Skip to content
All distributions

Updated 14:01

Determinate Secure Packages distribution

secure-packages-rollingSupportedFIPS supported

Built on Nixpkgs as it moves. Available for use in production environments and covered by our standard service-level agreement (SLA).

Fixed in the last 30 days

807

Fixed in the last 7 days

603

In progress

83

Determinate Secure Packages is available through FlakeHub to organizations with access. Not a customer yet? Get in touch to gain access or schedule a demo.

Standardflake.nix

{
  inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-rolling/0";
}
FIPS variant

FIPS variantflake.nix

{
  inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-rolling-fips/0";
}

In the FIPS variant, every covered package is compliant with Federal Information Processing Standards (FIPS). Using the FIPS variant has the details.

890 CVEs tracked

Severity
Status
CVEStatusSeveritySummaryFixed
FixedHighRUSTSEC-2026-0195: quick-xml NamespaceResolver::push unbounded allocations on many xmlns attributes cause OOMSep 6, 2026
FixedHighRUSTSEC-2026-0194: quick-xml default duplicate-attribute check is O(N^2), causing CPU DoS on large tagsSep 6, 2026
FixedHighRUSTSEC-2026-0187: lopdf load_mem parses deeply nested PDF arrays/dicts with unbounded recursion, causing stack overflow DoSSep 6, 2026
FixedHighRUSTSEC-2026-0185: Non-contiguous stream fragments cause Assembler excessive buffering, enabling RecvStream memory exhaustionSep 6, 2026
FixedMediumRUSTSEC-2026-0068: tar-rs <=0.4.44 ignores PAX size override, causing cross-parser file size discrepanciesSep 6, 2026
FixedMediumRUSTSEC-2026-0067: tar-rs <=0.4.44 symlink handling lets crafted tarballs chmod arbitrary directories outside extraction rootSep 6, 2026
FixedHighRUSTSEC-2026-0048: AWS-LC CRL DP matching bug allows revoked certificates to bypass validation with partitioned IDP CRLsSep 6, 2026
FixedHighRUSTSEC-2026-0047: Improper signature validation in AWS-LC PKCS7_verify() enables unauthenticated bypass with Authenticated AttributesSep 6, 2026
FixedHighRUSTSEC-2026-0046: AWS-LC PKCS7_verify certificate chain verification bypass for multiple signers (non-final); affects aws-lc-sysSep 6, 2026
FixedMediumRUSTSEC-2026-0045: AWS-LC AES-CCM EVP CIPHER timing side-channel reveals authentication tag validitySep 6, 2026
FixedHighRUSTSEC-2026-0041: LZ4 lz4_flex block API offset validation flaw leaks uninitialized/prior buffer dataSep 6, 2026
FixedHighRUSTSEC-2026-0037: Panic when parsing invalid QUIC transport parameters due to unwrap() callsSep 6, 2026
FixedMediumRUSTSEC-2026-0009: RFC 2822 parsing permits stack exhaustion DoS via maliciously crafted, deprecated feature usageSep 6, 2026
FixedMediumRUSTSEC-2023-0071: Timing side-channel in rsa crate leaks private keys due to non-constant-time implementationSep 6, 2026
FixedHighGHSA-xwg4-73v4-xw9w: nanoid size integer overflow corrupts CSPRNG pool, returning deterministic 'u' IDs process-wideSep 6, 2026
FixedLowGHSA-xwfj-jgwm-7wp5: tracing-subscriber vulnerable to ANSI escape injection, enabling terminal manipulation and potential exploitationSep 6, 2026
FixedHighGHSA-xvcm-6775-5m9r: Immutable.js Map/Set DoS from attacker-crafted key hash collisions and linear bucketsSep 6, 2026
FixedMediumGHSA-xv59-967r-8726: openssl crate AES wrap-pad cipher updates mis-size buffers, enabling attacker-controlled heap corruptionSep 6, 2026
FixedHighGHSA-xpqw-6gx7-v673: SVGO entity expansion vulnerability: custom XML entities cause DoS and Node.js OOM crashesSep 6, 2026
FixedMediumGHSA-xphf-cx8h-7q9g: Function returns reference into OpenSSL structure that OpenSSL may mutate unexpectedly, causing unsafety.Sep 6, 2026
FixedHighGHSA-xp3w-r5p5-63rr: X509Ref::ocsp_responders creates invalid &str for non-UTF-8 OCSP URLs, causing undefined behaviorSep 6, 2026
FixedLowGHSA-xmgf-hq76-4vx2: OpenSSL pre-3.x *_from_pem_callback length validation bug causes password buffer over-readSep 6, 2026
FixedLowGHSA-xgp8-3hg3-c2mh: Wildcard DNS incorrectly accepted under permitted subtree constraints, allowing outside-subtree namesSep 6, 2026
