← All distributions
Updated 14:01
Determinate Secure Packages distribution
secure-packages-rollingSupportedAvailable for use in production environments and covered by our standard service-level agreement (SLA).FIPS supportedA FIPS distribution is available for environments that require cryptography compliant with Federal Information Processing Standards.
Built on Nixpkgs as it moves. Available for use in production environments and covered by our standard service-level agreement (SLA).
Fixed in the last 30 days
807
Fixed in the last 7 days
603
In progress
83
Use this distribution
Customers onlyDeterminate Secure Packages is available through FlakeHub to organizations with access. Not a customer yet? Get in touch to gain access or schedule a demo.
Standardflake.nix
{
inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-rolling/0";
}FIPS variant
FIPS variantflake.nix
{
inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-rolling-fips/0";
}In the FIPS variant, every covered package is compliant with Federal Information Processing Standards (FIPS). Using the FIPS variant has the details.
890 CVEs tracked
| CVE | Status | Severity | Summary | Fixed |
|---|---|---|---|---|
| Fixed | High | RUSTSEC-2026-0195: quick-xml NamespaceResolver::push unbounded allocations on many xmlns attributes cause OOM | Sep 6, 2026 | |
| Fixed | High | RUSTSEC-2026-0194: quick-xml default duplicate-attribute check is O(N^2), causing CPU DoS on large tags | Sep 6, 2026 | |
| Fixed | High | RUSTSEC-2026-0187: lopdf load_mem parses deeply nested PDF arrays/dicts with unbounded recursion, causing stack overflow DoS | Sep 6, 2026 | |
| Fixed | High | RUSTSEC-2026-0185: Non-contiguous stream fragments cause Assembler excessive buffering, enabling RecvStream memory exhaustion | Sep 6, 2026 | |
| Fixed | Medium | RUSTSEC-2026-0068: tar-rs <=0.4.44 ignores PAX size override, causing cross-parser file size discrepancies | Sep 6, 2026 | |
| Fixed | Medium | RUSTSEC-2026-0067: tar-rs <=0.4.44 symlink handling lets crafted tarballs chmod arbitrary directories outside extraction root | Sep 6, 2026 | |
| Fixed | High | RUSTSEC-2026-0048: AWS-LC CRL DP matching bug allows revoked certificates to bypass validation with partitioned IDP CRLs | Sep 6, 2026 | |
| Fixed | High | RUSTSEC-2026-0047: Improper signature validation in AWS-LC PKCS7_verify() enables unauthenticated bypass with Authenticated Attributes | Sep 6, 2026 | |
| Fixed | High | RUSTSEC-2026-0046: AWS-LC PKCS7_verify certificate chain verification bypass for multiple signers (non-final); affects aws-lc-sys | Sep 6, 2026 | |
| Fixed | Medium | RUSTSEC-2026-0045: AWS-LC AES-CCM EVP CIPHER timing side-channel reveals authentication tag validity | Sep 6, 2026 | |
| Fixed | High | RUSTSEC-2026-0041: LZ4 lz4_flex block API offset validation flaw leaks uninitialized/prior buffer data | Sep 6, 2026 | |
| Fixed | High | RUSTSEC-2026-0037: Panic when parsing invalid QUIC transport parameters due to unwrap() calls | Sep 6, 2026 | |
| Fixed | Medium | RUSTSEC-2026-0009: RFC 2822 parsing permits stack exhaustion DoS via maliciously crafted, deprecated feature usage | Sep 6, 2026 | |
| Fixed | Medium | RUSTSEC-2023-0071: Timing side-channel in rsa crate leaks private keys due to non-constant-time implementation | Sep 6, 2026 | |
| Fixed | High | GHSA-xwg4-73v4-xw9w: nanoid size integer overflow corrupts CSPRNG pool, returning deterministic 'u' IDs process-wide | Sep 6, 2026 | |
| Fixed | Low | GHSA-xwfj-jgwm-7wp5: tracing-subscriber vulnerable to ANSI escape injection, enabling terminal manipulation and potential exploitation | Sep 6, 2026 | |
| Fixed | High | GHSA-xvcm-6775-5m9r: Immutable.js Map/Set DoS from attacker-crafted key hash collisions and linear buckets | Sep 6, 2026 | |
| Fixed | Medium | GHSA-xv59-967r-8726: openssl crate AES wrap-pad cipher updates mis-size buffers, enabling attacker-controlled heap corruption | Sep 6, 2026 | |
| Fixed | High | GHSA-xpqw-6gx7-v673: SVGO entity expansion vulnerability: custom XML entities cause DoS and Node.js OOM crashes | Sep 6, 2026 | |
| Fixed | Medium | GHSA-xphf-cx8h-7q9g: Function returns reference into OpenSSL structure that OpenSSL may mutate unexpectedly, causing unsafety. | Sep 6, 2026 | |
| Fixed | High | GHSA-xp3w-r5p5-63rr: X509Ref::ocsp_responders creates invalid &str for non-UTF-8 OCSP URLs, causing undefined behavior | Sep 6, 2026 | |
