cbcvebase.

Denoland Deno vulnerabilities

38 known vulnerabilities affecting denoland/deno.

Total CVEs
38
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL9HIGH13MEDIUM14LOW2

Vulnerabilities

Page 1 of 2
CVE-2023-28445P3CRITICALCVSS 9.8Exploitedv= 1.32.02023-03-24
CVE-2023-28445 [CRITICAL] CWE-125 CVE-2023-28445: Deno is a runtime for JavaScript and TypeScript that uses V8 and is built in Rust. Resizable ArrayBu Deno is a runtime for JavaScript and TypeScript that uses V8 and is built in Rust. Resizable ArrayBuffers passed to asynchronous functions that are shrunk during the asynchronous operation could result in an out-of-bound read/write. It is unlikely that this has been exploited in the wild, as the only version affected is Deno 1.32.0. Deno Deploy us
nvd
CVE-2026-27190P2CRITICALCVSS 9.8v>= 2.7.0, < 2.7.22026-02-20
CVE-2026-27190 [CRITICAL] CWE-78 CVE-2026-27190: Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.6.8, a command injection vulne Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.6.8, a command injection vulnerability exists in Deno's node:child_process implementation. This vulnerability is fixed in 2.6.8.
nvd
CVE-2022-24783P2CRITICALCVSS 10.0v>= 1.18.0, < 1.20.32022-03-25
CVE-2022-24783 [CRITICAL] CWE-269 CVE-2022-24783: Deno is a runtime for JavaScript and TypeScript. The versions of Deno between release 1.18.0 and 1.2 Deno is a runtime for JavaScript and TypeScript. The versions of Deno between release 1.18.0 and 1.20.2 (inclusive) are vulnerable to an attack where a malicious actor controlling the code executed in a Deno runtime could bypass all permission checks and execute arbitrary shell code. This vulnerability does not affect users of Deno Deploy. The vul
nvd
CVE-2026-103473P2HIGHCVSS 8.1≥ 2.7.0, ≤ 2.9.72026-09-30
CVE-2026-103473 [HIGH] CWE-78 CVE-2026-103473: Deno versions 2.7.0 through 2.9.7 on Windows contain a command injection vulnerability in node:child Deno versions 2.7.0 through 2.9.7 on Windows contain a command injection vulnerability in node:child_process where shell arguments are escaped for the wrong shell type. Attackers can inject OS commands by passing untrusted arguments with the shell option, allowing arbitrary command execution with Deno process privileges.
nvd
CVE-2025-61787P3HIGHCVSS 8.1v>= 2.3.0, < 2.5.3fixed in 2.2.152025-10-08
CVE-2025-61787 [HIGH] CWE-77 CVE-2025-61787: Deno is a JavaScript, TypeScript, and WebAssembly runtime. Versions prior to 2.5.3 and 2.2.15 are vu Deno is a JavaScript, TypeScript, and WebAssembly runtime. Versions prior to 2.5.3 and 2.2.15 are vulnerable to Command Line Injection attacks on Windows when batch files are executed. In Windows, ``CreateProcess()`` always implicitly spawns ``cmd.exe`` if a batch file (.bat, .cmd, etc.) is being executed even if the application does not specify it via
nvd
CVE-2024-27933P3HIGHCVSS 8.8v= 1.39.02024-03-21
CVE-2024-27933 [HIGH] CWE-863 CVE-2024-27933: Deno is a JavaScript, TypeScript, and WebAssembly runtime. In version 1.39.0, use of raw file descri Deno is a JavaScript, TypeScript, and WebAssembly runtime. In version 1.39.0, use of raw file descriptors in `op_node_ipc_pipe()` leads to premature close of arbitrary file descriptors, allowing standard input to be re-opened as a different resource resulting in permission prompt bypass. Node child_process IPC relies on the JS side to pass the raw IPC
nvd
CVE-2026-44726P3CRITICALCVSS 9.1v>= 2.0.0, < 2.7.82026-06-23
