Skip to content
All distributions

Updated 14:01

Determinate Secure Packages distribution

secure-packages-25.11SupportedFIPS planned

Built on Nixpkgs 25.11. Available for use in production environments and covered by our standard service-level agreement (SLA).

Fixed in the last 30 days

794

Fixed in the last 7 days

674

In progress

123

Determinate Secure Packages is available through FlakeHub to organizations with access. Not a customer yet? Get in touch to gain access or schedule a demo.

Standardflake.nix

{
  inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-25.11/0";
}

917 CVEs tracked

Severity
Status
CVEStatusSeveritySummaryFixed
FixedLowSkia cross-origin data leak in Chrome <152.0.7977.75 via crafted HTML, compromised rendererSep 6, 2026
FixedMediumImproper Downloads privileges allow address bar spoofing from compromised renderer in Chrome pre-152.0.7977.75Sep 6, 2026
FixedMediumChrome Omnibox input validation flaw enables web origin policy bypass pre-152.0.7977.75 via crafted network trafficSep 6, 2026
FixedMediumChrome pre-152.0.7977.75 fullscreen UI bug enables address bar spoofing via crafted HTMLSep 6, 2026
FixedLowChrome <152.0.7977.75: Navigation authorization flaw allows web origin policy bypass via compromised rendererSep 6, 2026
FixedCriticalChrome <152.0.7977.75 FileSystem auth flaw allows RCE outside sandbox via crafted HTMLSep 6, 2026
FixedHighChrome Windows GPU buffer overflow enables sandbox escape RCE via crafted HTML (pre-152.0.7977.75)Sep 6, 2026
FixedHighChrome TabStrip use-after-free enabling RCE outside sandbox via UI interaction pre-152.0.7977.75Sep 6, 2026
FixedHighChrome <152.0.7977.75 Browser UAF allows code execution outside sandbox after renderer compromise via crafted HTMLSep 6, 2026
FixedMediumChrome <152.0.7977.75 MediaCapture info leak via crafted HTML allows remote data exposureSep 6, 2026
FixedHighChrome pre-152.0.7977.75 WebRTC use-after-free enables sandboxed RCE via crafted HTMLSep 6, 2026
FixedHighChrome TabStrip authorization bug enables arbitrary code execution outside sandbox via crafted HTML (pre-152.0.7977.75)Sep 6, 2026
FixedHighIncorrect Chromoting authorization allows local code execution outside sandbox on Windows before 152.0.7977.75Sep 6, 2026
FixedMediumGoogle Chrome <152.0.7977.75 SiteSettings authorization bug allows remote bypass of access restrictions via crafted HTMLSep 6, 2026
FixedLowChrome <152.0.7977.75 Actor auth flaw let compromised renderer bypass web origin policy via crafted HTMLSep 6, 2026
FixedMediumWindows Chrome pre-152.0.7977.75 CredentialProvider confused deputy leaks sensitive info from compromised renderer via HTMLSep 6, 2026
FixedLowMissing FileSystem authorization in Chrome <152.0.7977.75 lets compromised renderer bypass web origin policySep 6, 2026
FixedHighChrome V8 uninitialized resource enables sandboxed RCE via crafted HTML (pre-152.0.7977.75)Sep 6, 2026
FixedCriticalChrome <152.0.7977.75 DataTransfer validation bug enables system access bypass via co-installed appSep 6, 2026
FixedCriticalGoogle Chrome pre-152.0.7977.75 Proxy use-after-free enables RCE outside sandbox via crafted trafficSep 6, 2026
FixedMediumChrome <152.0.7977.75 FileSystem auth bypass lets compromised renderer exfiltrate data via crafted HTMLSep 6, 2026
FixedHighWebView external reference vulnerability allows code execution outside sandbox pre-152.0.7977.65 AndroidSep 6, 2026
FixedMediumiOS Chrome <152.0.7977.65 local sensitive info leak via crafted fileSep 6, 2026
FixedHighRUSTSEC-2026-0195: quick-xml NsReader unbounded namespace declarations cause excessive heap allocation and potential OOMSep 5, 2026
FixedHighRUSTSEC-2026-0194: quick-xml BytesStart::attributes duplicate-name check O(N²), enabling CPU exhaustion on large tagsSep 5, 2026
