Updated 22:00
Determinate Secure Packages distribution
secure-packages-26.05SupportedAvailable for use in production environments and covered by our standard service-level agreement (SLA).FIPS supportedA FIPS distribution is available for environments that require cryptography compliant with Federal Information Processing Standards.Until November 2029Covered until November 2029. Until then, every CVE in it gets a fix within our service-level agreement (SLA): 7 days for critical, 15 for high, 45 for medium, and 90 for low.
Built on Nixpkgs 26.05. Available for use in production environments and covered by our standard service-level agreement (SLA).
Fixed within SLA
479
last 30 days
Fixed within SLA
18
last 7 days
Open
27
not yet fixed but still within SLA
Overdue
0
open
Missed SLA
0
last 30 days
Use this distribution
Customers onlyDeterminate Secure Packages is available through FlakeHub to organizations with access. Not a customer yet? Get in touch to gain access or schedule a demo.
Email sales@determinate.systemsStandardflake.nix
{
inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-26.05/0";
}FIPS variant
FIPS variantflake.nix
{
inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-26.05-fips/0";
}In the FIPS variant, every covered package is compliant with Federal Information Processing Standards (FIPS). Using the FIPS variant has the details.
506 CVEs tracked
| CVE | Status | Severity | Summary | Clock started | Deadline | Fixed | Time to fix |
|---|---|---|---|---|---|---|---|
| Fixed within SLA | High | Use-after-free in Chrome Payments enables sandbox escape via crafted HTML (pre-151.0.7922.109) | Aug 11, 2026 | Aug 26, 2026 | Aug 11, 2026 | same day | |
| Fixed within SLA | High | Skia use-after-free in Chrome for Android pre-151.0.7922.109 enables sandbox escape via crafted HTML | Aug 11, 2026 | Aug 26, 2026 | Aug 11, 2026 | same day | |
| Fixed within SLA | High | Google Chrome Workers input validation flaw allows site isolation bypass before 151.0.7922.109 | Aug 11, 2026 | Aug 26, 2026 | Aug 11, 2026 | same day | |
| Fixed within SLA | High | Chrome <151.0.7922.109 Navigation policy flaw allows renderer sandbox escape via crafted HTML | Aug 11, 2026 | Aug 26, 2026 | Aug 11, 2026 | same day | |
| Fixed within SLA | High | Chrome V8 use-after-free enables sandboxed RCE via crafted HTML pre-151.0.7922.109 | Aug 11, 2026 | Aug 26, 2026 | Aug 11, 2026 | same day | |
| Fixed within SLA | High | V8 inappropriate implementation allows remote sandboxed RCE via crafted HTML in Chrome <151.0.7922.109 | Aug 11, 2026 | Aug 26, 2026 | Aug 11, 2026 | same day | |
| Fixed within SLA | Critical | Critical use-after-free in Google Chrome Aura on Linux <151.0.7922.109 enables remote sandbox escape | Aug 11, 2026 | Aug 18, 2026 | Aug 11, 2026 | same day | |
| Fixed within SLA | High | Chrome Linux GPU out-of-bounds write allows sandbox escape via crafted HTML pre-151.0.7922.109 High severity | Aug 11, 2026 | Aug 26, 2026 | Aug 11, 2026 | same day | |
| Fixed within SLA | Medium | Chrome Android <151.0.7922.109 GPU uninitialized use leaks memory via crafted HTML | Aug 11, 2026 | Sep 25, 2026 | Aug 11, 2026 | same day | |
| Fixed within SLA | High | Chrome Translate use-after-free enables sandbox RCE via crafted HTML (pre-151.0.7922.109) | Aug 11, 2026 | Aug 26, 2026 | Aug 11, 2026 | same day | |
| Fixed within SLA | High | Android Chrome <151 WebAPKs: input validation flaw enables local sandbox escape via malicious file | Aug 11, 2026 | Aug 26, 2026 | Aug 11, 2026 | same day | |
| Fixed within SLA | High | Chrome Android <151.0.7922.109 use-after-free in Resources enables sandbox escape via crafted HTML | Aug 11, 2026 | Aug 26, 2026 | Aug 11, 2026 | same day | |
| Fixed within SLA | High | Chrome <151.0.7922.109 GPU use-after-free enables sandbox escape via crafted HTML | Aug 11, 2026 | Aug 26, 2026 | Aug 11, 2026 | same day | |
| Fixed within SLA | High | Race in Chrome Windows CredentialProvider pre-151.0.7922.109 enables local privilege escalation via malicious file | Aug 11, 2026 | Aug 26, 2026 | Aug 11, 2026 | same day | |
| Fixed within SLA | High | Chrome pre-151.0.7922.109 CrashReporting heap overflow allows sandbox escape from compromised renderer | Aug 11, 2026 | Aug 26, 2026 | Aug 11, 2026 | same day | |
| Fixed within SLA | High | Critical Chrome Android WebGL use-after-free enables sandbox escape after renderer compromise (pre-151.0.7922.109) | Aug 11, 2026 | Aug 26, 2026 | Aug 11, 2026 | same day | |
| Fixed within SLA | Medium | Windows Chrome Updater vulnerability enables local UI spoofing via malicious file (pre-151.0.7922.72) | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Critical | Pre-151.0.7922.72 Chrome for Mac Tint flaw enabled remote sandbox escape via HTML | Aug 5, 2026 | Aug 12, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | DevTools input validation flaw allowed remote attacker to bypass navigation via crafted HTML before 151.0.7922.72 | Aug 4, 2026 | Sep 18, 2026 | Aug 11, 2026 | 7 days | |
