CVE-2026-49440
published 2026-06-23CVE-2026-49440: Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, node:crypto.checkPrime(candidate[, options][, callback]) and…
PriorityP341high7.4CVSS 3.1
AVNACHPRNUINSUCHIHAN
EPSS
0.24%
15.0th percentile
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, node:crypto.checkPrime(candidate[, options][, callback]) and crypto.checkPrimeSync(candidate[, options]) ran no Miller-Rabin rounds at all when the caller left options.checks at its default of 0. In that mode, the only test applied to the candidate was trial division by the primes up to 17,863. Any composite whose smallest prime factor exceeds that bound — for example the product of two primes just above it, such as 17,881 × 17,891 — was reported as true ("probably prime"). The same divergence affected the lower-level op_node_check_prime / op_node_check_prime_bytes paths that the polyfill calls into. This vulnerability is fixed in 2.8.1.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| deno | deno | < 2.8.1 | 2.8.1 |
| deno | deno | >= 0 < 2.8.1 | 2.8.1 |
| denoland | deno | < 2.8.1 | 2.8.1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
denoland deno up to 2.8.0 missing cryptographic step (GHSA-9xg4-qhm4-g43w)
vuldb·2026-06-23·CVSS 7.4
CVE-2026-49440 [HIGH] denoland deno up to 2.8.0 missing cryptographic step (GHSA-9xg4-qhm4-g43w)
A vulnerability was found in denoland deno up to 2.8.0. It has been declared as problematic. This impacts an unknown function. The manipulation results in missing cryptographic step.
This vulnerability was named CVE-2026-49440. The attack may be performed from remote. There is no available exploit.
It is recommended to upgrade the affected component.
GHSA
Deno: Miller-Rabin Primality Test Allows Zero Rounds
ghsa·2026-06-16
CVE-2026-49440 [HIGH] CWE-325 Deno: Miller-Rabin Primality Test Allows Zero Rounds
Deno: Miller-Rabin Primality Test Allows Zero Rounds
## Summary
`node:crypto.checkPrime(candidate[, options][, callback])` and `crypto.checkPrimeSync(candidate[, options])` ran no Miller-Rabin rounds at all when the caller left `options.checks` at its default of `0`. In that mode, the only test applied to the candidate was trial division by the primes up to `17,863`. Any composite whose smallest prime factor exceeds that bound — for example the product of two primes just above it, such as `17,881 × 17,891` — was reported as `true` ("probably prime").
The same divergence affected the lower-level `op_node_check_prime` / `op_node_check_prime_bytes` paths that the polyfill calls into.
Node.js itself does not have this problem: it forwards `checks = 0` to OpenSSL's `BN_check_prime`, which s
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-23
Published