CVE-2026-49859
published 2026-06-23CVE-2026-49859: Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, when fetch() was called, Deno checked the destination hostname against --deny-net…
PriorityP424medium5.2CVSS 3.1
AVLACLPRLUINSCCLILAN
EPSS
0.14%
3.8th percentile
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, when fetch() was called, Deno checked the destination hostname against --deny-net rules but did not re-check the IP addresses that hostname resolved to. An attacker-controlled script could use a specially crafted domain name that passes the hostname check yet resolves to a denied IP, bypassing the network restriction entirely. This vulnerability is fixed in 2.8.1.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| deno | deno | < 2.8.1 | 2.8.1 |
| deno | deno | >= 0 < 2.8.1 | 2.8.1 |
| denoland | deno | < 2.8.1 | 2.8.1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
denoland deno up to 2.8.0 Domain fetch protection mechanism (GHSA-cpgj-f7g3-2pp2)
vuldb·2026-06-23·CVSS 5.2
CVE-2026-49859 [MEDIUM] denoland deno up to 2.8.0 Domain fetch protection mechanism (GHSA-cpgj-f7g3-2pp2)
A vulnerability was found in denoland deno up to 2.8.0. It has been rated as problematic. Affected is the function fetch of the component Domain Handler. This manipulation causes protection mechanism failure.
The identification of this vulnerability is CVE-2026-49859. The attack can only be executed locally. There is no exploit available.
Upgrading the affected component is advised.
GHSA
Deno: `fetch()` API sandbox bypass via missing DNS resolution check
ghsa·2026-06-16
CVE-2026-49859 [MEDIUM] CWE-693 Deno: `fetch()` API sandbox bypass via missing DNS resolution check
Deno: `fetch()` API sandbox bypass via missing DNS resolution check
## Summary
When `fetch()` was called, Deno checked the destination hostname against
`--deny-net` rules but did not re-check the IP addresses that hostname
resolved to. An attacker-controlled script could use a specially crafted domain
name that passes the hostname check yet resolves to a denied IP, bypassing the
network restriction entirely.
## Impact
Code running under `--deny-net` could reach hosts that the user intended to
block. In practice this means network isolation rules — for example, blocking
access to `localhost` or internal services — could be silently circumvented by
a malicious or compromised dependency.
A companion advisory covers the same class of issue in the WebSocket API.
## Who is affected
Users
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-23
Published