. - A record whose products map to no attribute is not listed. One whose lookup failed upstream is retried on later runs.
Every half hour, and at once when a CVE is newly added, the stored list of nixpkgs security issues is read, and any listed CVE that now has an issue gets tracker and leadHours. trackerCheckedAt on an entry says when it was last checked; an entry without it has not been checked yet. trackerReadAt is when that last happened and trackerListedAt when the stored list was itself fetched from GitHub, so a match is only as recent as the latter. The list is never crawled from here.
publishedAt is the CVE List v5 publication time, not necessarily first public disclosure. publicAdvisory is populated only when the CVE record references a GitHub security advisory and its API confirms this CVE ID, or when the CNA supplies a datePublic. Repository advisory dates are read from the repository advisory API, not the later GitHub global advisory database. mappedAt is when Vulnpatch mapped the record. leadHours compares mapping with tracker issue filing, not first public disclosure. A null publicAdvisory means no independently dated advisory was obtained, not that the CVE was first disclosed on publishedAt.
What it is not
Candidates, not confirmations. A version inside an affected range can still carry the fix as a nixpkgs patch without a new version, and a mapping by package name can be wrong for a package that shares its name with another project. The CVE page for each entry shows the full record with every source.
Parameters
| Parameter | Values | Meaning |
|---|---|---|
tracked | all (default), no, yes | Only the CVEs without a nixpkgs security issue, or only those with one |
inRange | 1 | Only the CVEs with at least one channel version inside the affected ranges |
Response
{
"success": true,
"data": {
"entries": [
{
"cveId": "CVE-2026-53493",
"publishedAt": "2026-09-25T00:06:43.298Z",
"publishedAtSource": "cve_list_v5",
"publicAdvisory": null,
"mappedAt": "2026-09-28T12:05:00.000Z",
"severity": "medium",
"summary": "containerd is an open-source container runtime...",
"candidates": [
{ "identity": "vendor_and_product", "attr": "containerd", "channel": "nixos-25.11", "version": "2.2.1", "derivedFrom": "containerd",
"verdict": { "status": "in_affected_range", "fixedIn": "2.2.9", "range": ">= 2.1.0, < 2.2.9" } }
],
"candidateCount": 1,
"candidatesTruncated": false,
"inAffectedRange": 1,
"tracker": null
}
],
"counts": { "listed": 1, "untracked": 1, "inAffectedRange": 1, "trackedLater": 0, "trackedFirst": 0 },
"updatedAt": "2026-09-28T12:05:00.000Z",
"trackerReadAt": "2026-09-28T12:05:00.000Z",
"coverage": {
"queue": { "pending": 0, "complete": true, "oldestQueuedAt": null, "observedAt": "2026-09-28T12:05:00.000Z", "atRisk": false },
"processing": { "mapped": 1, "kept": 1, "notMapped": 0, "failed": 0 },
"retentionDays": 30,
"maxListedEntries": 400,
"exhaustive": false,
"warning": null
},
"method": "..."
}
}leadHours appears once the tracker has filed: hours from our mapping to the issue, negative when the issue came first. Each candidate's identity says how it was shown to be the CVE's project. candidateCount counts all corroborated package/channel rows for an entry; candidates returns at most 12, with affected-range rows first. candidatesTruncated says whether the sample is incomplete. The full CVE dossier remains the place to inspect all package evidence. The top-level counts describe only the returned, filtered entries, not all published CVEs. coverage.processing counters start when this version of the poll first runs; they are not all-time ingestion totals. coverage.queue.pending is a snapshot from the last poll, not a live count.
| Status | Code | Meaning |
|---|---|---|
| 200 | The list | |
| 400 | BAD_FILTER | tracked is not all, no or yes |
| 503 | NOT_BUILT | No list yet; the poll builds it as new CVEs arrive. Never to be read as nothing new |
| 503 | STORE_UNAVAILABLE | The list could not be read |