FixedLowGHSA-xffm-g5w8-qvg7: ReDoS in @eslint/plugin-kit ConfigCommentParser#parseJSONLikeConfig from unanchored regexSep 6, 2026
FixedMediumGHSA-xcf7-rvmh-g6q4: Empty string argument causes OpenSSL to call strlen, reading arbitrary memory until NULSep 6, 2026
FixedMediumGHSA-x5fp-wj9c-mxmx: qs v6.15.3 bracket-key comma=true inputs bypass arrayLimit/throwOnLimitExceeded, enabling DoSSep 6, 2026
FixedHighGHSA-x494-mj8g-cj27: DoS in gix-pack: truncated deltas panic, attacker-sized allocations cause OOMSep 6, 2026
FixedHighGHSA-wwq9-3cpr-mm53: Borsh HashMap serialization non-canonical, order-dependent, lacking decode checks; risks consensus splitsSep 6, 2026
FixedCriticalGHSA-wf6x-7x77-mvgw: Immutable.js merge/mergeDeep/mergeDeepWith and Map.toJS/toObject vulnerable to prototype pollutionSep 6, 2026
FixedMediumGHSA-w9m9-85wc-3x92: postcss-selector-parser toString uncontrolled recursion allows remote DoS (pre-6.1.3/7.1.1)Sep 6, 2026
FixedMediumGHSA-w8wr-v893-vjvp: node-tar DoS: extracting PAX entry with all-digit path causes uncaught TypeErrorSep 6, 2026
FixedCriticalGHSA-w7jw-789q-3m8p: shell-quote quote() lacks .op validation; line terminators pass unescaped, enabling command injection via object tokensSep 6, 2026
FixedLowGHSA-w7fw-mjwx-w883: qs: comma option bypasses arrayLimit, enabling DoS by massive array allocationSep 6, 2026
FixedHighGHSA-w5hq-g745-h8pq: uuid v3/v5/v6 accept out-of-range buf/offset, causing silent partial writesSep 6, 2026
FixedHighGHSA-w3rx-r6r6-pgpr: image-size <=2.0.2 ICNS parser DoS blocks Node.js event loop via zero-length entrySep 6, 2026
FixedMediumGHSA-w2qp-rph6-63g4: Fastify <5.12.1 validates coerced root primitives but exposes uncoerced body to handlersSep 6, 2026
FixedHighGHSA-vxpw-j846-p89q: Undici WebSocket lacks fragment count limit, enabling memory exhaustion DoS since 6.17.0Sep 6, 2026
FixedHighGHSA-vw5v-4f2q-w9xf: aws-lc-sys PKCS7_verify certificate chain bypass with multiple signers (0.24.0–<0.38.0)Sep 6, 2026
FixedHighGHSA-vvp9-7p8x-rfvv: lz4_flex block decompression leaks uninitialized or previous buffer data due to invalid offset handlingSep 6, 2026
FixedHighGHSA-vmh5-mc38-953g: Undici ProxyAgent drops requestTls with SOCKS5, bypassing custom TLS settings and CA pinningSep 6, 2026
FixedMediumGHSA-vmf3-w455-68vh: node-tar PAX size applied to L/K/x headers causes parser desync, interpretation differentialSep 6, 2026
FixedMediumGHSA-v6wh-96g9-6wx3: Windows UNC path handling in launch-editor leaks NTLMv2 hashes to attacker SMB serversSep 6, 2026
FixedLowGHSA-v6h2-p8h4-qcjw: Remote ReDoS in juliangruber brace-expansion expand() from inefficient regex; affects <=4.0.0Sep 6, 2026
FixedHighGHSA-v5mp-jgw5-2x6j: toml.parse allows Object.prototype pollution via scalar __proto__ traversal and path-tracking desyncSep 6, 2026
FixedHighGHSA-v56q-mh7h-f735: Immutable.js List large index causes infinite loop/OOM; setSize silently wraps/truncatesSep 6, 2026
FixedLowGHSA-v422-hmwv-36x6: body-parser invalid limit silently disables size check, allowing oversized request DoSSep 6, 2026
FixedMediumGHSA-v3rj-xjv7-4jmq: smol-toml parser crashes from stack overflow on thousands of consecutive comment linesSep 6, 2026
FixedMediumGHSA-v3r7-h72x-cjcm: Undici setCookie attribute injection via domain and unparsed fields bypasses SameSite/HttpOnlySep 6, 2026
FixedHighGHSA-v39h-62p7-jpjc: fast-uri <=3.1.1 decodes %40/%3A in host, enabling host confusion attacksSep 6, 2026
FixedHighGHSA-v2hh-gcrm-f6hx: fast-uri ≤4.1.0 backslash handling diverges from Node URL, enabling host policy desync/SSRFSep 6, 2026

Make CVE remediation our job, not yours.

Tell us what you run. We'll show you what Determinate Secure Packages covers, how the SLA applies, and how to get started.

Contact sales

Provide us with some basic details and we'll follow up with you about , usually within one business day.

We'll only use this to get back to you. See our privacy policy (opens in a new tab). This site is protected by reCAPTCHA and the Google Privacy Policy (opens in a new tab) and Terms of Service (opens in a new tab) apply.