Denoland Deno vulnerabilities
38 known vulnerabilities affecting denoland/deno.
Total CVEs
38
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL9HIGH13MEDIUM14LOW2
Vulnerabilities
Page 2 of 2
CVE-2026-49440P3HIGHCVSS 7.4fixed in 2.8.12026-06-23
CVE-2026-49440 [HIGH] CWE-325 CVE-2026-49440: Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, node:crypto.checkPrime(ca
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, node:crypto.checkPrime(candidate[, options][, callback]) and crypto.checkPrimeSync(candidate[, options]) ran no Miller-Rabin rounds at all when the caller left options.checks at its default of 0. In that mode, the only test applied to the candidate was trial division by the pri
nvd
CVE-2024-27931P3MEDIUMCVSS 6.5fixed in 1.41.12024-03-05
CVE-2024-27931 [MEDIUM] CWE-20 CVE-2024-27931: Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults. Insufficient validat
Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults. Insufficient validation of parameters in `Deno.makeTemp*` APIs would allow for creation of files outside of the allowed directories. This may allow the user to overwrite important files on the system that may affect other systems. A user may provide a prefix or suffix to
nvd
CVE-2023-22499P3HIGHCVSS 7.5v>= 1.9, < 1.29.32023-01-17
CVE-2023-22499 [HIGH] CWE-362 CVE-2023-22499: Deno is a runtime for JavaScript and TypeScript that uses V8 and is built in Rust. Multi-threaded pr
Deno is a runtime for JavaScript and TypeScript that uses V8 and is built in Rust. Multi-threaded programs were able to spoof interactive permission prompt by rewriting the prompt to suggest that program is waiting on user confirmation to unrelated action. A malicious program could clear the terminal screen after permission prompt was shown and write
nvd
CVE-2024-27936P4MEDIUMCVSS 6.5v>= 1.32.1, < 1.41.02024-03-21
CVE-2024-27936 [MEDIUM] CWE-150 CVE-2024-27936: Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults. Starting in version
Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults. Starting in version 1.32.1 and prior to version 1.41.0 of the deno library, maliciously crafted permission request can show the spoofed permission prompt by inserting a broken ANSI escape sequence into the request contents. Deno is stripping any ANSI escape sequences from
nvd
CVE-2024-37150P4MEDIUMCVSS 6.5v= 1.44.02024-06-06
CVE-2024-37150 [MEDIUM] CWE-200 CVE-2024-37150: An issue in `.npmrc` support in Deno 1.44.0 was discovered where Deno would send `.npmrc` credential
An issue in `.npmrc` support in Deno 1.44.0 was discovered where Deno would send `.npmrc` credentials for the scope to the tarball URL when the registry provided URLs for a tarball on a different domain. All users relying on .npmrc are potentially affected by this vulnerability if their private registry references tarball URLs at a different domain.
nvd
CVE-2026-49411P4MEDIUMCVSS 6.5fixed in 2.8.02026-06-23
CVE-2026-49411 [MEDIUM] CWE-284 CVE-2026-49411: Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.0, the Node.js compatibility
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.0, the Node.js compatibility TCP path checked the permission against the original hostname string before resolution and then did not re-check after resolution. A caller could therefore pass a numeric alias of an IP address (for example the decimal integer 2130706433 or the hex f
nvd
CVE-2025-24015P4MEDIUMCVSS 5.3v>= 1.46.0, < 2.1.72025-06-03
CVE-2025-24015 [MEDIUM] CWE-347 CVE-2025-24015: Deno is a JavaScript, TypeScript, and WebAssembly runtime. Versions 1.46.0 through 2.1.6 have an iss
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Versions 1.46.0 through 2.1.6 have an issue that affects AES-256-GCM and AES-128-GCM in Deno in which the authentication tag is not being validated. This means tampered ciphertexts or incorrect keys might not be detected, which breaks the guarantees expected from AES-GCM. Older versions of D
nvd
CVE-2026-49406P4MEDIUMCVSS 5.5fixed in 2.7.122026-06-23
CVE-2026-49406 [MEDIUM] CWE-22 CVE-2026-49406: Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.12, when Deno was run in BYO
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.12, when Deno was run in BYONM mode (nodeModulesDir: "manual"), the module resolver did not validate that a package's resolved entrypoint stayed within its node_modules// directory. A malicious package.json whose main field contained .. segments was able to resolve to an arbitrar
nvd
CVE-2025-48888P4MEDIUMCVSS 5.3v>= 1.41.3, < 2.1.13v>= 2.2.0, < 2.2.13+1 more2025-06-04
CVE-2025-48888 [MEDIUM] CWE-863 CVE-2025-48888: Deno is a JavaScript, TypeScript, and WebAssembly runtime. Starting in version 1.41.3 and prior to v
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Starting in version 1.41.3 and prior to versions 2.1.13, 2.2.13, and 2.3.2, `deno run --allow-read --deny-read main.ts` results in allowed, even though 'deny' should be stronger. The result is the same with all global unary permissions given as `--allow-* --deny-*`. This only affects a nonse
nvd
CVE-2025-48934P4MEDIUMCVSS 5.3fixed in 2.1.13v>= 2.2.0, < 2.2.132025-06-04
CVE-2025-48934 [MEDIUM] CWE-201 CVE-2025-48934: Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to versions 2.1.13 and 2.2.13, the
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to versions 2.1.13 and 2.2.13, the `Deno.env.toObject` method ignores any variables listed in the `--deny-env` option of the `deno run` command. When looking at the documentation of the `--deny-env` option this might lead to a false impression that variables listed in the option are imp
nvd
CVE-2024-32468P4MEDIUMCVSS 5.4vdeno_doc: < 0.119.0vdeno: < 1.42.02024-11-25
CVE-2024-32468 [MEDIUM] CWE-79 CVE-2024-32468: Deno is a runtime for JavaScript and TypeScript written in rust. Several cross-site scripting vulner
Deno is a runtime for JavaScript and TypeScript written in rust. Several cross-site scripting vulnerabilities existed in the `deno_doc` crate which lead to Self-XSS with deno doc --html. 1.) XSS in generated `search_index.js`, `deno_doc` outputs a JavaScript file for searching. However, the generated file used `innerHTML` on unsanitzed HTML input. 2.
