Updated 02:00
Determinate Secure Packages distribution
secure-packages-26.05SupportedAvailable for use in production environments and covered by our standard service-level agreement (SLA).FIPS supportedA FIPS distribution is available for environments that require cryptography compliant with Federal Information Processing Standards.Until November 2029Covered until November 2029. Until then, every CVE in it gets a fix within our service-level agreement (SLA): 7 days for critical, 15 for high, 45 for medium, and 90 for low.
Built on Nixpkgs 26.05. Available for use in production environments and covered by our standard service-level agreement (SLA).
Fixed within SLA
479
last 30 days
Fixed within SLA
18
last 7 days
Open
27
not yet fixed but still within SLA
Overdue
0
open
Missed SLA
0
last 30 days
Use this distribution
Customers onlyDeterminate Secure Packages is available through FlakeHub to organizations with access. Not a customer yet? Get in touch to gain access or schedule a demo.
Email sales@determinate.systemsStandardflake.nix
{
inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-26.05/0";
}FIPS variant
FIPS variantflake.nix
{
inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-26.05-fips/0";
}In the FIPS variant, every covered package is compliant with Federal Information Processing Standards (FIPS). Using the FIPS variant has the details.
506 CVEs tracked
| CVE | Status | Severity | Summary | Clock started | Deadline | Fixed | Time to fix |
|---|---|---|---|---|---|---|---|
| Fixed within SLA | Medium | Chrome iOS <151.0.7922.72 SOP bypass via crafted HTML requiring specific user gestures | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome iOS race allows remote UI spoofing via crafted HTML before 151.0.7922.72 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Google Chrome Passwords UI flaw enables domain spoofing via crafted HTML (pre-151.0.7922.72) | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | UI spoofing vulnerability in Chrome for iOS before 151.0.7922.72 via crafted HTML | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome iOS pre-151.0.7922.72 incorrect security UI enables domain spoofing via crafted HTML | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Critical | Chrome DevTools untrusted input validation flaw enables sandbox escape via crafted HTML (pre-151.0.7922.72) | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Chrome <151.0.7922.72 V8 use-after-free enables sandboxed remote code execution via crafted HTML | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome for iOS <151.0.7922.72 allows remote UI spoofing via crafted HTML | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Critical | Chrome Passwords validation flaw enables sandbox escape from compromised renderer via crafted HTML (pre-151.0.7922.72) | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Google Chrome Passwords pre-151.0.7922.72 cross-origin data leak via crafted HTML | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Critical | Use-after-free in ANGLE allows sandbox escape in Google Chrome pre-151.0.7922.72 via crafted HTML | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Insufficient validation of untrusted input in Chrome Passwords allows UI spoofing by compromised renderer | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome for iOS <151.0.7922.72 navigation restriction bypass via crafted HTML by remote attacker | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome Passwords vulnerability pre-151.0.7922.72 leaks cross-origin data via crafted HTML | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Google Chrome for iOS <151.0.7922.72 allows UI spoofing via crafted HTML | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome CSS bug before 151.0.7922.72 enables UXSS via crafted HTML page | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Low | Chrome for iOS <151.0.7922.72 cross-origin data leak via crafted HTML and UI gestures Medium severity | Aug 4, 2026 | Nov 2, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome Android <151.0.7922.72 Passwords policy bug allows discretionary access control bypass via crafted HTML | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Insufficient ServiceWorker policy enforcement enabled same-origin policy bypass in Google Chrome pre-151.0.7922.72 via crafted HTML | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome <151.0.7922.72 WebXR policy enforcement flaw enables same-origin policy bypass | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome iOS race condition allows remote UI spoofing via crafted HTML pre-151.0.7922.72 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome before 151.0.7922.72 extension policy flaw enables bypass of navigation restrictions | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome pre-151.0.7922.72 Autofill policy flaw leaked cross-origin data via crafted pages | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Google Chrome <151.0.7922.72 WebAppInstalls vulnerability allows remote UI spoofing via crafted HTML | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Remote UXSS via crafted HTML in Chrome <151.0.7922.72 Network component | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Pre-151.0.7922.72 Chrome ReportingAndNEL cross-origin data leak via crafted HTML page | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Android Chrome Speech policy enforcement bug enables compromised renderer privilege escalation via crafted HTML | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome GuestView insufficient policy enforcement enables cross-origin data leak pre-151.0.7922.72 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | iOS Chrome input validation flaw bypasses navigation restrictions via crafted HTML, pre-151.0.7922.72 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Policy enforcement flaw allows navigation bypass in Chrome for iOS <151.0.7922.72 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome <151.0.7922.72 DigitalCredentials flaw enables remote UI spoofing via crafted HTML page | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Use-after-free in Chrome ANGLE on Windows allows sandbox escape via crafted HTML (pre-151.0.7922.72) | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome Dawn uninitialized use leaks cross-origin data via crafted HTML, pre-151.0.7922.72 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome Extensions input validation bug enables sandbox escape via crafted HTML after renderer compromise (<151.0.7922.72) | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | WebGL uninitialized use leaks cross-origin data in Chrome Android before 151.0.7922.72 via crafted HTML | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Chrome V8 use-after-free enables sandboxed RCE via crafted HTML before 151.0.7922.72 | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Google Chrome Extensions pre-151.0.7922.72 input validation flaw enables renderer sandbox escape | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Insufficient Glic policy enforcement in Chrome Android <151.0.7922.72 allows remote navigation bypass via HTML | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Critical | Use-after-free in Chrome Media enables sandbox escape via crafted HTML (pre-151.0.7922.72) | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Critical | Chrome pre-151 Save to Drive input validation bug enabling renderer sandbox escape via crafted PDF | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Critical | ANGLE out-of-bounds read/write allows remote attacker sandbox escape via crafted HTML in Chrome <151.0.7922.72 | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Pre-151.0.7922.72 Chrome MediaRecording bug leaks process memory via crafted HTML | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome Safe Browsing input validation bug pre-151.0.7922.72 enables DAC bypass via malicious file | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Google Chrome WebXR side-channel leak exposes process memory via crafted HTML (pre-151.0.7922.72) | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Insufficient input validation enables Chrome Android pre-151.0.7922.72 Omnibox spoofing via crafted HTML after renderer compromise | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Remote UI spoofing via crafted HTML in Chrome Android Messages pre-151.0.7922.72 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome Windows ANGLE uninitialized use leaks process memory via crafted HTML pre-151.0.7922.72 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome prior to 151.0.7922.72 extension flaw allows malicious extensions to leak cross-origin data | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Use-after-free in Chrome Extensions pre-151.0.7922.72 enables sandboxed arbitrary code execution | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Low | Android Chrome Clipboard validation flaw prior to 151.0.7922.72 leaks cross-origin data locally | Aug 4, 2026 | Nov 2, 2026 | Aug 4, 2026 | same day |
Make CVE remediation our job, not yours.
Tell us what you run. We'll show you what Determinate Secure Packages covers, how the SLA applies, and how to get started.