CVE-2026-49860
published 2026-06-23CVE-2026-49860: Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, when a WebSocket connection was opened, Deno checked the destination hostname…
PriorityP424medium5.2CVSS 3.1
AVLACLPRLUINSCCLILAN
EPSS
0.14%
3.8th percentile
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, when a WebSocket connection was opened, Deno checked the destination hostname against --deny-net rules but did not re-check the IP addresses that hostname resolved to. An attacker-controlled script could use a specially crafted domain name that passes the hostname check yet resolves to a denied IP, bypassing the network restriction entirely. This vulnerability is fixed in 2.8.1.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| deno | deno | < 2.8.1 | 2.8.1 |
| deno | deno | >= 0 < 2.8.1 | 2.8.1 |
| denoland | deno | < 2.8.1 | 2.8.1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
denoland deno up to 2.8.0 Domain server-side request forgery (GHSA-83pc-3rw9-qpwj)
vuldb·2026-06-23·CVSS 5.2
CVE-2026-49860 [MEDIUM] denoland deno up to 2.8.0 Domain server-side request forgery (GHSA-83pc-3rw9-qpwj)
A vulnerability categorized as critical has been discovered in denoland deno up to 2.8.0. Affected by this vulnerability is an unknown functionality of the component Domain Handler. Such manipulation leads to server-side request forgery.
This vulnerability is referenced as CVE-2026-49860. It is possible to launch the attack remotely. No exploit is available.
It is advisable to upgrade the affected component.
GHSA
Deno: WebSocket API sandbox bypass via missing post-DNS check
ghsa·2026-06-16
CVE-2026-49860 [MEDIUM] CWE-918 Deno: WebSocket API sandbox bypass via missing post-DNS check
Deno: WebSocket API sandbox bypass via missing post-DNS check
## Summary
When a WebSocket connection was opened, Deno checked the destination hostname
against `--deny-net` rules but did not re-check the IP addresses that hostname
resolved to. An attacker-controlled script could use a specially crafted domain
name that passes the hostname check yet resolves to a denied IP, bypassing the
network restriction entirely.
## Impact
Code running under `--deny-net` could connect to hosts that the user intended
to block. In practice this means network isolation rules — for example,
blocking access to `localhost` or internal services — could be silently
circumvented by a malicious or compromised dependency.
`Deno.connect` and `fetch()` were not affected by this specific issue (a
companion adviso
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-23
Published