Updated 01:00
Determinate Secure Packages distribution
secure-packages-26.05SupportedAvailable for use in production environments and covered by our standard service-level agreement (SLA).FIPS supportedA FIPS distribution is available for environments that require cryptography compliant with Federal Information Processing Standards.Until November 2029Covered until November 2029. Until then, every CVE in it gets a fix within our service-level agreement (SLA): 7 days for critical, 15 for high, 45 for medium, and 90 for low.
Built on Nixpkgs 26.05. Available for use in production environments and covered by our standard service-level agreement (SLA).
Fixed within SLA
479
last 30 days
Fixed within SLA
18
last 7 days
Open
27
not yet fixed but still within SLA
Overdue
0
open
Missed SLA
0
last 30 days
Use this distribution
Customers onlyDeterminate Secure Packages is available through FlakeHub to organizations with access. Not a customer yet? Get in touch to gain access or schedule a demo.
Email sales@determinate.systemsStandardflake.nix
{
inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-26.05/0";
}FIPS variant
FIPS variantflake.nix
{
inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-26.05-fips/0";
}In the FIPS variant, every covered package is compliant with Federal Information Processing Standards (FIPS). Using the FIPS variant has the details.
506 CVEs tracked
| CVE | Status | Severity | Summary | Clock started | Deadline | Fixed | Time to fix |
|---|---|---|---|---|---|---|---|
| Fixed within SLA | Medium | Insufficient input validation in Chrome Mac Updater allows sandbox escape from compromised renderer | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | WebXR vulnerability leaks Chrome process memory via crafted HTML (pre-151.0.7922.72) | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | <151.0.7922.72 Chrome Android ANGLE use-after-free allows sandbox escape via crafted HTML | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome DevTools insufficient input validation enables sandbox escape via crafted HTML from compromised renderer | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | WebXR uninitialized use in Chrome <151.0.7922.72 leaks cross-origin data via HTML | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Chrome pre-151.0.7922.72 WebUI input validation flaw enables sandbox escape via malicious network traffic | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Chrome <151.0.7922.72 TabStrip use-after-free enables heap corruption via crafted HTML and UI gestures | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Use-after-free in Chrome Enterprise pre-151.0.7922.72 enables remote heap corruption via HTML | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome Paint cross-origin data leak via crafted HTML before 151.0.7922.72 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Chrome WebRTC lifecycle bug pre-151.0.7922.72 allows remote heap corruption via crafted HTML | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Remote attacker could bypass same-origin policy in Headless Chrome <151.0.7922.72 via crafted HTML | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome <151.0.7922.72 extension policy flaw allows site isolation bypass via malicious extension | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | WebXR integer overflow in Chrome <151.0.7922.72 enables sandboxed remote code execution via crafted HTML page | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome Autofill cross-origin data leak via crafted HTML page prior to 151.0.7922.72 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome Autofill cross-origin data leak via crafted HTML (pre-151.0.7922.72) | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome <151.0.7922.72 CSS bug enables UXSS via crafted HTML page | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Pre-151.0.7922.72 Chrome Payments bug leaks cross-origin data via crafted HTML | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | PDFium use-after-free enables sandboxed RCE via crafted PDF in Chrome <151.0.7922.72 | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome for iOS before 151.0.7922.72 allows UI spoofing via crafted HTML | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | iOS Chrome <151.0.7922.72: insufficient policy enforcement enables HTML-based discretionary access control bypass | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Cryptographic flaw in WebAppInstalls allows local sandbox escape via crafted HTML in Android Chrome pre-151.0.7922.72 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Pre-151.0.7922.72 Chrome Passwords cross-origin data leak via crafted page, UI gestures | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome Cast pre-151.0.7922.72 insufficient input validation leaks cross-origin data on LAN | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Chrome <151.0.7922.72 WebXR out-of-bounds read enables remote memory disclosure | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Chrome USB policy enforcement bug (<151.0.7922.72) allows remote privilege escalation via crafted HTML | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Insufficient input validation in Chrome Dawn allows remote sandbox escape via crafted HTML page | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Type confusion in Tab allows sandbox escape post-renderer compromise in Chrome Android <151.0.7922.72 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Critical | Google Chrome Mac Crypto bug allows sandbox escape from compromised renderer via crafted HTML pre-151.0.7922.72 | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Chrome Mac Updater pre-151.0.7922.72 local OS-level privilege escalation via malicious file | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Chrome Windows pre-151.0.7922.72: Local privilege escalation via malicious file | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Chrome Windows Tracing use-after-free allows local privilege escalation via malicious file (pre-151.0.7922.72) | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Insufficient input validation in Chrome Updater allows local privilege escalation via malicious file (pre-151.0.7922.72) | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Low | Android Chrome <151.0.7922.72: Omnibox spoofing via malicious local file; insufficient input validation | Aug 4, 2026 | Nov 2, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Google Chrome <151.0.7922.72 favicon implementation leaks cross-origin data via crafted HTML page | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome WebNN uninitialized use on Windows <151.0.7922.72 leaks cross-origin data via crafted HTML | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome Network cross-origin data leak via crafted HTML before 151.0.7922.72 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Critical | Chrome Mac pre-151.0.7922.72 network flaw enables sandbox escape via crafted HTML after renderer compromise | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Critical | DevTools race on Mac Chrome pre-151.0.7922.72 enables sandbox escape from compromised renderer | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome <151.0.7922.72 WebMCP policy flaw enables remote same-origin policy bypass via crafted HTML | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome <151.0.7922.72 DevTools: compromised renderer injects script/HTML into privileged pages | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome Media Router pre-151.0.7922.72 Same-Origin Policy bypass via crafted HTML by remote attacker | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Pre-151.0.7922.72 Chrome Autofill side-channel leak enables cross-origin exfiltration via compromised renderer | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome Permissions bug pre-151.0.7922.72 enables same-origin policy bypass via crafted HTML | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome iOS <151.0.7922.72 Omnibox spoofing via malicious network traffic | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Critical | Integer overflow in Google Chrome Codecs enables remote sandbox escape via crafted video pre-151.0.7922.72 | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Critical | ANGLE input validation flaw allows sandbox escape via crafted HTML in Chrome <151.0.7922.72 | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome Windows Media bug pre-151.0.7922.72 allows compromised renderer to bypass same-origin policy via crafted HTML | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome <151.0.7922.72 CSS UXSS allows remote script/HTML injection via crafted page | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Pre-151.0.7922.72 Chrome Cast input validation allowed local attacker to leak cross-origin data | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome CSS flaw before 151.0.7922.72 leaks cross-origin data via crafted HTML | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day |
Make CVE remediation our job, not yours.
Tell us what you run. We'll show you what Determinate Secure Packages covers, how the SLA applies, and how to get started.