cbcvebase.
CVE-2026-49860
published 2026-06-23

CVE-2026-49860: Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, when a WebSocket connection was opened, Deno checked the destination hostname…

PriorityP424medium5.2CVSS 3.1
AVLACLPRLUINSCCLILAN
EPSS
0.14%
3.8th percentile
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, when a WebSocket connection was opened, Deno checked the destination hostname against --deny-net rules but did not re-check the IP addresses that hostname resolved to. An attacker-controlled script could use a specially crafted domain name that passes the hostname check yet resolves to a denied IP, bypassing the network restriction entirely. This vulnerability is fixed in 2.8.1.

Affected

3 ranges
VendorProductVersion rangeFixed in
denodeno< 2.8.12.8.1
denodeno>= 0 < 2.8.12.8.1
denolanddeno< 2.8.12.8.1
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.