| Fixed within SLA | High | Chrome Linux Views use-after-free allows remote heap corruption via crafted HTML, prior to 151.0.7922.72 | Aug 5, 2026 | Aug 20, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Chrome Android GPU side-channel leaks cross-origin data via crafted HTML page pre-151.0.7922.72 | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Chrome Cast pre-151.0.7922.72 allows remote cross-origin data leak via crafted HTML | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Chrome pre-151.0.7922.72 CSS implementation enables UXSS script/HTML injection via crafted page | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | GetUserMedia flaw leaks cross-origin data via crafted page after renderer compromise in Chrome <151.0.7922.72 | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Credential Management UI spoofing via crafted HTML in Chrome prior to 151.0.7922.72 | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Insufficient input validation in Chrome Payments pre-151.0.7922.72 enables UI spoofing from compromised renderer | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Chrome iOS pre-151.0.7922.72: Untrusted input validation flaw enables remote navigation restrictions bypass | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Blink cross-origin data leak via crafted HTML in Chrome before 151.0.7922.72 | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Chrome DevTools SOP bypass via crafted HTML before 151.0.7922.72; remote attacker, Medium | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | High | Insufficient DevTools input validation in Chrome allows privilege escalation via crafted extension (<151.0.7922.72) | Aug 5, 2026 | Aug 20, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | ANGLE uninitialized use in Chrome <151.0.7922.72 enables cross-origin data leak via crafted HTML page | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | High | Chrome Mac Audio use-after-free enables sandbox escape pre-151.0.7922.72 via crafted HTML | Aug 5, 2026 | Aug 20, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Pre-151.0.7922.72 Chrome Loader leaks cross-origin data via crafted HTML | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Chrome iOS prior to 151.0.7922.72 Omnibox spoofing via crafted HTML (incorrect security UI) | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Chrome Isolated Web Apps allowed remote bypass of navigation restrictions via crafted HTML pre-151.0.7922.72 | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Google Chrome Site Isolation bypass before 151.0.7922.72 via crafted HTML page | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Chrome Autofill flaw pre-151.0.7922.72 enables remote cross-origin data leak via crafted HTML | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Receiver policy bypass in Chrome pre-151.0.7922.72 enables sandbox escape from compromised renderer via crafted HTML | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | PresentationAPI in Chrome <151.0.7922.72 leaked cross-origin data via crafted HTML page | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | High | Insufficient input validation in Chrome Variations pre-151.0.7922.72 allows heap corruption by privileged network attacker | Aug 5, 2026 | Aug 20, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Google Chrome Cast input validation flaw leaks cross-origin data via crafted HTML | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | WebGL out-of-bounds read in Chrome pre-151.0.7922.72 allows remote memory disclosure | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Skia uninitialized use in Chrome <151.0.7922.72 leaks cross-origin data via crafted HTML | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Chrome Mac Media out-of-bounds read allows sandbox escape after renderer compromise pre-151.0.7922.72 | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Insufficient untrusted input validation in Chrome Cast enables cross-origin data leak via crafted HTML (pre-151.0.7922.72) | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Critical | WebSockets input validation flaw enables sandbox escape from compromised renderer in Chrome <151.0.7922.72 | Aug 5, 2026 | Aug 12, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Android Chrome WebView untrusted input validation flaw leaks cross-origin data via compromised renderer pre-151.0.7922.72 | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | FedCM SOP bypass in Chrome prior to 151.0.7922.72 via crafted HTML page | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Chrome for iOS <151.0.7922.72 cross-origin data leak via crafted HTML page | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Chrome iOS <151.0.7922.72 UXSS from insufficient validation of untrusted network input | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days |
Make CVE remediation our job, not yours.
Tell us what you run. We'll show you what Determinate Secure Packages covers, how the SLA applies, and how to get started.