CVE-2026-44726 [CRITICAL] CWE-319 CVE-2026-44726: Deno is a JavaScript, TypeScript, and WebAssembly runtime. From 2.0.0 until 2.7.8, a flaw in Deno's Deno is a JavaScript, TypeScript, and WebAssembly runtime. From 2.0.0 until 2.7.8, a flaw in Deno's Node.js tls compatibility layer could cause a TLS client to transmit application data in plaintext after a connection retry. When `autoSelectFamily was enabled and the first address-family attempt failed, the socket reinitialization path reused a sta
nvd
CVE-2026-22864P3CRITICALCVSS 9.8fixed in 2.5.62026-01-15
CVE-2026-22864 [CRITICAL] CWE-77 CVE-2026-22864: Deno is a JavaScript, TypeScript, and WebAssembly runtime. Before 2.5.6, a prior patch aimed to bloc Deno is a JavaScript, TypeScript, and WebAssembly runtime. Before 2.5.6, a prior patch aimed to block spawning Windows batch/shell files by returning an error when a spawned path’s extension matched .bat or .cmd. That check performs a case-sensitive comparison against lowercase literals and therefore can be bypassed when the extension uses alternat
nvd
CVE-2023-33966P3CRITICALCVSS 9.8vdeno = 1.34.0vdeno_runtime = 0.114.02023-05-31
CVE-2023-33966 [CRITICAL] CWE-269 CVE-2023-33966: Deno is a runtime for JavaScript and TypeScript. In deno 1.34.0 and deno_runtime 0.114.0, outbound H Deno is a runtime for JavaScript and TypeScript. In deno 1.34.0 and deno_runtime 0.114.0, outbound HTTP requests made using the built-in `node:http` or `node:https` modules are incorrectly not checked against the network permission allow list (`--allow-net`). Dependencies relying on these built-in modules are subject to the vulnerability too. User
nvd
CVE-2025-48935P3CRITICALCVSS 9.1v>= 2.2.0, < 2.2.52025-06-04
CVE-2025-48935 [CRITICAL] CWE-863 CVE-2025-48935: Deno is a JavaScript, TypeScript, and WebAssembly runtime. Starting in version 2.2.0 and prior to ve Deno is a JavaScript, TypeScript, and WebAssembly runtime. Starting in version 2.2.0 and prior to versions 2.2.5, it is possible to bypass Deno's permission read/write db permission check by using `ATTACH DATABASE` statement. Version 2.2.5 contains a patch for the issue.
nvd
CVE-2026-49402P3HIGHCVSS 8.1fixed in 2.7.102026-06-23
CVE-2026-49402 [HIGH] CWE-78 CVE-2026-49402: Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.10, Deno's node:child_proces Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.10, Deno's node:child_process implementation provided an escapeShellArg() helper used when callers passed shell: true to spawn / spawnSync / exec and friends. On Windows, the helper failed to quote arguments that contained cmd.exe metacharacters and did not neutralize % (which cmd.
nvd
CVE-2021-32619P3CRITICALCVSS 9.8fixed in 1.10.22021-05-28
CVE-2021-32619 [CRITICAL] CWE-285 CVE-2021-32619: Deno is a runtime for JavaScript and TypeScript that uses V8 and is built in Rust. In Deno versions Deno is a runtime for JavaScript and TypeScript that uses V8 and is built in Rust. In Deno versions 1.5.0 to 1.10.1, modules that are dynamically imported through `import()` or `new Worker` might have been able to bypass network and file system permission checks when statically importing other modules. The vulnerability has been patched in Deno rel
nvd
CVE-2024-27934P3HIGHCVSS 8.8v>= 1.36.2, < 1.40.32024-03-21
CVE-2024-27934 [HIGH] CWE-416 CVE-2024-27934: Deno is a JavaScript, TypeScript, and WebAssembly runtime. Starting in version 1.36.2 and prior to v Deno is a JavaScript, TypeScript, and WebAssembly runtime. Starting in version 1.36.2 and prior to version 1.40.3, use of inherently unsafe `*const c_void` and `ExternalPointer` leads to use-after-free access of the underlying structure, resulting in arbitrary code execution. Use of inherently unsafe `*const c_void` and `ExternalPointer` leads to use-
nvd
CVE-2024-34346P3CRITICALCVSS 9.0fixed in 1.43.02024-05-07