FixedHighRUSTSEC-2026-0189: rmcp <1.4.0 HTTP transport lacked Host validation, enabling DNS rebinding to local MCP serversSep 5, 2026
FixedHighRUSTSEC-2026-0187: lopdf unbounded recursion on nested PDF arrays causes stack overflow SIGABRT DoS (<=0.41.0)Sep 5, 2026
FixedHighRUSTSEC-2026-0185: Assembler handling of sparse RecvStream fragments causes high buffering overhead and memory exhaustion riskSep 5, 2026
FixedHighRUSTSEC-2026-0103: thin-vec: Panic during Drop causes double free/UAF in IntoIter::drop and ThinVec::clearSep 5, 2026
FixedMediumRUSTSEC-2026-0068: tar-rs <=0.4.44 ignores PAX size override when base header nonzero; inconsistent parsingSep 5, 2026
FixedMediumRUSTSEC-2026-0067: tar-rs <=0.4.44 unpack_dir symlink bug allows chmod outside extraction rootSep 5, 2026
FixedMediumRUSTSEC-2026-0066: astral-tokio-tar <=0.5.6 silently skips malformed PAX extensions, enabling parser differential riskSep 5, 2026
FixedHighRUSTSEC-2026-0048: AWS-LC CRL distribution point bug lets revoked certs bypass revocation with partitioned CRLs, IDPSep 5, 2026
FixedHighRUSTSEC-2026-0047: AWS-LC PKCS7_verify improper signature validation allows unauthenticated bypass via authenticated attributesSep 5, 2026
FixedHighRUSTSEC-2026-0046: Unauthenticated chain bypass in AWS-LC/aws-lc-sys PKCS7_verify for multi-signer PKCS7 except final signerSep 5, 2026
FixedMediumRUSTSEC-2026-0045: Timing side-channel in AWS-LC AES-CCM EVP decryption leaks authentication tag validitySep 5, 2026
FixedHighRUSTSEC-2026-0041: lz4_flex block decompression offset bug leaks uninitialized memory and previous output buffer contentsSep 5, 2026
FixedHighRUSTSEC-2026-0037: Panic on invalid QUIC transport parameters due to unwrap() in parsing.Sep 5, 2026
FixedMediumRUSTSEC-2026-0009: RFC 2822 parsing vulnerability enables denial-of-service via stack exhaustion with malicious inputSep 5, 2026
FixedMediumRUSTSEC-2025-0021: gitoxide uses SHA-1 without collision detection, enabling hash collision attacks on Git objectsSep 5, 2026
FixedHighRUSTSEC-2024-0013: libgit2 <1.7.2 vulnerabilities: revparse DoS, index add RCE, smart transport OOB readSep 5, 2026
FixedMediumRUSTSEC-2023-0071: Non-constant-time RSA in rsa crate leaks keys via network timing side-channelSep 5, 2026
FixedMediumRUSTSEC-2020-0071: time crate unsynchronized environment variable updates cause multithreaded Unix segfaults (v0.1, 0.2.7–0.2.22)Sep 5, 2026
FixedHighGHSA-xxjr-mmjv-4gpg: Lodash 4.0.0–4.17.22 prototype pollution via _.unset/_.omit deletes global prototype propertiesSep 5, 2026
FixedMediumGHSA-xx64-wwv2-hcqq: astral-tokio-tar <=0.6.0 unpack_in modifies permissions of external directories outside archiveSep 5, 2026
FixedHighGHSA-xwg4-73v4-xw9w: Integer overflow in nanoid(size) breaks randomness; all IDs become 'u' until restartSep 5, 2026
FixedLowGHSA-xwfj-jgwm-7wp5: tracing-subscriber pre-0.3.20 allows ANSI escape injection via logs, enabling terminal manipulationSep 5, 2026
FixedHighGHSA-xvcm-6775-5m9r: Immutable.js Map/Set DoS via deterministic string hash collisions on attacker-controlled keysSep 5, 2026
FixedMediumGHSA-xv59-967r-8726: CipherCtxRef/symm::Crypter update mis-sizes AES key-wrap-with-padding output, causing attacker-controlled heap overflowSep 5, 2026
FixedHighGHSA-xpqw-6gx7-v673: SVGO allows unguarded XML entity expansion causing DoS and Node.js heap exhaustionSep 5, 2026

Make CVE remediation our job, not yours.

Tell us what you run. We'll show you what Determinate Secure Packages covers, how the SLA applies, and how to get started.

Contact sales

Provide us with some basic details and we'll follow up with you about , usually within one business day.

We'll only use this to get back to you. See our privacy policy (opens in a new tab). This site is protected by reCAPTCHA and the Google Privacy Policy (opens in a new tab) and Terms of Service (opens in a new tab) apply.