CVE-2025-24015
published 2025-06-03CVE-2025-24015: Deno is a JavaScript, TypeScript, and WebAssembly runtime. Versions 1.46.0 through 2.1.6 have an issue that affects AES-256-GCM and AES-128-GCM in Deno in…
PriorityP430medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
0.27%
20.1th percentile
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Versions 1.46.0 through 2.1.6 have an issue that affects AES-256-GCM and AES-128-GCM in Deno in which the authentication tag is not being validated. This means tampered ciphertexts or incorrect keys might not be detected, which breaks the guarantees expected from AES-GCM. Older versions of Deno correctly threw errors in such cases, as does Node.js. Without authentication tag verification, AES-GCM degrades to essentially CTR mode, removing integrity protection. Authenticated data set with set_aad is also affected, as it is incorporated into the GCM hash (ghash) but this too is not validated, rendering AAD checks ineffective. Version 2.1.7 includes a patch that addresses this issue.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| deno | deno | >= 1.46.0 < 2.1.7 | 2.1.7 |
| deno | deno | >= 1.46.0 < 2.1.7 | 2.1.7 |
| denoland | deno | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv4.07.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Deno's AES GCM authentication tags are not verified
osv·2025-06-04
CVE-2025-24015 [HIGH] Deno's AES GCM authentication tags are not verified
Deno's AES GCM authentication tags are not verified
### Summary
This affects AES-256-GCM and AES-128-GCM in Deno, introduced by commit [0d1beed](https://github.com/denoland/deno/commit/0d1beed). Specifically, the authentication tag is not being validated. This means tampered ciphertexts or incorrect keys might not be detected, which breaks the guarantees expected from AES-GCM. Older versions of Deno correctly threw errors in such cases, as does Node.js.
Without authentication tag verification, AES-GCM degrades to essentially CTR mode, removing integrity protection. Authenticated data set with set_aad is also affected, as it is incorporated into the GCM hash (ghash) but this too is not validated, rendering AAD checks ineffective.
### PoC
```ts
import { Buffer } from "node:buffer";
impo
GHSA
Deno's AES GCM authentication tags are not verified
ghsa·2025-06-04
CVE-2025-24015 [HIGH] CWE-347 Deno's AES GCM authentication tags are not verified
Deno's AES GCM authentication tags are not verified
### Summary
This affects AES-256-GCM and AES-128-GCM in Deno, introduced by commit [0d1beed](https://github.com/denoland/deno/commit/0d1beed). Specifically, the authentication tag is not being validated. This means tampered ciphertexts or incorrect keys might not be detected, which breaks the guarantees expected from AES-GCM. Older versions of Deno correctly threw errors in such cases, as does Node.js.
Without authentication tag verification, AES-GCM degrades to essentially CTR mode, removing integrity protection. Authenticated data set with set_aad is also affected, as it is incorporated into the GCM hash (ghash) but this too is not validated, rendering AAD checks ineffective.
### PoC
```ts
import { Buffer } from "node:buffer";
impo
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/denoland/deno/commit/0d1beedhttps://github.com/denoland/deno/commit/4f27d7cdc02e3edfb9d36275341fb8185d6e99edhttps://github.com/denoland/deno/commit/a4003a5292bd0affefad3ecb24a8732886900f67https://github.com/denoland/deno/security/advisories/GHSA-2x3r-hwv5-p32xhttps://github.com/denoland/deno/security/advisories/GHSA-2x3r-hwv5-p32x
2025-06-03
Published