Skip to content

Updated 03:00

Determinate Secure Packages CVE Remediation Dashboard

Every CVE (Common Vulnerabilities and Exposures record) in Determinate Secure Packages has a fix deadline determined by our service-level agreement (SLA). See how Determinate Secure Packages stays ahead of CVEs.

Fixed within SLA

933

last 30 days

Fixed within SLA

44

last 7 days

Open

82

not yet fixed but still within SLA

Overdue

0

open

Missed SLA

0

last 30 days

Currently tracked CVEs

Every dot is one currently tracked CVE, with a color and shape indicating its current status, and placed in the row that corresponds to its severity and the position on the x-axis that corresponds to the day of its SLA deadline. The vertically aligned dotted purple lines indicate SLA dates for the corresponding severity.

Severity
Status

52 of 516 tracked CVEs shown.

Critical7-day SLA (0)+7dHigh15-day SLA (52)+15dAug 2Aug 9Aug 16Aug 23Sep 6Sep 13Aug 2Aug 9Aug 16Aug 23Aug 30Sep 6Sep 13SeveritySLA deadlineTodayCVE-2026-14679 · Open · CVE-2026-14679: PostgreSQL stack buffer overflow via OUT parameter count in argument name matching; 0x0/0x1 writesCVE-2026-14671 · Open · CVE-2026-14671: PostgreSQL refint type confusion enables arbitrary code execution as DB OS user; affects <18.5/17.11/16.15/15.19/14.24CVE-2026-6471 · Open · CVE-2026-6471: PostgreSQL logical decoding auth flaw lets REPLICATION users dlopen arbitrary files, execute codeCVE-2026-16238 · Open · CVE-2026-16238: PostgreSQL 18.0-18.4 pg_restore_attribute_stats type confusion enables OS-level code execution via range/multirangeCVE-2026-14677 · Open · CVE-2026-14677: PostgreSQL 32-bit pltcl/plperl integer wraparound enables OOB write and RCE (pre-18.5/17.11/16.15/15.19/14.24)CVE-2026-64117 · Open · CVE-2026-64117: mac80211 use-after-free: fast-RX reads RX status after mesh forwarding reuses skb->cbCVE-2026-14668 · Open · CVE-2026-14668: PostgreSQL ctid selectivity estimator type confusion leaks 4-byte memory data (pre-18.5/17.11/16.15/15.19/14.24)CVE-2026-14680 · Open · CVE-2026-14680: Type confusion in PostgreSQL 'internal' arguments enables arbitrary code execution by any user via functionsCVE-2026-19385 · Open · CVE-2026-19385: pg_dump heap overflow on long transform lists enables RCE; PostgreSQL <18.5/17.11/16.15/15.19/14.24CVE-2026-14669 · Open · CVE-2026-14669: Heap overflow in PostgreSQL to_char(timestamptz) enables code execution via long timezone abbreviationCVE-2026-15742 · Open · CVE-2026-15742: PostgreSQL fuzzystrmatch integer wraparound enables RCE via levenshtein; affects versions before 18.5/17.11/16.15/15.19/14.24CVE-2026-18408 · Open · CVE-2026-18408: Restore-time code execution via psql \restrict/\unrestrict in PostgreSQL pg_dump/pg_dumpall/pg_restoreCVE-2026-14670 · Open · CVE-2026-14670: Heap buffer overflow in PostgreSQL plperl tied hash return enables function owner OS code executionCVE-2026-14664 · Open · CVE-2026-14664: PostgreSQL regexp heap overflow permits RCE via invalid encoding; pre-18.5/17.11/16.15/15.19/14.24 affectedCVE-2026-15741 · Open · CVE-2026-15741: PostgreSQL EXTRACT() deparse SQL injection lets object owners run superuser SQL; affects pg_dump and psqlCVE-2026-16239 · Open · CVE-2026-16239: PostgreSQL portal/cursor type confusion enables arbitrary OS-level code execution; before 18.5/17.11/16.15/15.19/14.24.CVE-2026-6464 · Open · CVE-2026-6464: psql COPY FROM STDIN may execute data rows as commands on early failureCVE-2026-14662 · Open · CVE-2026-14662: PostgreSQL tsvector/tsquery integer wraparound causes OOB write RCE; affects <18.5/17.11/16.15/15.19/14.24CVE-2026-14669 · Open · CVE-2026-14669: PostgreSQL to_char(timestamptz) heap overflow via long POSIX timezone allows OS-user RCECVE-2026-15742 · Open · CVE-2026-15742: PostgreSQL fuzzystrmatch integer wraparound enables RCE via levenshtein/levenshtein_less_equal extreme inputsCVE-2026-14662 · Open · CVE-2026-14662: PostgreSQL tsvector/tsquery integer wraparound enables unprivileged OOB write and potential RCECVE-2026-15741 · Open · CVE-2026-15741: PostgreSQL EXTRACT() deparse SQL injection lets object owners escalate to superuser via deparse consumersCVE-2026-18408 · Open · CVE-2026-18408: PostgreSQL pg_dump/pg_dumpall/pg_restore restore-time RCE via psql \restrict/\unrestrict expansion; CVE-2025-8714 bypassCVE-2026-14671 · Open · CVE-2026-14671: PostgreSQL refint type confusion allows arbitrary code execution as DB OS user (pre-18.5/17.11/16.15/15.19/14.24)CVE-2026-16238 · Open · CVE-2026-16238: pg_restore_attribute_stats type confusion lets object creators execute OS code in PostgreSQL 18 before 18.5CVE-2026-6464 · Open · CVE-2026-6464: Security: psql COPY FROM STDIN may execute data rows as commands on failureCVE-2026-6471 · Open · CVE-2026-6471: Logical decoding lacks authorization, REPLICATION users can dlopen arbitrary files, execute code as server accountCVE-2026-19385 · Open · CVE-2026-19385: PostgreSQL pg_dump heap buffer overflow via crafted long transform lists enables OS user RCECVE-2026-14668 · Open · CVE-2026-14668: Type confusion in PostgreSQL ctid selectivity estimator enables memory disclosure via crafted non-ctid inputCVE-2026-16239 · Open · CVE-2026-16239: PostgreSQL portal/cursor type confusion permits arbitrary code execution as database OS user pre-18.5/17.11/16.15/15.19/14.24CVE-2026-14670 · Open · CVE-2026-14670: PostgreSQL plperl tied-hash return heap overflow enables OS code execution; affects pre 18.5/17.11/16.15/15.19/14.24CVE-2026-14679 · Open · CVE-2026-14679: PostgreSQL stack buffer overflow in argument name matching via OUT parameter countCVE-2026-14664 · Open · CVE-2026-14664: PostgreSQL regexp heap overflow enables OS-level RCE via invalid-encoding text; pre-18.5/17.11/16.15/15.19/14.24 affectedCVE-2026-14677 · Open · CVE-2026-14677: PostgreSQL pltcl/plperl 32-bit integer wraparound causes OOB write, potential RCE; pre-18.5 affectedCVE-2026-14680 · Open · CVE-2026-14680: PostgreSQL 'internal' type confusion enables arbitrary OS code execution by any userCVE-2026-18408 · Open · CVE-2026-18408: pg_dump/pg_dumpall/pg_restore restore-time RCE via psql \restrict/\unrestrict; affects pre-18.5/17.11/16.15/15.19/14.24CVE-2026-14664 · Open · CVE-2026-14664: PostgreSQL regexp heap overflow enables arbitrary code execution via invalid encoding input affects pre-18.5/17.11/16.15/15.19/14.24CVE-2026-14679 · Open · CVE-2026-14679: PostgreSQL stack buffer overflow in OUT parameter name matching with limited 0/1-byte writesCVE-2026-15742 · Open · CVE-2026-15742: Integer wraparound RCE in PostgreSQL fuzzystrmatch via levenshtein/less_equal before 18.5/17.11/16.15/15.19/14.24CVE-2026-19385 · Open · CVE-2026-19385: PostgreSQL pg_dump heap buffer overflow in transform lists enables RCE; versions <18.5/17.11/16.15/15.19/14.24CVE-2026-6464 · Open · CVE-2026-6464: psql COPY FROM STDIN pre-input error executes data lines as commandsCVE-2026-14677 · Open · CVE-2026-14677: PostgreSQL 32-bit pltcl/plperl integer wraparound causes undersized allocation, OOB write, RCECVE-2026-14680 · Open · CVE-2026-14680: PostgreSQL 'internal' type confusion lets any user execute arbitrary code; affects <18.5,17.11,16.15,15.19,14.24CVE-2026-14669 · Open · CVE-2026-14669: Heap buffer overflow in PostgreSQL to_char(timestamptz) via long timezone abbreviation enables RCECVE-2026-14671 · Open · CVE-2026-14671: PostgreSQL refint type confusion allows arbitrary OS code execution; no CVE; affects pre-18.5/17.11/16.15/15.19/14.24CVE-2026-14670 · Open · CVE-2026-14670: PostgreSQL plperl tied-hash return heap overflow enables RCE as database OS userCVE-2026-14662 · Open · CVE-2026-14662: PostgreSQL tsvector/tsquery integer wraparound allows OOB write, potential RCE by unprivileged usersCVE-2026-16239 · Open · CVE-2026-16239: Type confusion in PostgreSQL portal/cursor lifecycle enables OS-level code execution; pre-18.5, 17.11, 16.15, 15.19, 14.24CVE-2026-6471 · Open · CVE-2026-6471: PostgreSQL logical decoding auth flaw lets REPLICATION users execute arbitrary code as server OS accountCVE-2026-14668 · Open · CVE-2026-14668: PostgreSQL ctid selectivity estimator type confusion leaks 4-byte memory-derived values via non-ctid inputCVE-2026-16238 · Open · CVE-2026-16238: PostgreSQL 18<18.5 pg_restore_attribute_stats type confusion allows RCE as database OS userCVE-2026-15741 · Open · CVE-2026-15741: SQL injection in PostgreSQL EXTRACT() deparse allows superuser execution via hostile object definitions

  • Open (52)
  • Today
  • SLA deadline for a CVE published today

About Determinate Secure Packages

Every fix on this page is one you didn't have to make. Determinate Secure Packages watches the packages you depend on, patches them within the SLA, and ships the builds to you.

Determinate Secure Packages overview

What you get, how it fits your Nix setup, and how to start.

determinate.systems (opens in a new tab)

Documentation

How the SLA works, which packages we cover, and how to use them.

docs.determinate.systems (opens in a new tab)

Supply chain security

Control over the code, dependencies, builds, and environments behind every system you run.

determinate.systems (opens in a new tab)

Make CVE remediation our job, not yours.

Tell us what you run. We'll show you what Determinate Secure Packages covers, how the SLA applies, and how to get started.

Email sales@determinate.systems

Vulnerability databases

The databases the dashboard draws on. Every CVE here is one of theirs.