nvd
CVE-2026-49983P4MEDIUMCVSS 5.2fixed in 2.8.12026-06-23
CVE-2026-49983 [MEDIUM] CWE-863 CVE-2026-49983: Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, environment access is gat
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, environment access is gated by the env permission. You can deny it with --deny-env, or restrict it to a specific allowlist with --allow-env=FOO,BAR. The expectation is that a program running without env permission cannot change process.env. process.loadEnvFile() (the Node-com
nvd
CVE-2026-49859P4MEDIUMCVSS 5.2fixed in 2.8.12026-06-23
CVE-2026-49859 [MEDIUM] CWE-693 CVE-2026-49859: Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, when fetch() was called,
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, when fetch() was called, Deno checked the destination hostname against --deny-net rules but did not re-check the IP addresses that hostname resolved to. An attacker-controlled script could use a specially crafted domain name that passes the hostname check yet resolves to a den
nvd
CVE-2026-49860P4MEDIUMCVSS 5.2fixed in 2.8.12026-06-23
CVE-2026-49860 [MEDIUM] CWE-918 CVE-2026-49860: Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, when a WebSocket connecti
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, when a WebSocket connection was opened, Deno checked the destination hostname against --deny-net rules but did not re-check the IP addresses that hostname resolved to. An attacker-controlled script could use a specially crafted domain name that passes the hostname check yet r
nvd
CVE-2024-27932P4MEDIUMCVSS 4.6v>= 1.8.0, < 1.40.42024-03-21
CVE-2024-27932 [MEDIUM] CWE-20 CVE-2024-27932: Deno is a JavaScript, TypeScript, and WebAssembly runtime. Starting in version 1.8.0 and prior to ve
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Starting in version 1.8.0 and prior to version 1.40.4, Deno improperly checks that an import specifier's hostname is equal to or a child of a token's hostname, which can cause tokens to be sent to servers they shouldn't be sent to. An auth token intended for `example[.]com` may be sent to `no
nvd
CVE-2026-55517P4MEDIUMCVSS 4.3fixed in 2.7.52026-06-23
CVE-2026-55517 [MEDIUM] CWE-248 CVE-2026-55517: Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.5, a Deno program that opens
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.5, a Deno program that opens a client WebSocket connection could be crashed by the remote server. While handling the WebSocket handshake response, Deno parsed the Sec-WebSocket-Protocol and Sec-WebSocket-Extensions response headers in a way that assumed their bytes were always p
nvd
CVE-2025-61785P4LOWCVSS 3.3v>= 2.3.0, < 2.5.3fixed in 2.2.152025-10-08
CVE-2025-61785 [LOW] CWE-266 CVE-2025-61785: Deno is a JavaScript, TypeScript, and WebAssembly runtime. In versions prior to 2.5.3 and 2.2.15, `D
Deno is a JavaScript, TypeScript, and WebAssembly runtime. In versions prior to 2.5.3 and 2.2.15, `Deno.FsFile.prototype.utime` and `Deno.FsFile.prototype.utimeSync` are not limited by the permission model check `--deny-write=./`. It's possible to change to change the access (`atime`) and modification (`mtime`) times on the file stream resource even wh
nvd
CVE-2025-61786P4LOWCVSS 3.3v>= 2.3.0, < 2.5.3fixed in 2.2.152025-10-08
CVE-2025-61786 [LOW] CWE-269 CVE-2025-61786: Deno is a JavaScript, TypeScript, and WebAssembly runtime. In versions prior to 2.5.3 and 2.2.15, `D
Deno is a JavaScript, TypeScript, and WebAssembly runtime. In versions prior to 2.5.3 and 2.2.15, `Deno.FsFile.prototype.stat` and `Deno.FsFile.prototype.statSync` are not limited by the permission model check `--deny-read=./`. It's possible to retrieve stats from files that the user do not have explicit read access to (the script is executed with `--d
nvd
← Previous2 / 2