Skip to content
VulniPulse
Advisory severityCritical9.6Red Hat Linux

Critical [CVE-2026-71476] @nx/s3-cache: @nx/gcs-cache: @nx/azure-cache: @nx/shared-fs-cache: @nx/powerpack-s3-cache: @nx/powerpack-gcs-cache: @nx/powerpack-azure-cache: @nx/powerpack-shared-fs-cache: Nx: Remote Code Executi…

This critical-severity Red Hat Linux advisory covers CVE-2026-71476.

Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.

CVE-2026-71476 Source published Source updated

VulniPulse record published Record updated

Affected products & platforms
Red Hat LinuxUnclassified
Open source advisory

Android app · Google Play

Monitor future Red Hat Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

Nx is a monorepo solution for TypeScript and polyglot codebases. From version 20.8.0 until 22.7.7 and 23.0.2, the Nx self-hosted HTTP remote cache extracts downloaded cache artifacts without constraining where files are written.

A malicious or on-path (MITM) remote cache server can return a crafted tar archive whose entries escape the cache directory and write to arbitrary locations on the machine running Nx, which can be escalated to remote code execution.

Nx's default local cache and Nx Cloud are not affected; only workspaces configured to use a self-hosted remote cache are affected. This issue is fixed in versions 22.7.7 and 23.0.2.

A flaw was found in Nx. A malicious or on-path (Man-in-the-Middle) remote cache server can exploit this Zip-Slip vulnerability by providing a specially crafted archive.

Red Hat products that bundle Nx use it as a build tool and do not use the self-hosted remote cache feature, limiting the exploitability of this vulnerability in Red Hat environments. The AAP 2.6 and 2.7 gateway container images bundle a vulnerable version of Nx and are being evaluated for impact.

Red Hat severity: Critical — CVSS 9.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H). Weakness: CWE-22.

Red Hat lists Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Hardened Images as not affected.

Affected versions

No affected-version range was extracted from the source record. The vendor advisory is authoritative — check it before change work.

Official advisory · high-confidence parse· fetched 24 days ago·verify at source

Fixed versions
  • 22.7.7
  • 23.0.2

Official advisory · high-confidence parse· fetched 24 days ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • Do not configure Nx to use a self-hosted HTTP remote cache. Use Nx's default local cache or Nx Cloud instead, neither of which are affected by this vulnerability. If a self-hosted remote cache is required, ensure the cache server is trusted and accessed over a secure, authenticated connection to prevent man-in-the-middle attacks. Upgrading to Nx 22.7.7 or 23.0.2 resolves the underlying path traversal issue.

Official advisory · high-confidence parse· fetched 24 days ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.