Updated 00:01
Determinate Secure Packages distribution
secure-packages-26.05SupportedAvailable for use in production environments and covered by our standard service-level agreement (SLA).FIPS supportedA FIPS distribution is available for environments that require cryptography compliant with Federal Information Processing Standards.Until November 2029Covered until November 2029. Until then, every CVE in it gets a fix within our service-level agreement (SLA): 7 days for critical, 15 for high, 45 for medium, and 90 for low.
Built on Nixpkgs 26.05. Available for use in production environments and covered by our standard service-level agreement (SLA).
Fixed within SLA
479
last 30 days
Fixed within SLA
18
last 7 days
Open
27
not yet fixed but still within SLA
Overdue
0
open
Missed SLA
0
last 30 days
Use this distribution
Customers onlyDeterminate Secure Packages is available through FlakeHub to organizations with access. Not a customer yet? Get in touch to gain access or schedule a demo.
Email sales@determinate.systemsStandardflake.nix
{
inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-26.05/0";
}FIPS variant
FIPS variantflake.nix
{
inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-26.05-fips/0";
}In the FIPS variant, every covered package is compliant with Federal Information Processing Standards (FIPS). Using the FIPS variant has the details.
506 CVEs tracked
| CVE | Status | Severity | Summary | Clock started | Deadline | Fixed | Time to fix |
|---|---|---|---|---|---|---|---|
| Fixed within SLA | Medium | Chrome <151.0.7922.72 Dawn uninitialized use leaks process memory via crafted HTML when renderer compromised | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Insufficient Navigation input validation in Chrome <151.0.7922.72 allows UI spoofing post-renderer compromise | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome for iOS <151.0.7922.72 allows navigation restriction bypass via crafted HTML | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Google Chrome <151.0.7922.72 parser flaw allows CSP bypass via crafted HTML page | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Cross-origin data leak via SVG side-channel in Google Chrome before 151.0.7922.72 using crafted HTML | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Omnibox URL spoofing in Chrome for iOS before 151.0.7922.72 via crafted HTML | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Critical | Chrome Android PiP input validation bug enables sandbox escape post-renderer compromise via crafted HTML | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Insufficient untrusted input validation in Chrome Passwords enables UI spoofing via network traffic (pre-151.0.7922.72) | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome Android pre-151.0.7922.72 FullScreen flaw enables remote UI spoofing via crafted HTML | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome DevTools vulnerability before 151.0.7922.72 enables bypass of navigation restrictions via crafted HTML with gestures | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Heap buffer overflow in Chrome Codecs enables sandboxed RCE via crafted HTML (pre-151.0.7922.72) | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome DevTools insufficient validation of untrusted input enabled navigation restriction bypass via crafted HTML pre-151.0.7922.72 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome DOMStorage vulnerability allowed remote cross-origin data leak via crafted HTML page pre-151.0.7922.72 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome Windows DataTransfer use-after-free leaks process memory via crafted HTML pre-151.0.7922.72 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome DevTools navigation restriction bypass via crafted HTML page (pre-151.0.7922.72) | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Pre-151.0.7922.72 Chrome Extensions untrusted input validation flaw allows renderer privilege escalation via HTML | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Pre-151.0.7922.72 Chrome DevTools insufficient input validation lets remote attackers bypass navigation via malicious file | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome <151.0.7922.72 DataTransfer bug leaks cross-origin data via crafted HTML | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome DevTools insufficient policy enforcement pre-151.0.7922.72 enables cross-origin data leak via malicious extension | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome DevTools insufficient input validation enables navigation bypass via crafted HTML and user gestures | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome Android Cast before 151.0.7922.72 allows same-origin policy bypass via crafted HTML | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Critical | Chrome pre-151.0.7922.72 DNS use-after-free enables sandbox escape from compromised renderer via HTML | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Google Chrome Enterprise pre-151.0.7922.72 policy flaw lets remote attackers bypass navigation restrictions via crafted domains | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Chrome Enterprise <151.0.7922.72 inappropriate implementation enables remote code execution via crafted HTML | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome pre-151.0.7922.72 navigation input validation flaw enables renderer-based navigation restriction bypass | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Chrome V8 use-after-free enables sandboxed code execution via malicious extension pre-151.0.7922.72 | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome Mac pre-151.0.7922.72 Enterprise policy enforcement flaw allows local privilege escalation with physical access | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Use-after-free in Chrome Sync allows sandboxed code execution via crafted HTML pre-151.0.7922.72 | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | iOS Chrome pre-151.0.7922.72 policy enforcement flaw lets remote bypass DAC via crafted HTML | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Insufficient Settings policy enforcement allows compromised renderer privilege escalation in Chrome <151.0.7922.72 via crafted HTML. | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Android Chrome WebView UI spoofing vulnerability before 151.0.7922.72 via crafted HTML | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Skia side-channel leak in Chrome exposes process memory via crafted HTML (pre-151.0.7922.72) | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Remote attacker bypasses navigation restrictions in iOS Chrome pre-151.0.7922.72 via crafted HTML | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Insufficient SVG policy enforcement in Google Chrome <151.0.7922.72 enables cross-origin data leak via crafted HTML | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Android Chrome NFC policy enforcement flaw allows remote cross-origin data leak pre-151.0.7922.72 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Insufficient untrusted input validation in Chrome Isolated Web Apps allows cross-origin data leak via network | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Pre-151.0.7922.72 Windows Chrome Printing input validation bug allows sandbox escape via crafted HTML post-renderer compromise | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome pre-151.0.7922.72 Network component side-channel leaks cross-origin data via crafted HTML | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Google Chrome <151.0.7922.72 Bluetooth input validation bug allows renderer sandbox escape via HTML | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome SurfaceCapture bug before 151.0.7922.72 lets remote attacker leak cross-origin data via crafted HTML | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Android Chrome <151.0.7922.72 NFC policy flaw leaks cross-origin data via crafted HTML | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chromecast in Chrome pre-151.0.7922.72 allows LAN script/HTML injection into privileged page | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Low | Chrome Linux Editing component leaks cross-origin data via crafted HTML prior to 151.0.7922.72 | Aug 4, 2026 | Nov 2, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome Android Sharing input validation flaw pre-151.0.7922.72 enables remote navigation bypass | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Remote cross-origin data leak in Chrome Enterprise Windows <151.0.7922.72 via malicious file | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Insufficient DevTools policy enforcement enables Chrome extension privilege escalation before 151.0.7922.72 | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Chrome DevTools use-after-free enables sandboxed code execution via malicious extension pre-151.0.7922.72 | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Inappropriate ORB implementation in Chrome pre-151.0.7922.72 leaks cross-origin data via crafted HTML | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Use-after-free in Chrome DevTools allows sandboxed RCE via crafted HTML (pre-151.0.7922.72) | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome pre-151.0.7922.72 DataTransfer flaw leaks cross-origin data via crafted page/UI gestures | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day |
Make CVE remediation our job, not yours.
Tell us what you run. We'll show you what Determinate Secure Packages covers, how the SLA applies, and how to get started.