CVE-2026-49411
published 2026-06-23CVE-2026-49411: Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.0, the Node.js compatibility TCP path checked the permission against the original…
PriorityP430medium6.5CVSS 3.1
AVLACLPRLUINSCCHINAN
EPSS
0.16%
5.3th percentile
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.0, the Node.js compatibility TCP path checked the permission against the original hostname string before resolution and then did not re-check after resolution. A caller could therefore pass a numeric alias of an IP address (for example the decimal integer 2130706433 or the hex form 0x7f000001, both of which resolve to 127.0.0.1) and reach the denied destination through node:net.connect or node:http.request's { host, port } options form. This vulnerability is fixed in 2.8.0.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| deno | deno | >= 0 < 2.8.0 | 2.8.0 |
| deno | deno | >= 2.7.14 < 2.8.0 | 2.8.0 |
| denoland | deno | < 2.8.0 | 2.8.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
denoland deno up to 2.7.x access control (GHSA-v8fw-85r8-5m23)
vuldb·2026-06-23·CVSS 6.5
CVE-2026-49411 [MEDIUM] denoland deno up to 2.7.x access control (GHSA-v8fw-85r8-5m23)
A vulnerability was found in denoland deno up to 2.7.x. It has been classified as critical. This affects an unknown function. The manipulation leads to improper access controls.
This vulnerability is uniquely identified as CVE-2026-49411. Local access is required to approach this attack. No exploit exists.
Upgrading the affected component is recommended.
GHSA
Deno: Node TCPWrap numeric hostname aliases bypass --deny-net resolved-IP deny checks
ghsa·2026-06-16
CVE-2026-49411 [MEDIUM] CWE-284 Deno: Node TCPWrap numeric hostname aliases bypass --deny-net resolved-IP deny checks
Deno: Node TCPWrap numeric hostname aliases bypass --deny-net resolved-IP deny checks
## Summary
Deno's network permission model is designed so that `--deny-net` rules apply to the **resolved IP address** of a destination, not just the literal string supplied by the caller. That means `--deny-net=127.0.0.1` (or `--deny-net=127.0.0.0/8`) is expected to block any attempt to reach loopback, regardless of how the hostname is spelled.
On affected versions, the Node.js compatibility TCP path checked the permission against the **original hostname string** before resolution and then did not re-check after resolution. A caller could therefore pass a numeric alias of an IP address (for example the decimal integer `2130706433` or the hex form `0x7f000001`, both of which resolve to `127.0.0.1`) and
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-23
Published