Updated 03:00
Determinate Secure Packages distribution
secure-packages-26.05SupportedAvailable for use in production environments and covered by our standard service-level agreement (SLA).FIPS supportedA FIPS distribution is available for environments that require cryptography compliant with Federal Information Processing Standards.Until November 2029Covered until November 2029. Until then, every CVE in it gets a fix within our service-level agreement (SLA): 7 days for critical, 15 for high, 45 for medium, and 90 for low.
Built on Nixpkgs 26.05. Available for use in production environments and covered by our standard service-level agreement (SLA).
Fixed within SLA
479
last 30 days
Fixed within SLA
18
last 7 days
Open
27
not yet fixed but still within SLA
Overdue
0
open
Missed SLA
0
last 30 days
Use this distribution
Customers onlyDeterminate Secure Packages is available through FlakeHub to organizations with access. Not a customer yet? Get in touch to gain access or schedule a demo.
Email sales@determinate.systemsStandardflake.nix
{
inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-26.05/0";
}FIPS variant
FIPS variantflake.nix
{
inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-26.05-fips/0";
}In the FIPS variant, every covered package is compliant with Federal Information Processing Standards (FIPS). Using the FIPS variant has the details.
506 CVEs tracked
| CVE | Status | Severity | Summary | Clock started | Deadline | Fixed | Time to fix |
|---|---|---|---|---|---|---|---|
| Fixed within SLA | Medium | Google Chrome WebProtect bug pre-151.0.7922.72 lets compromised renderer leak cross-origin data via crafted HTML | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome <151.0.7922.72 GPU bug allows cross-origin data leak after renderer compromise via crafted HTML | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome pre-151.0.7922.72 NoStatePrefetch side-channel allowed remote cross-origin data leaks via crafted HTML | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome <151.0.7922.72 Codecs uninitialized use leaks memory via crafted HTML | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Critical | Dawn heap buffer overflow in Chrome <151.0.7922.72 enables potential remote sandbox escape via crafted HTML | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome Skia uninitialized use allows cross-origin data leak via crafted HTML (pre-151.0.7922.72) | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome Autofill vulnerability pre-151.0.7922.72: remote cross-origin data leak via crafted HTML | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Use-after-free in Chrome Views on Mac pre-151.0.7922.72 enables remote heap corruption via crafted HTML | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Google Chrome AdFilter sandbox RCE via crafted HTML before 151.0.7922.72 | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Chrome pre-151.0.7922.72 ANGLE use-after-free allows remote sandbox escape via crafted HTML | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Insufficient input validation in Chrome Android Payments enables UI spoofing via compromised renderer | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome Mac GPU use-after-free allows sandbox escape from compromised renderer via crafted HTML (pre-151.0.7922.72) | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Skia out-of-bounds read enables sandbox escape after renderer compromise, Chrome <151.0.7922.72 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Chrome Linux File Input vulnerability enables remote sandbox escape via crafted HTML (pre-151.0.7922.72) | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome Payments insufficient policy enforcement allows cross-origin data leak via crafted HTML page | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | WebView untrusted input validation flaw enables sandbox escape in Chrome Android prior to 151.0.7922.72 | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | ANGLE uninitialized use in Chrome <151.0.7922.72 leaks cross-origin data via crafted HTML | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Insufficient policy enforcement allows UXSS via malicious extensions in Chrome pre-151.0.7922.72 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Android Chrome Bluetooth use-after-free enables sandbox escape by compromised renderer via crafted HTML pre-151.0.7922.72 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Android Chrome <151 WebView input validation bug lets compromised renderer escape sandbox via HTML | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome Android QUIC flaw enabled remote cross-origin data leak via crafted HTML (pre-151.0.7922.72) | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Low | Pre-151.0.7922.72 Chrome SVG flaw leaks cross-origin data via crafted HTML | Aug 4, 2026 | Nov 2, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Android Chrome Autofill prior to 151.0.7922.72 leaks cross-origin data via crafted page | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome <151 Autofill side-channel allowed cross-origin data leak via crafted page and UI gestures | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Critical | Chrome Android <151.0.7922.72 WebGL out-of-bounds write enables remote sandbox escape via crafted HTML | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Critical | WebGL integer overflow allows sandbox escape in Chrome Android before 151.0.7922.72 via crafted HTML | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | V8 type confusion in Chrome <151.0.7922.72 allows sandboxed RCE via crafted HTML | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | WebView lifecycle bug in Android Chrome pre-151.0.7922.72 allowed renderer-compromised sandbox escape | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Critical | ANGLE out-of-bounds write allows remote sandbox escape via crafted HTML in Chrome <151.0.7922.72 High severity | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Low | High-severity Chrome Passwords policy flaw leaks cross-origin data via compromised renderer (pre-151.0.7922.72) | Aug 4, 2026 | Nov 2, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | High-severity use-after-free in Input enables sandboxed RCE via crafted HTML in Chrome <151.0.7922.72 | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Critical | Use-after-free in ANGLE allows remote sandbox escape via crafted HTML on Chrome <151.0.7922.72 | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Critical | High severity ANGLE integer overflow in Chrome <151.0.7922.72 enables remote sandbox escape via crafted HTML | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Low | Chrome Passwords before 151.0.7922.72: cross-origin data leak via crafted HTML, UI gestures | Aug 4, 2026 | Nov 2, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | High-severity ANGLE uninitialized use in Chrome pre-151.0.7922.72 enables remote memory disclosure via crafted HTML | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Chrome Mac Skia race pre-151.0.7922.72 enables sandboxed remote code execution via crafted HTML | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Critical | Chrome Mac <151.0.7922.72 Downloads race allows sandbox escape after renderer compromise via crafted HTML page | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Critical | Google Chrome Mac <151.0.7922.72 MHTML flaw enables sandbox escape from compromised renderer via crafted HTML | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Critical | Chrome Mac pre-151.0.7922.72 Downloads race allows sandbox escape after renderer compromise | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Critical | Google Chrome Audio use-after-free enables sandbox escape from compromised renderer via crafted HTML pre-151.0.7922.72 | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome Windows pre-151.0.7922.72 Media uninitialized use info leak via crafted HTML requiring renderer compromise | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | High-severity Chrome <151.0.7922.72 libxml integer overflow allows sandboxed RCE via crafted HTML | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Critical | Chrome <151.0.7922.72 ANGLE use-after-free enables sandbox escape via crafted HTML | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome iOS <151.0.7922.72 policy enforcement bug allows navigation restriction bypass via crafted HTML remote attacker | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Low | Chrome <151.0.7922.72 Skia cross-origin data leak via crafted HTML with compromised renderer | Aug 4, 2026 | Nov 2, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome pre-151.0.7922.72 Actor input validation flaw leaks cross-origin data via compromised renderer | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Use-after-free in Chrome Views enables local attacker sandbox escape via malicious file (pre-151.0.7922.72) | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Chrome on Android UI input validation flaw pre-151.0.7922.72 allows local cross-origin data leak | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Critical | Chrome ANGLE type confusion enabling sandbox escape via crafted HTML in versions <151.0.7922.72 | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome Media side-channel allows remote cross-origin data leak via crafted HTML (pre-151.0.7922.72) | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day |
Make CVE remediation our job, not yours.
Tell us what you run. We'll show you what Determinate Secure Packages covers, how the SLA applies, and how to get started.