| Fixed | Low | GHSA-xmgf-hq76-4vx2: OpenSSL pre-3.x *_from_pem_callback length validation bug causes password buffer over-read | Sep 6, 2026 | |
| Fixed | Low | GHSA-xgp8-3hg3-c2mh: Wildcard DNS incorrectly accepted under permitted subtree constraints, allowing outside-subtree names | Sep 6, 2026 | |
| Fixed | Low | GHSA-xffm-g5w8-qvg7: ReDoS in @eslint/plugin-kit ConfigCommentParser#parseJSONLikeConfig from unanchored regex | Sep 6, 2026 | |
| Fixed | Medium | GHSA-xcf7-rvmh-g6q4: Empty string argument causes OpenSSL to call strlen, reading arbitrary memory until NUL | Sep 6, 2026 | |
| Fixed | Medium | GHSA-x5fp-wj9c-mxmx: qs v6.15.3 bracket-key comma=true inputs bypass arrayLimit/throwOnLimitExceeded, enabling DoS | Sep 6, 2026 | |
| Fixed | High | GHSA-x494-mj8g-cj27: DoS in gix-pack: truncated deltas panic, attacker-sized allocations cause OOM | Sep 6, 2026 | |
| Fixed | High | GHSA-wwq9-3cpr-mm53: Borsh HashMap serialization non-canonical, order-dependent, lacking decode checks; risks consensus splits | Sep 6, 2026 | |
| Fixed | Critical | GHSA-wf6x-7x77-mvgw: Immutable.js merge/mergeDeep/mergeDeepWith and Map.toJS/toObject vulnerable to prototype pollution | Sep 6, 2026 | |
| Fixed | Medium | GHSA-w9m9-85wc-3x92: postcss-selector-parser toString uncontrolled recursion allows remote DoS (pre-6.1.3/7.1.1) | Sep 6, 2026 | |
| Fixed | Medium | GHSA-w8wr-v893-vjvp: node-tar DoS: extracting PAX entry with all-digit path causes uncaught TypeError | Sep 6, 2026 | |
| Fixed | Critical | GHSA-w7jw-789q-3m8p: shell-quote quote() lacks .op validation; line terminators pass unescaped, enabling command injection via object tokens | Sep 6, 2026 | |
| Fixed | Low | GHSA-w7fw-mjwx-w883: qs: comma option bypasses arrayLimit, enabling DoS by massive array allocation | Sep 6, 2026 | |
| Fixed | High | GHSA-w5hq-g745-h8pq: uuid v3/v5/v6 accept out-of-range buf/offset, causing silent partial writes | Sep 6, 2026 | |
| Fixed | High | GHSA-w3rx-r6r6-pgpr: image-size <=2.0.2 ICNS parser DoS blocks Node.js event loop via zero-length entry | Sep 6, 2026 | |
| Fixed | Medium | GHSA-w2qp-rph6-63g4: Fastify <5.12.1 validates coerced root primitives but exposes uncoerced body to handlers | Sep 6, 2026 | |
| Fixed | High | GHSA-vxpw-j846-p89q: Undici WebSocket lacks fragment count limit, enabling memory exhaustion DoS since 6.17.0 | Sep 6, 2026 | |
| Fixed | High | GHSA-vw5v-4f2q-w9xf: aws-lc-sys PKCS7_verify certificate chain bypass with multiple signers (0.24.0–<0.38.0) | Sep 6, 2026 | |
| Fixed | High | GHSA-vvp9-7p8x-rfvv: lz4_flex block decompression leaks uninitialized or previous buffer data due to invalid offset handling | Sep 6, 2026 | |
| Fixed | High | GHSA-vmh5-mc38-953g: Undici ProxyAgent drops requestTls with SOCKS5, bypassing custom TLS settings and CA pinning | Sep 6, 2026 | |
| Fixed | Medium | GHSA-vmf3-w455-68vh: node-tar PAX size applied to L/K/x headers causes parser desync, interpretation differential | Sep 6, 2026 | |
| Fixed | Medium | GHSA-v6wh-96g9-6wx3: Windows UNC path handling in launch-editor leaks NTLMv2 hashes to attacker SMB servers | Sep 6, 2026 | |
| Fixed | Low | GHSA-v6h2-p8h4-qcjw: Remote ReDoS in juliangruber brace-expansion expand() from inefficient regex; affects <=4.0.0 | Sep 6, 2026 | |
| Fixed | High | GHSA-v5mp-jgw5-2x6j: toml.parse allows Object.prototype pollution via scalar __proto__ traversal and path-tracking desync | Sep 6, 2026 | |
| Fixed | High | GHSA-v56q-mh7h-f735: Immutable.js List large index causes infinite loop/OOM; setSize silently wraps/truncates | Sep 6, 2026 | |
| Fixed | Low | GHSA-v422-hmwv-36x6: body-parser invalid limit silently disables size check, allowing oversized request DoS | Sep 6, 2026 | |
| Fixed | Medium | GHSA-v3rj-xjv7-4jmq: smol-toml parser crashes from stack overflow on thousands of consecutive comment lines | Sep 6, 2026 | |
| Fixed | Medium | GHSA-v3r7-h72x-cjcm: Undici setCookie attribute injection via domain and unparsed fields bypasses SameSite/HttpOnly | Sep 6, 2026 | |
| Fixed | High | GHSA-v39h-62p7-jpjc: fast-uri <=3.1.1 decodes %40/%3A in host, enabling host confusion attacks | Sep 6, 2026 | |
| Fixed | High | GHSA-v2hh-gcrm-f6hx: fast-uri ≤4.1.0 backslash handling diverges from Node URL, enabling host policy desync/SSRF | Sep 6, 2026 |
Make CVE remediation our job, not yours.
Tell us what you run. We'll show you what Determinate Secure Packages covers, how the SLA applies, and how to get started.