Skip to content
All distributions

Updated 14:01

Determinate Secure Packages distribution

secure-packages-26.05SupportedFIPS supported

Built on Nixpkgs 26.05. Available for use in production environments and covered by our standard service-level agreement (SLA).

Fixed in the last 30 days

751

Fixed in the last 7 days

575

In progress

189

Determinate Secure Packages is available through FlakeHub to organizations with access. Not a customer yet? Get in touch to gain access or schedule a demo.

Standardflake.nix

{
  inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-26.05/0";
}
FIPS variant

FIPS variantflake.nix

{
  inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-26.05-fips/0";
}

In the FIPS variant, every covered package is compliant with Federal Information Processing Standards (FIPS). Using the FIPS variant has the details.

940 CVEs tracked

Severity
Status
CVEStatusSeveritySummaryFixed
FixedHighRUSTSEC-2026-0245: sevenz-rust path traversal: decompress_impl allows extraction outside target directory via unchecked entry pathsSep 6, 2026
FixedHighRUSTSEC-2026-0195: quick-xml NsReader/NamespaceResolver unbounded heap from many namespace declarations, enabling attacker-triggered OOMSep 6, 2026
FixedHighRUSTSEC-2026-0194: O(N^2) duplicate-attribute check in quick-xml, including NsReader, allows CPU DoSSep 6, 2026
FixedHighRUSTSEC-2026-0189: rmcp Streamable HTTP server pre-1.4.0 missing Host validation allows DNS rebinding attacksSep 6, 2026
FixedHighRUSTSEC-2026-0187: lopdf::Document::load_mem unbounded recursion on nested PDF arrays/dicts; stack overflow DoSSep 6, 2026
FixedHighRUSTSEC-2026-0185: Non-contiguous RecvStream fragments cause Assembler buffer bloat, risking memory exhaustion during ordered readsSep 6, 2026
FixedHighRUSTSEC-2026-0103: thin-vec IntoIter::drop and clear on panic trigger double free/UAF memory corruption via safe RustSep 6, 2026
FixedMediumRUSTSEC-2026-0068: tar-rs <=0.4.44 ignores PAX size override if base size set, mismatching archiversSep 6, 2026
FixedMediumRUSTSEC-2026-0067: tar-rs ≤0.4.44 unpack_dir symlink bug allows chmod of directories outside extraction rootSep 6, 2026
FixedMediumRUSTSEC-2026-0066: astral-tokio-tar <=0.5.6 silently skips malformed PAX extensions, enabling parser differentialSep 6, 2026
FixedHighRUSTSEC-2026-0048: AWS-LC CRL distribution point bug lets revoked certificates bypass checks with partitioned CRLsSep 6, 2026
FixedHighRUSTSEC-2026-0047: AWS-LC PKCS7_verify signature validation flaw enables unauthenticated bypass; affects aws-lc-sys usersSep 6, 2026
FixedHighRUSTSEC-2026-0046: AWS-LC PKCS7_verify improper certificate validation enables chain bypass with multiple signersSep 6, 2026
FixedMediumRUSTSEC-2026-0045: Timing side-channel in AWS-LC EVP AES-CCM decryption leaks tag validitySep 6, 2026
FixedHighRUSTSEC-2026-0041: Invalid LZ4 block decompression leaks uninitialized/prior buffer data due to lz4_flex offset validation bugSep 6, 2026
FixedHighRUSTSEC-2026-0037: Invalid QUIC transport parameters cause panic due to unwrap() in parsing codeSep 6, 2026
FixedMediumRUSTSEC-2026-0009: RFC 2822 parsing vulnerability enables stack-exhaustion DoS with maliciously crafted inputsSep 6, 2026
FixedMediumRUSTSEC-2023-0071: rsa crate timing side-channel leaks private key over network due to non-constant-timeSep 6, 2026
FixedHighRUSTSEC-2021-0041: BigInt exponent parsing in parse_duration::parse leads to CPU/memory exhaustion DoSSep 6, 2026
FixedMediumGHSA-xx64-wwv2-hcqq: astral-tokio-tar <=0.6.0 unpack_in can change permissions of directories outside archiveSep 6, 2026
FixedHighGHSA-xwg4-73v4-xw9w: nanoid size integer overflow corrupts CSPRNG pool; process-wide persistent deterministic 'u' IDsSep 6, 2026
FixedLowGHSA-xwfj-jgwm-7wp5: ANSI escape sequence injection in tracing-subscriber logs can manipulate terminal outputSep 6, 2026
FixedHighGHSA-xvcm-6775-5m9r: Immutable.Map/Set hash collision DoS via crafted keys causing O(n^2) operationsSep 6, 2026
FixedMediumGHSA-xv59-967r-8726: rust-openssl AES wrap_pad updates overflow on non-multiple-of-8 inputs, causing attacker-controlled heap corruptionSep 6, 2026
