CVE-2021-4076
NixOS vulnerability analysis and mitigation

Overview

A vulnerability (CVE-2021-4076) was discovered in Tang, a network-based cryptographic binding server, affecting versions 8 through 11. The flaw could result in the leak of private keys. The vulnerability was initially discovered by Twitter's Kernel and OS team during a source code audit while evaluating Tang/Clevis for their needs (GitHub PR).

Technical details

The vulnerability has a CVSS v3.1 Base Score of 7.5 (High) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N. The issue was introduced in Tang version 8 through commit 609050586e4863329d2db9b7cb73da5c09eeea2b and was fixed in version 11 via commit e82459fda10f0630c3414ed2afbc6320bb9ea7c9. The vulnerability is classified under CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) (NVD).

Impact

The vulnerability could lead to the exposure of private keys to unauthorized actors. Given the CVSS scoring, the flaw has a high impact on confidentiality while maintaining no impact on integrity and availability. As Tang is used for network-based cryptographic binding, a compromise of private keys could potentially affect the security of dependent systems (Red Hat Bugzilla).

Mitigation and workarounds

The vulnerability was fixed in Tang version 11 by moving the signing functionality from find_by_thp() to find_jws() to ensure proper handling of signing keys and responses to queries. Users are advised to upgrade to version 11 or later to address this security issue (GitHub PR).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-22783HIGH8.1
  • NixOSNixOS
  • iris
NoYesJan 12, 2026
CVE-2026-0821MEDIUM6.9
  • NixOSNixOS
  • quickjs
NoNoJan 10, 2026
CVE-2025-68949MEDIUM5.3
  • NixOSNixOS
  • n8n
NoYesJan 13, 2026
CVE-2026-22784LOW2.3
  • NixOSNixOS
  • lychee
NoYesJan 12, 2026
CVE-2026-23497LOW1.3
  • NixOSNixOS
  • learning
NoYesJan 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management