CVE-2024-34346 [CRITICAL] CWE-863 CVE-2024-34346: Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults. The Deno sandbox may Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults. The Deno sandbox may be unexpectedly weakened by allowing file read/write access to privileged files in various locations on Unix and Windows platforms. For example, reading `/proc/self/environ` may provide access equivalent to `--allow-env`, and writing `/proc/self/me
nvd
CVE-2024-27935P3HIGHCVSS 8.3v>= 1.35.1, < 1.36.32024-03-21
CVE-2024-27935 [HIGH] CWE-488 CVE-2024-27935: Deno is a JavaScript, TypeScript, and WebAssembly runtime. Starting in version 1.35.1 and prior to v Deno is a JavaScript, TypeScript, and WebAssembly runtime. Starting in version 1.35.1 and prior to version 1.36.3, a vulnerability in Deno's Node.js compatibility runtime allows for cross-session data contamination during simultaneous asynchronous reads from Node.js streams sourced from sockets or files. The issue arises from the re-use of a global bu
nvd
CVE-2023-28446P3HIGHCVSS 8.8v>= 1.8.0, < 1.31.22023-03-24
CVE-2023-28446 [HIGH] CWE-150 CVE-2023-28446: Deno is a simple, modern and secure runtime for JavaScript and TypeScript that uses V8 and is built Deno is a simple, modern and secure runtime for JavaScript and TypeScript that uses V8 and is built in Rust. Arbitrary program names without any ANSI filtering allows any malicious program to clear the first 2 lines of a `op_spawn_child` or `op_kill` prompt and replace it with any desired text. This works with any command on the respective platform, gi
nvd
CVE-2026-49401P3HIGHCVSS 8.4fixed in 2.7.142026-06-23
CVE-2026-49401 [HIGH] CWE-41 CVE-2026-49401: Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.14, Deno's permission system Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.14, Deno's permission system enforces filesystem and execution restrictions by comparing the requested path against the path supplied to --deny-read, --deny-write, --deny-run, or --deny-ffi. On macOS, that comparison was done at the raw-byte level while the APFS filesystem treats d
nvd
CVE-2026-22863P3HIGHCVSS 7.5fixed in 2.6.02026-01-15
CVE-2026-22863 [HIGH] CWE-325 CVE-2026-22863: Deno is a JavaScript, TypeScript, and WebAssembly runtime. Before 2.6.0, node:crypto doesn't finaliz Deno is a JavaScript, TypeScript, and WebAssembly runtime. Before 2.6.0, node:crypto doesn't finalize cipher. The vulnerability allows an attacker to have infinite encryptions. This can lead to naive attempts at brute forcing, as well as more refined attacks with the goal to learn the server secrets. This vulnerability is fixed in 2.6.0.
nvd
CVE-2024-32477P3HIGHCVSS 7.4fixed in 1.42.22024-04-18
CVE-2024-32477 [HIGH] CWE-78 CVE-2024-32477: Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults. By using ANSI escape Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults. By using ANSI escape sequences and a race between `libc::tcflush(0, libc::TCIFLUSH)` and reading standard input, it's possible to manipulate the permission prompt and force it to allow an unsafe action regardless of the user input. Some ANSI escape sequences act as a info r
nvd
CVE-2025-21620P3HIGHCVSS 7.5fixed in 2.1.22025-01-06
CVE-2025-21620 [HIGH] CWE-200 CVE-2025-21620: Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults. When you send a requ Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults. When you send a request with the Authorization header to one domain, and the response asks to redirect to a different domain, Deno'sfetch() redirect handling creates a follow-up redirect request that keeps the original Authorization header, leaking its content to that seco
nvd
Denoland Deno vulnerabilities | cvebase