hsec-2025-0005

osv_haskell
Description

# `cabal-install` dependency confusion For **cabal-install < 3.4.0.0** and where multiple repositories are configured, the resolver picks the highest available version across all repositories. Where a package is only defined in a private repository, this behaviour leads to a [*dependency confusion*][blog] supply chain vulnerability. If the private package name becomes known, a malicious actor can claim the name in the public repository and publish a malicious version at a higher version number. Default `cabal-install` configurations that only use the `hackage.haskell.org` repository are not affected. Configurations that use curated private repositories **exclusively** are also not affected. [blog]: https://frasertweedale.github.io/blog-fp/posts/2021-02-12-haskell-dependency-confusion.html ## Mitigations *cabal-install* version **3.4.0.0** and higher provide an `override` option in the repository configuration. It marks the associated repository as canonical for all packages defined in that repository. No other repositories will be considered. For example: ``` -- For packages in repo.example.com, -- only versions in repo.example.com are considered active-repositories: , hackage.haskell.org , repo.example.com:override ``` Users and organisations using private repositories that contain private packages in addition to public repositories **MUST** use the `override` option to prevent dependency confusion attacks. Alternatively, projects and organisations can run a private instance of *hackage-server* and carefully curate and review its contents. Using that instance exclusively defeats supply chain attacks including *dependency confusion*. For *cabal-install < 3.4* and where using multiple repositories, this is the only effective mitigation against dependency confusion attacks.

Timeline
Published
unknown
Last Modified
unknown
CVSS Details

CVSS details not available.

Affected Products

No product information available.

References
Linked Vulnerabilities

No linked vulnerabilities found.

{
  "affected": [
    {
      "database_specific": {
        "human_link": "https://github.com/haskell/security-advisories/tree/main/advisories/published/2025/HSEC-2025-0005.md",
        "osv": "https://raw.githubusercontent.com/haskell/security-advisories/refs/heads/generated/osv-export/2025/HSEC-2025-0005.json",
        "source": "https://github.com/haskell/security-advisories/blob/generated/osv-export/2025/HSEC-2025-0005.json"
      },
      "package": {
        "ecosystem": "Hackage",
        "name": "cabal-install",
        "purl": "pkg:hackage/cabal-install"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "1.0.0.0"
            },
            {
              "fixed": "3.4.0.0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ],
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N",
          "type": "CVSS_V3"
        }
      ],
      "versions": [
        "1.16.0",
        "1.16.0.1",
        "1.16.0.2",
        "1.16.1.0",
        "1.18.0",
        "1.18.0.1",
        "1.18.0.2",
        "1.18.0.3",
        "1.18.0.4",
        "1.18.0.5",
        "1.18.0.6",
        "1.18.0.7",
        "1.18.0.8",
        "1.18.1.0",
        "1.18.2.0",
        "1.20.0.0",
        "1.20.0.1",
        "1.20.0.2",
        "1.20.0.3",
        "1.20.0.4",
        "1.20.0.5",
        "1.20.0.6",
        "1.20.1.0",
        "1.20.2.0",
        "1.22.0.0",
        "1.22.0.1",
        "1.22.2.0",
        "1.22.3.0",
        "1.22.4.0",
        "1.22.5.0",
        "1.22.6.0",
        "1.22.7.0",
        "1.22.8.0",
        "1.22.9.0",
        "1.24.0.0",
        "1.24.0.1",
        "1.24.0.2",
        "2.0.0.0",
        "2.0.0.1",
        "2.2.0.0",
        "2.4.0.0",
        "2.4.1.0",
        "3.0.0.0",
        "3.2.0.0"
      ]
    }
  ],
  "database_specific": {
    "home": "https://github.com/haskell/security-advisories",
    "osvs": "https://raw.githubusercontent.com/haskell/security-advisories/refs/heads/generated/osv-export",
    "repository": "https://github.com/haskell/security-advisories"
  },
  "details": "# `cabal-install` dependency confusion\n\nFor **cabal-install < 3.4.0.0** and where multiple repositories are\nconfigured, the resolver picks the highest available version across\nall repositories.  Where a package is only defined in a private\nrepository, this behaviour leads to a [*dependency confusion*][blog]\nsupply chain vulnerability.  If the private package name becomes\nknown, a malicious actor can claim the name in the public repository\nand publish a malicious version at a higher version number.\n\nDefault `cabal-install` configurations that only use the\n`hackage.haskell.org` repository are not affected.  Configurations\nthat use curated private repositories **exclusively** are also not\naffected.\n\n[blog]: https://frasertweedale.github.io/blog-fp/posts/2021-02-12-haskell-dependency-confusion.html\n\n\n## Mitigations\n\n*cabal-install* version **3.4.0.0** and higher provide an `override`\noption in the repository configuration.  It marks the associated\nrepository as canonical for all packages defined in that repository.\nNo other repositories will be considered.  For example:\n\n```\n-- For packages in repo.example.com,\n-- only versions in repo.example.com are considered\nactive-repositories:\n  , hackage.haskell.org\n  , repo.example.com:override\n```\n\nUsers and organisations using private repositories that contain\nprivate packages in addition to public repositories **MUST** use the\n`override` option to prevent dependency confusion attacks.\n\nAlternatively, projects and organisations can run a private instance\nof *hackage-server* and carefully curate and review its contents.\nUsing that instance exclusively defeats supply chain attacks\nincluding *dependency confusion*.  For *cabal-install < 3.4* and\nwhere using multiple repositories, this is the only effective\nmitigation against dependency confusion attacks.\n",
  "id": "HSEC-2025-0005",
  "modified": "2025-11-14T18:15:46.044845Z",
  "published": "2025-11-14T14:45:34Z",
  "references": [
    {
      "type": "REPORT",
      "url": "https://frasertweedale.github.io/blog-fp/posts/2021-02-12-haskell-dependency-confusion.html"
    }
  ],
  "schema_version": "1.7.5",
  "summary": "cabal-install dependency confusion"
}
View JSON API Download JSON