← All distributions
Updated 14:01
Determinate Secure Packages distribution
secure-packages-25.11SupportedAvailable for use in production environments and covered by our standard service-level agreement (SLA).FIPS plannedPackages are not yet available in a FIPS-compliant variant, but we plan to release one.
Built on Nixpkgs 25.11. Available for use in production environments and covered by our standard service-level agreement (SLA).
Fixed in the last 30 days
794
Fixed in the last 7 days
674
In progress
123
Use this distribution
Customers onlyDeterminate Secure Packages is available through FlakeHub to organizations with access. Not a customer yet? Get in touch to gain access or schedule a demo.
Standardflake.nix
{
inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-25.11/0";
}917 CVEs tracked
| CVE | Status | Severity | Summary | Fixed |
|---|---|---|---|---|
| Fixed | Low | Skia cross-origin data leak in Chrome <152.0.7977.75 via crafted HTML, compromised renderer | Sep 6, 2026 | |
| Fixed | Medium | Improper Downloads privileges allow address bar spoofing from compromised renderer in Chrome pre-152.0.7977.75 | Sep 6, 2026 | |
| Fixed | Medium | Chrome Omnibox input validation flaw enables web origin policy bypass pre-152.0.7977.75 via crafted network traffic | Sep 6, 2026 | |
| Fixed | Medium | Chrome pre-152.0.7977.75 fullscreen UI bug enables address bar spoofing via crafted HTML | Sep 6, 2026 | |
| Fixed | Low | Chrome <152.0.7977.75: Navigation authorization flaw allows web origin policy bypass via compromised renderer | Sep 6, 2026 | |
| Fixed | Critical | Chrome <152.0.7977.75 FileSystem auth flaw allows RCE outside sandbox via crafted HTML | Sep 6, 2026 | |
| Fixed | High | Chrome Windows GPU buffer overflow enables sandbox escape RCE via crafted HTML (pre-152.0.7977.75) | Sep 6, 2026 | |
| Fixed | High | Chrome TabStrip use-after-free enabling RCE outside sandbox via UI interaction pre-152.0.7977.75 | Sep 6, 2026 | |
| Fixed | High | Chrome <152.0.7977.75 Browser UAF allows code execution outside sandbox after renderer compromise via crafted HTML | Sep 6, 2026 | |
| Fixed | Medium | Chrome <152.0.7977.75 MediaCapture info leak via crafted HTML allows remote data exposure | Sep 6, 2026 | |
| Fixed | High | Chrome pre-152.0.7977.75 WebRTC use-after-free enables sandboxed RCE via crafted HTML | Sep 6, 2026 | |
| Fixed | High | Chrome TabStrip authorization bug enables arbitrary code execution outside sandbox via crafted HTML (pre-152.0.7977.75) | Sep 6, 2026 | |
| Fixed | High | Incorrect Chromoting authorization allows local code execution outside sandbox on Windows before 152.0.7977.75 | Sep 6, 2026 | |
| Fixed | Medium | Google Chrome <152.0.7977.75 SiteSettings authorization bug allows remote bypass of access restrictions via crafted HTML | Sep 6, 2026 | |
| Fixed | Low | Chrome <152.0.7977.75 Actor auth flaw let compromised renderer bypass web origin policy via crafted HTML | Sep 6, 2026 | |
| Fixed | Medium | Windows Chrome pre-152.0.7977.75 CredentialProvider confused deputy leaks sensitive info from compromised renderer via HTML | Sep 6, 2026 | |
| Fixed | Low | Missing FileSystem authorization in Chrome <152.0.7977.75 lets compromised renderer bypass web origin policy | Sep 6, 2026 | |
| Fixed | High | Chrome V8 uninitialized resource enables sandboxed RCE via crafted HTML (pre-152.0.7977.75) | Sep 6, 2026 | |
| Fixed | Critical | Chrome <152.0.7977.75 DataTransfer validation bug enables system access bypass via co-installed app | Sep 6, 2026 | |
| Fixed | Critical | Google Chrome pre-152.0.7977.75 Proxy use-after-free enables RCE outside sandbox via crafted traffic | Sep 6, 2026 | |
| Fixed | Medium | Chrome <152.0.7977.75 FileSystem auth bypass lets compromised renderer exfiltrate data via crafted HTML | Sep 6, 2026 | |
| Fixed | High | WebView external reference vulnerability allows code execution outside sandbox pre-152.0.7977.65 Android | Sep 6, 2026 | |
| Fixed | Medium | iOS Chrome <152.0.7977.65 local sensitive info leak via crafted file | Sep 6, 2026 | |
| Fixed | High | RUSTSEC-2026-0195: quick-xml NsReader unbounded namespace declarations cause excessive heap allocation and potential OOM | Sep 5, 2026 | |