FixedHighGHSA-xpqw-6gx7-v673: SVGO expands custom XML entities recursively, enabling DoS and Node.js heap out-of-memory.Sep 6, 2026
FixedHighGHSA-xphw-cqx3-667j: thin_vec IntoIter::drop and clear cause double free/UAF when element Drop panicsSep 6, 2026
FixedMediumGHSA-xphf-cx8h-7q9g: Unsafe reference returned into OpenSSL data structure; OpenSSL may mutate behind callers' back.Sep 6, 2026
FixedHighGHSA-xp3w-r5p5-63rr: Unchecked UTF-8 in X509Ref::ocsp_responders causes undefined behavior with non-ASCII IA5String OCSP URLsSep 6, 2026
FixedMediumGHSA-xmgf-hq76-4vx2: Password callback over-read due to *_from_pem_callback length validation bug in pre-3.x OpenSSLSep 6, 2026
FixedLowGHSA-xgp8-3hg3-c2mh: Wildcard DNS names bypass permitted subtree checks in X.509 name constraintsSep 6, 2026
FixedMediumGHSA-xcf7-rvmh-g6q4: Empty string input triggers OpenSSL strlen, causing out-of-bounds memory read until NUL.Sep 6, 2026
FixedMediumGHSA-x5fp-wj9c-mxmx: qs v6.15.3 bracket-key input bypasses arrayLimit when comma=true, enabling memory DoSSep 6, 2026
FixedHighGHSA-x494-mj8g-cj27: gix-pack DoS: unchecked delta indexing panics and uncapped size headers OOM via malicious packsSep 6, 2026
FixedCriticalGHSA-wwq9-3cpr-mm53: Non-canonical Borsh HashMap serialization; order-dependent encoding and missing checks cause consensus splitsSep 6, 2026
FixedCriticalGHSA-wf6x-7x77-mvgw: Immutable.js prototype pollution in merge/mergeDeep/mergeDeepWith and Map.toJS/toObject APIsSep 6, 2026
FixedMediumGHSA-w9m9-85wc-3x92: Uncontrolled recursion in postcss-selector-parser AST toString leads remote DoS (pre-6.1.3/7.1.1)Sep 6, 2026
FixedMediumGHSA-w8wr-v893-vjvp: All-digit PAX path parsed as number crashes node-tar extraction with uncaught TypeErrorSep 6, 2026
FixedCriticalGHSA-w7jw-789q-3m8p: shell-quote quote() fails to escape line terminators in object .op, enabling command injectionSep 6, 2026
FixedHighGHSA-w5hq-g745-h8pq: External buffer out-of-range not rejected in uuid v3/v5/v6; silent partial writes; inconsistent with v4/v1/v7Sep 6, 2026
FixedHighGHSA-w3rx-r6r6-pgpr: image-size ≤2.0.2 DoS: ICNS zero-length entry triggers infinite Node.js event loopSep 6, 2026
FixedMediumGHSA-w2qp-rph6-63g4: Root primitive body coercion mismatch exposes uncoerced value to handlers in Fastify <5.12.1Sep 6, 2026
FixedHighGHSA-vxpw-j846-p89q: undici WebSocket client allows unbounded message fragments, causing memory exhaustion denial-of-serviceSep 6, 2026
FixedHighGHSA-vw5v-4f2q-w9xf: aws-lc-sys PKCS7_verify certificate chain verification bypass with multiple signers (v0.24.0–0.37.x)Sep 6, 2026
FixedHighGHSA-vvp9-7p8x-rfvv: Invalid offset handling in lz4_flex block decompression leaks uninitialized/previous buffer dataSep 6, 2026
FixedHighGHSA-vmh5-mc38-953g: Undici SOCKS5 ProxyAgent drops requestTls, bypassing custom TLS options and CA pinningSep 6, 2026
FixedMediumGHSA-vmf3-w455-68vh: node-tar PAX size misapplied to L/K/x headers causes parsing desync, hidden filesSep 6, 2026
FixedMediumGHSA-vfvv-c25p-m7mm: rkyv InlineVec and SerVec clear() not panic-safe, enabling double free/use-after-free vulnerabilitiesSep 6, 2026
FixedMediumGHSA-v6wh-96g9-6wx3: launch-editor allows UNC paths, triggering Windows NTLM auth and leaking NTLMv2 hashesSep 6, 2026
FixedHighGHSA-v5mp-jgw5-2x6j: toml.parse Object.prototype pollution via scalar __proto__ traversal and path-tracking desyncSep 6, 2026
FixedHighGHSA-v56q-mh7h-f735: Immutable.js List index >=2^30 triggers uncatchable loop or OOM abort; setSize wrapsSep 6, 2026

Make CVE remediation our job, not yours.

Tell us what you run. We'll show you what Determinate Secure Packages covers, how the SLA applies, and how to get started.

Contact sales

Provide us with some basic details and we'll follow up with you about , usually within one business day.

We'll only use this to get back to you. See our privacy policy (opens in a new tab). This site is protected by reCAPTCHA and the Google Privacy Policy (opens in a new tab) and Terms of Service (opens in a new tab) apply.