Debian 11 security packages 404 and the archive is missing
Debian 11 bullseye-security still serves a package index, but the .deb files are gone and archive.debian.org has no bullseye-security. Check your old servers.
Debian 11 security packages are in the worst possible state: the index says they exist, the files return 404, and there is no archive to fall back on. Bullseye LTS ended August 31, 2026. Almost a month later the bullseye-security suite is still being advertised by deb.debian.org while the packages behind it are being deleted, and archive.debian.org — the place every EOL Debian release eventually lands — has no bullseye-security at all. We checked this ourselves today. If you have a box still pointed at bullseye, apt update will tell you everything is fine and apt install will hand you a 404.
What actually happened
We pulled the live files rather than take anyone's word for it. As of September 27, 2026:
- The Release file is still served.
https://deb.debian.org/debian-security/dists/bullseye-security/Releasereturns 200, dated Sat, 12 Sep 2026, suiteoldoldstable-security, codenamebullseye-security. - The index still lists the packages. The
updates/mainamd64Packages.gzlists 3,816 binary packages, includingopensslversion 1.1.1w-0+deb11u8. - The package file is gone.
.../pool/updates/main/o/openssl/openssl_1.1.1w-0+deb11u8_amd64.debreturns 404. The pool directory itself still returns 200. The metadata and the bits have diverged. - There is no archived fallback.
https://archive.debian.org/debian-security/dists/bullseye-security/returns 404 — the directory does not exist. Debian 10's security archive is there, atdists/buster/updates/. Bullseye's is not. - Non-security bullseye is fine.
archive.debian.org/debian/dists/bullseye/Releasereturns 200. It is specifically the security suite that fell into the gap.
This was flagged on the debian-mirrors list on September 8 by a mirror operator watching the same divergence: indexes referencing deleted files, no archive snapshot to redirect to. Nineteen days later it is still broken. To be clear about what this is — an incomplete archival transition, not a compromise. That does not make it less disruptive.
Why a broken package archive matters for your business
Your CI is the thing that breaks first. Every FROM debian:11 image, every Ansible role with apt: name=openssl state=latest, every provisioning script written in 2022 and never touched since. The failure mode is nasty because apt update succeeds — the signed Release file and the indexes are valid. You only fail at fetch time, deep in a build, with a 404 on a package your index swears exists. That is a red pipeline on a Monday for a reason nobody on your team will guess.
"It still boots" is not a patch strategy. Bullseye left LTS four weeks ago. Right now the practical situation is worse than unsupported: you cannot even reinstall the last security build of openssl from the official mirror. If you are running bullseye in production today you have no supported patch path, and as of this week no reliable reinstall path either. The options are a real upgrade to bookworm or trixie, or Freexian's commercial ELTS, which is a paid subscription and a different set of repository URLs. Both are work. Pretending is not a third option.
Pin your base images to a digest, and mirror what you depend on. This is the second time this year a dependency we all treat as permanent infrastructure has quietly moved. If your build reaches out to a public mirror at build time, your build's reproducibility is somebody else's retention policy. Cache the packages you actually install, pin base images by digest rather than tag, and keep a local mirror of anything you cannot rebuild from scratch on demand.
Run the check now, not after the outage. grep -r bullseye /etc/apt/sources.list* on every host. grep -rn "debian:11\|bullseye" Dockerfile* across every repo. It takes ten minutes and tells you exactly how exposed you are.
Key takeaways
- Debian 11 bullseye LTS ended August 31, 2026; the security suite is now in a broken transitional state
- Verified September 27:
bullseye-securityRelease returns 200 and lists 3,816 amd64 packages, but the openssl.debit references returns 404 archive.debian.org/debian-security/dists/bullseye-security/does not exist — Debian 10's security archive doesapt updatestill succeeds, so the failure surfaces mid-build as a 404 on a package the index claims exists- Real paths forward: upgrade to bookworm/trixie, or buy Freexian ELTS — there is no free supported option
- Audit now:
grep -r bullseye /etc/apt/sources.list*on hosts,debian:11in every Dockerfile
A build that fetches from a public mirror at build time is a build someone else can break. We move small businesses off unsupported base images and onto pinned, reproducible builds that do not depend on anyone's retention policy. See how we build, or have us audit what your servers are still pointed at.
Sources: debian-mirrors list, September 8, 2026, archive.debian.org, Debian LTS.
- #debian
- #linux
- #patching
- #devops
- #supply-chain
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
Plugin4Shell: your SHA pin was never verified
Plugin4Shell let attackers swap AI coding agent plugins past SHA pinning. Claude Code and Codex are patched; Copilot and Gemini CLI are not.
Read itNetScaler patches land: eight CVEs, two already exploited
Citrix bulletin CTX697096 assigns CVEs to the exploited NetScaler zero-days and ships fixed builds. Patch to 14.1-73.37 or 13.1-64.23 now.
Read it