| Fixed | High | RUSTSEC-2026-0194: quick-xml BytesStart::attributes duplicate-name check O(N²), enabling CPU exhaustion on large tags | Sep 5, 2026 | |
| Fixed | High | RUSTSEC-2026-0189: rmcp <1.4.0 HTTP transport lacked Host validation, enabling DNS rebinding to local MCP servers | Sep 5, 2026 | |
| Fixed | High | RUSTSEC-2026-0187: lopdf unbounded recursion on nested PDF arrays causes stack overflow SIGABRT DoS (<=0.41.0) | Sep 5, 2026 | |
| Fixed | High | RUSTSEC-2026-0185: Assembler handling of sparse RecvStream fragments causes high buffering overhead and memory exhaustion risk | Sep 5, 2026 | |
| Fixed | High | RUSTSEC-2026-0103: thin-vec: Panic during Drop causes double free/UAF in IntoIter::drop and ThinVec::clear | Sep 5, 2026 | |
| Fixed | Medium | RUSTSEC-2026-0068: tar-rs <=0.4.44 ignores PAX size override when base header nonzero; inconsistent parsing | Sep 5, 2026 | |
| Fixed | Medium | RUSTSEC-2026-0067: tar-rs <=0.4.44 unpack_dir symlink bug allows chmod outside extraction root | Sep 5, 2026 | |
| Fixed | Medium | RUSTSEC-2026-0066: astral-tokio-tar <=0.5.6 silently skips malformed PAX extensions, enabling parser differential risk | Sep 5, 2026 | |
| Fixed | High | RUSTSEC-2026-0048: AWS-LC CRL distribution point bug lets revoked certs bypass revocation with partitioned CRLs, IDP | Sep 5, 2026 | |
| Fixed | High | RUSTSEC-2026-0047: AWS-LC PKCS7_verify improper signature validation allows unauthenticated bypass via authenticated attributes | Sep 5, 2026 | |
| Fixed | High | RUSTSEC-2026-0046: Unauthenticated chain bypass in AWS-LC/aws-lc-sys PKCS7_verify for multi-signer PKCS7 except final signer | Sep 5, 2026 | |
| Fixed | Medium | RUSTSEC-2026-0045: Timing side-channel in AWS-LC AES-CCM EVP decryption leaks authentication tag validity | Sep 5, 2026 | |
| Fixed | High | RUSTSEC-2026-0041: lz4_flex block decompression offset bug leaks uninitialized memory and previous output buffer contents | Sep 5, 2026 | |
| Fixed | High | RUSTSEC-2026-0037: Panic on invalid QUIC transport parameters due to unwrap() in parsing. | Sep 5, 2026 | |
| Fixed | Medium | RUSTSEC-2026-0009: RFC 2822 parsing vulnerability enables denial-of-service via stack exhaustion with malicious input | Sep 5, 2026 | |
| Fixed | Medium | RUSTSEC-2025-0021: gitoxide uses SHA-1 without collision detection, enabling hash collision attacks on Git objects | Sep 5, 2026 | |
| Fixed | High | RUSTSEC-2024-0013: libgit2 <1.7.2 vulnerabilities: revparse DoS, index add RCE, smart transport OOB read | Sep 5, 2026 | |
| Fixed | Medium | RUSTSEC-2023-0071: Non-constant-time RSA in rsa crate leaks keys via network timing side-channel | Sep 5, 2026 | |
| Fixed | Medium | RUSTSEC-2020-0071: time crate unsynchronized environment variable updates cause multithreaded Unix segfaults (v0.1, 0.2.7–0.2.22) | Sep 5, 2026 | |
| Fixed | High | GHSA-xxjr-mmjv-4gpg: Lodash 4.0.0–4.17.22 prototype pollution via _.unset/_.omit deletes global prototype properties | Sep 5, 2026 | |
| Fixed | Medium | GHSA-xx64-wwv2-hcqq: astral-tokio-tar <=0.6.0 unpack_in modifies permissions of external directories outside archive | Sep 5, 2026 | |
| Fixed | High | GHSA-xwg4-73v4-xw9w: Integer overflow in nanoid(size) breaks randomness; all IDs become 'u' until restart | Sep 5, 2026 | |
| Fixed | Low | GHSA-xwfj-jgwm-7wp5: tracing-subscriber pre-0.3.20 allows ANSI escape injection via logs, enabling terminal manipulation | Sep 5, 2026 | |
| Fixed | High | GHSA-xvcm-6775-5m9r: Immutable.js Map/Set DoS via deterministic string hash collisions on attacker-controlled keys | Sep 5, 2026 | |
| Fixed | Medium | GHSA-xv59-967r-8726: CipherCtxRef/symm::Crypter update mis-sizes AES key-wrap-with-padding output, causing attacker-controlled heap overflow | Sep 5, 2026 | |
| Fixed | High | GHSA-xpqw-6gx7-v673: SVGO allows unguarded XML entity expansion causing DoS and Node.js heap exhaustion | Sep 5, 2026 |
Make CVE remediation our job, not yours.
Tell us what you run. We'll show you what Determinate Secure Packages covers, how the SLA applies, and how to get started.