Skip to content
All distributions

Updated 00:01

Determinate Secure Packages distribution

secure-packages-26.05SupportedFIPS supportedUntil November 2029

Built on Nixpkgs 26.05. Available for use in production environments and covered by our standard service-level agreement (SLA).

Fixed within SLA

479

last 30 days

Fixed within SLA

18

last 7 days

Open

27

not yet fixed but still within SLA

Overdue

0

open

Missed SLA

0

last 30 days

Determinate Secure Packages is available through FlakeHub to organizations with access. Not a customer yet? Get in touch to gain access or schedule a demo.

Email sales@determinate.systems

Standardflake.nix

{
  inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-26.05/0";
}
FIPS variant

FIPS variantflake.nix

{
  inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-26.05-fips/0";
}

In the FIPS variant, every covered package is compliant with Federal Information Processing Standards (FIPS). Using the FIPS variant has the details.

506 CVEs tracked

CVEStatusSeveritySummaryClock startedDeadlineFixedTime to fix
Fixed within SLAMediumChrome <151.0.7922.72 Dawn uninitialized use leaks process memory via crafted HTML when renderer compromisedAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumInsufficient Navigation input validation in Chrome <151.0.7922.72 allows UI spoofing post-renderer compromiseAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome for iOS <151.0.7922.72 allows navigation restriction bypass via crafted HTMLAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumGoogle Chrome <151.0.7922.72 parser flaw allows CSP bypass via crafted HTML pageAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumCross-origin data leak via SVG side-channel in Google Chrome before 151.0.7922.72 using crafted HTMLAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumOmnibox URL spoofing in Chrome for iOS before 151.0.7922.72 via crafted HTMLAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLACriticalChrome Android PiP input validation bug enables sandbox escape post-renderer compromise via crafted HTMLAug 4, 2026Aug 11, 2026Aug 4, 2026same day
Fixed within SLAMediumInsufficient untrusted input validation in Chrome Passwords enables UI spoofing via network traffic (pre-151.0.7922.72)Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome Android pre-151.0.7922.72 FullScreen flaw enables remote UI spoofing via crafted HTMLAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome DevTools vulnerability before 151.0.7922.72 enables bypass of navigation restrictions via crafted HTML with gesturesAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAHighHeap buffer overflow in Chrome Codecs enables sandboxed RCE via crafted HTML (pre-151.0.7922.72)Aug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome DevTools insufficient validation of untrusted input enabled navigation restriction bypass via crafted HTML pre-151.0.7922.72Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome DOMStorage vulnerability allowed remote cross-origin data leak via crafted HTML page pre-151.0.7922.72Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome Windows DataTransfer use-after-free leaks process memory via crafted HTML pre-151.0.7922.72Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome DevTools navigation restriction bypass via crafted HTML page (pre-151.0.7922.72)Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAHighPre-151.0.7922.72 Chrome Extensions untrusted input validation flaw allows renderer privilege escalation via HTMLAug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLAMediumPre-151.0.7922.72 Chrome DevTools insufficient input validation lets remote attackers bypass navigation via malicious fileAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome <151.0.7922.72 DataTransfer bug leaks cross-origin data via crafted HTMLAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome DevTools insufficient policy enforcement pre-151.0.7922.72 enables cross-origin data leak via malicious extensionAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome DevTools insufficient input validation enables navigation bypass via crafted HTML and user gesturesAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome Android Cast before 151.0.7922.72 allows same-origin policy bypass via crafted HTMLAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLACriticalChrome pre-151.0.7922.72 DNS use-after-free enables sandbox escape from compromised renderer via HTMLAug 4, 2026Aug 11, 2026Aug 4, 2026same day
Fixed within SLAMediumGoogle Chrome Enterprise pre-151.0.7922.72 policy flaw lets remote attackers bypass navigation restrictions via crafted domainsAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAHighChrome Enterprise <151.0.7922.72 inappropriate implementation enables remote code execution via crafted HTMLAug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome pre-151.0.7922.72 navigation input validation flaw enables renderer-based navigation restriction bypassAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAHighChrome V8 use-after-free enables sandboxed code execution via malicious extension pre-151.0.7922.72Aug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome Mac pre-151.0.7922.72 Enterprise policy enforcement flaw allows local privilege escalation with physical accessAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAHighUse-after-free in Chrome Sync allows sandboxed code execution via crafted HTML pre-151.0.7922.72Aug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLAMediumiOS Chrome pre-151.0.7922.72 policy enforcement flaw lets remote bypass DAC via crafted HTMLAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAHighInsufficient Settings policy enforcement allows compromised renderer privilege escalation in Chrome <151.0.7922.72 via crafted HTML.Aug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLAMediumAndroid Chrome WebView UI spoofing vulnerability before 151.0.7922.72 via crafted HTMLAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumSkia side-channel leak in Chrome exposes process memory via crafted HTML (pre-151.0.7922.72)Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumRemote attacker bypasses navigation restrictions in iOS Chrome pre-151.0.7922.72 via crafted HTMLAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumInsufficient SVG policy enforcement in Google Chrome <151.0.7922.72 enables cross-origin data leak via crafted HTMLAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumAndroid Chrome NFC policy enforcement flaw allows remote cross-origin data leak pre-151.0.7922.72Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumInsufficient untrusted input validation in Chrome Isolated Web Apps allows cross-origin data leak via networkAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumPre-151.0.7922.72 Windows Chrome Printing input validation bug allows sandbox escape via crafted HTML post-renderer compromiseAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome pre-151.0.7922.72 Network component side-channel leaks cross-origin data via crafted HTMLAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumGoogle Chrome <151.0.7922.72 Bluetooth input validation bug allows renderer sandbox escape via HTMLAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome SurfaceCapture bug before 151.0.7922.72 lets remote attacker leak cross-origin data via crafted HTMLAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumAndroid Chrome <151.0.7922.72 NFC policy flaw leaks cross-origin data via crafted HTMLAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumChromecast in Chrome pre-151.0.7922.72 allows LAN script/HTML injection into privileged pageAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLALowChrome Linux Editing component leaks cross-origin data via crafted HTML prior to 151.0.7922.72Aug 4, 2026Nov 2, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome Android Sharing input validation flaw pre-151.0.7922.72 enables remote navigation bypassAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumRemote cross-origin data leak in Chrome Enterprise Windows <151.0.7922.72 via malicious fileAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAHighInsufficient DevTools policy enforcement enables Chrome extension privilege escalation before 151.0.7922.72Aug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLAHighChrome DevTools use-after-free enables sandboxed code execution via malicious extension pre-151.0.7922.72Aug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLAMediumInappropriate ORB implementation in Chrome pre-151.0.7922.72 leaks cross-origin data via crafted HTMLAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAHighUse-after-free in Chrome DevTools allows sandboxed RCE via crafted HTML (pre-151.0.7922.72)Aug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome pre-151.0.7922.72 DataTransfer flaw leaks cross-origin data via crafted page/UI gesturesAug 4, 2026Sep 18, 2026Aug 4, 2026same day

Make CVE remediation our job, not yours.

Tell us what you run. We'll show you what Determinate Secure Packages covers, how the SLA applies, and how to get started.

Email sales@determinate.systems