← All distributions
Updated 14:01
Determinate Secure Packages distribution
secure-packages-26.05SupportedAvailable for use in production environments and covered by our standard service-level agreement (SLA).FIPS supportedA FIPS distribution is available for environments that require cryptography compliant with Federal Information Processing Standards.
Built on Nixpkgs 26.05. Available for use in production environments and covered by our standard service-level agreement (SLA).
Fixed in the last 30 days
751
Fixed in the last 7 days
575
In progress
189
Use this distribution
Customers onlyDeterminate Secure Packages is available through FlakeHub to organizations with access. Not a customer yet? Get in touch to gain access or schedule a demo.
Standardflake.nix
{
inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-26.05/0";
}FIPS variant
FIPS variantflake.nix
{
inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-26.05-fips/0";
}In the FIPS variant, every covered package is compliant with Federal Information Processing Standards (FIPS). Using the FIPS variant has the details.
940 CVEs tracked
| CVE | Status | Severity | Summary | Fixed |
|---|---|---|---|---|
| Fixed | High | RUSTSEC-2026-0245: sevenz-rust path traversal: decompress_impl allows extraction outside target directory via unchecked entry paths | Sep 6, 2026 | |
| Fixed | High | RUSTSEC-2026-0195: quick-xml NsReader/NamespaceResolver unbounded heap from many namespace declarations, enabling attacker-triggered OOM | Sep 6, 2026 | |
| Fixed | High | RUSTSEC-2026-0194: O(N^2) duplicate-attribute check in quick-xml, including NsReader, allows CPU DoS | Sep 6, 2026 | |
| Fixed | High | RUSTSEC-2026-0189: rmcp Streamable HTTP server pre-1.4.0 missing Host validation allows DNS rebinding attacks | Sep 6, 2026 | |
| Fixed | High | RUSTSEC-2026-0187: lopdf::Document::load_mem unbounded recursion on nested PDF arrays/dicts; stack overflow DoS | Sep 6, 2026 | |
| Fixed | High | RUSTSEC-2026-0185: Non-contiguous RecvStream fragments cause Assembler buffer bloat, risking memory exhaustion during ordered reads | Sep 6, 2026 | |
| Fixed | High | RUSTSEC-2026-0103: thin-vec IntoIter::drop and clear on panic trigger double free/UAF memory corruption via safe Rust | Sep 6, 2026 | |
| Fixed | Medium | RUSTSEC-2026-0068: tar-rs <=0.4.44 ignores PAX size override if base size set, mismatching archivers | Sep 6, 2026 | |
| Fixed | Medium | RUSTSEC-2026-0067: tar-rs ≤0.4.44 unpack_dir symlink bug allows chmod of directories outside extraction root | Sep 6, 2026 | |
| Fixed | Medium | RUSTSEC-2026-0066: astral-tokio-tar <=0.5.6 silently skips malformed PAX extensions, enabling parser differential | Sep 6, 2026 | |
| Fixed | High | RUSTSEC-2026-0048: AWS-LC CRL distribution point bug lets revoked certificates bypass checks with partitioned CRLs | Sep 6, 2026 | |
| Fixed | High | RUSTSEC-2026-0047: AWS-LC PKCS7_verify signature validation flaw enables unauthenticated bypass; affects aws-lc-sys users | Sep 6, 2026 | |
| Fixed | High | RUSTSEC-2026-0046: AWS-LC PKCS7_verify improper certificate validation enables chain bypass with multiple signers | Sep 6, 2026 | |
| Fixed | Medium | RUSTSEC-2026-0045: Timing side-channel in AWS-LC EVP AES-CCM decryption leaks tag validity | Sep 6, 2026 | |
| Fixed | High | RUSTSEC-2026-0041: Invalid LZ4 block decompression leaks uninitialized/prior buffer data due to lz4_flex offset validation bug | Sep 6, 2026 | |
| Fixed | High | RUSTSEC-2026-0037: Invalid QUIC transport parameters cause panic due to unwrap() in parsing code | Sep 6, 2026 | |
| Fixed | Medium | RUSTSEC-2026-0009: RFC 2822 parsing vulnerability enables stack-exhaustion DoS with maliciously crafted inputs | Sep 6, 2026 | |
| Fixed | Medium | RUSTSEC-2023-0071: rsa crate timing side-channel leaks private key over network due to non-constant-time | Sep 6, 2026 | |
| Fixed | High | RUSTSEC-2021-0041: BigInt exponent parsing in parse_duration::parse leads to CPU/memory exhaustion DoS | Sep 6, 2026 | |
| Fixed | Medium | GHSA-xx64-wwv2-hcqq: astral-tokio-tar <=0.6.0 unpack_in can change permissions of directories outside archive | Sep 6, 2026 | |
| Fixed | High | GHSA-xwg4-73v4-xw9w: nanoid size integer overflow corrupts CSPRNG pool; process-wide persistent deterministic 'u' IDs | Sep 6, 2026 | |
| Fixed | Low | GHSA-xwfj-jgwm-7wp5: ANSI escape sequence injection in tracing-subscriber logs can manipulate terminal output | Sep 6, 2026 | |
| Fixed | High | GHSA-xvcm-6775-5m9r: Immutable.Map/Set hash collision DoS via crafted keys causing O(n^2) operations | Sep 6, 2026 | |
| Fixed | Medium | GHSA-xv59-967r-8726: rust-openssl AES wrap_pad updates overflow on non-multiple-of-8 inputs, causing attacker-controlled heap corruption | Sep 6, 2026 | |
| Fixed | High | GHSA-xpqw-6gx7-v673: SVGO expands custom XML entities recursively, enabling DoS and Node.js heap out-of-memory. | Sep 6, 2026 | |
| Fixed | High | GHSA-xphw-cqx3-667j: thin_vec IntoIter::drop and clear cause double free/UAF when element Drop panics | Sep 6, 2026 | |
| Fixed | Medium | GHSA-xphf-cx8h-7q9g: Unsafe reference returned into OpenSSL data structure; OpenSSL may mutate behind callers' back. | Sep 6, 2026 | |
| Fixed | High | GHSA-xp3w-r5p5-63rr: Unchecked UTF-8 in X509Ref::ocsp_responders causes undefined behavior with non-ASCII IA5String OCSP URLs | Sep 6, 2026 | |
| Fixed | Medium | GHSA-xmgf-hq76-4vx2: Password callback over-read due to *_from_pem_callback length validation bug in pre-3.x OpenSSL | Sep 6, 2026 | |
| Fixed | Low | GHSA-xgp8-3hg3-c2mh: Wildcard DNS names bypass permitted subtree checks in X.509 name constraints | Sep 6, 2026 | |
| Fixed | Medium | GHSA-xcf7-rvmh-g6q4: Empty string input triggers OpenSSL strlen, causing out-of-bounds memory read until NUL. | Sep 6, 2026 | |
| Fixed | Medium | GHSA-x5fp-wj9c-mxmx: qs v6.15.3 bracket-key input bypasses arrayLimit when comma=true, enabling memory DoS | Sep 6, 2026 | |
| Fixed | High | GHSA-x494-mj8g-cj27: gix-pack DoS: unchecked delta indexing panics and uncapped size headers OOM via malicious packs | Sep 6, 2026 | |
| Fixed | Critical | GHSA-wwq9-3cpr-mm53: Non-canonical Borsh HashMap serialization; order-dependent encoding and missing checks cause consensus splits | Sep 6, 2026 | |
| Fixed | Critical | GHSA-wf6x-7x77-mvgw: Immutable.js prototype pollution in merge/mergeDeep/mergeDeepWith and Map.toJS/toObject APIs | Sep 6, 2026 | |
| Fixed | Medium | GHSA-w9m9-85wc-3x92: Uncontrolled recursion in postcss-selector-parser AST toString leads remote DoS (pre-6.1.3/7.1.1) | Sep 6, 2026 | |
| Fixed | Medium | GHSA-w8wr-v893-vjvp: All-digit PAX path parsed as number crashes node-tar extraction with uncaught TypeError | Sep 6, 2026 | |
| Fixed | Critical | GHSA-w7jw-789q-3m8p: shell-quote quote() fails to escape line terminators in object .op, enabling command injection | Sep 6, 2026 | |
| Fixed | High | GHSA-w5hq-g745-h8pq: External buffer out-of-range not rejected in uuid v3/v5/v6; silent partial writes; inconsistent with v4/v1/v7 | Sep 6, 2026 | |
| Fixed | High | GHSA-w3rx-r6r6-pgpr: image-size ≤2.0.2 DoS: ICNS zero-length entry triggers infinite Node.js event loop | Sep 6, 2026 | |
| Fixed | Medium | GHSA-w2qp-rph6-63g4: Root primitive body coercion mismatch exposes uncoerced value to handlers in Fastify <5.12.1 | Sep 6, 2026 | |
| Fixed | High | GHSA-vxpw-j846-p89q: undici WebSocket client allows unbounded message fragments, causing memory exhaustion denial-of-service | Sep 6, 2026 | |
| Fixed | High | GHSA-vw5v-4f2q-w9xf: aws-lc-sys PKCS7_verify certificate chain verification bypass with multiple signers (v0.24.0–0.37.x) | Sep 6, 2026 | |
| Fixed | High | GHSA-vvp9-7p8x-rfvv: Invalid offset handling in lz4_flex block decompression leaks uninitialized/previous buffer data | Sep 6, 2026 | |
| Fixed | High | GHSA-vmh5-mc38-953g: Undici SOCKS5 ProxyAgent drops requestTls, bypassing custom TLS options and CA pinning | Sep 6, 2026 | |
| Fixed | Medium | GHSA-vmf3-w455-68vh: node-tar PAX size misapplied to L/K/x headers causes parsing desync, hidden files | Sep 6, 2026 | |
| Fixed | Medium | GHSA-vfvv-c25p-m7mm: rkyv InlineVec and SerVec clear() not panic-safe, enabling double free/use-after-free vulnerabilities | Sep 6, 2026 | |
| Fixed | Medium | GHSA-v6wh-96g9-6wx3: launch-editor allows UNC paths, triggering Windows NTLM auth and leaking NTLMv2 hashes | Sep 6, 2026 | |
| Fixed | High | GHSA-v5mp-jgw5-2x6j: toml.parse Object.prototype pollution via scalar __proto__ traversal and path-tracking desync | Sep 6, 2026 | |
| Fixed | High | GHSA-v56q-mh7h-f735: Immutable.js List index >=2^30 triggers uncatchable loop or OOM abort; setSize wraps | Sep 6, 2026 |
Make CVE remediation our job, not yours.
Tell us what you run. We'll show you what Determinate Secure Packages covers, how the SLA applies, and how to get started.