Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

deno — Vulnerabilities & Security Advisories 39

All 39 CVE vulnerabilities found in deno, with AI-generated Chinese analysis, references, and POCs.

This page aggregates Common Weakness Enumeration (CWE) vulnerabilities associated with the Deno JavaScript and TypeScript runtime. It collects security issues affecting Deno across multiple major releases, covering the period from its initial stable release through to recent updates in 2024. This scope ensures that both legacy risks and contemporary threats are documented for comprehensive analysis. Visitors can use this resource to track Deno’s security advisories and understand the historical context of specific weakness classes within the runtime environment. By examining the chronological list of disclosed vulnerabilities, users can identify patterns in how Deno addresses security flaws over time. This includes looking up the product’s vulnerability history to assess the effectiveness of past patches and the overall security posture of the software. The data is organized to help developers and security professionals evaluate potential risks when integrating Deno into their applications. Understanding these vulnerabilities allows for better risk management and more informed decisions regarding dependency updates. The page serves as a centralized reference point for security researchers interested in the ecosystem surrounding Deno, providing a clear view of known issues without the noise of marketing materials. It is designed for technical audiences who require precise, factual information about security defects. Access to this aggregated data supports proactive defense strategies and aids in the maintenance of secure development practices. Users are encouraged to review each entry carefully to understand the specific impact and remediation steps required for their particular use cases.

Vendor: denoland

CVE IDTitleCVSSSeverityPublished
CVE-2026-55517 Deno: Denial of service via non-ASCII bytes in WebSocket response headers CWE-248 4.3 Medium2026-06-23
CVE-2026-44726 Deno: TLS retry copies stale upgrade hook, risking plaintext traffic CWE-319 7.4 High2026-06-23
CVE-2026-49401 Deno Permission Bypass via Unicode Normalization Mismatch on macOS (APFS) CWE-41 7.3 High2026-06-23
CVE-2026-49402 Deno: Command Injection via spawnSync & spawn on Windows CWE-78 8.1 High2026-06-23
CVE-2026-49406 Deno: BYONM module resolution allows `package.json` main path traversal to bypass `--allow-read` restrictions CWE-22 5.5 Medium2026-06-23
CVE-2026-49411 Deno Node TCPWrap numeric hostname aliases bypass --deny-net resolved-IP deny checks CWE-284 6.5 Medium2026-06-23
CVE-2026-49983 Deno: process.loadEnvFile() bypasses env permission checks and mutates process.env with only read access CWE-863 5.2 Medium2026-06-23
CVE-2026-49860 Deno: WebSocket API sandbox bypass via missing post-DNS check CWE-918 5.2 Medium2026-06-23
CVE-2026-49859 Deno: `fetch()` API sandbox bypass via missing DNS resolution check CWE-693 5.2 Medium2026-06-23
CVE-2026-49440 Deno: Miller-Rabin Primality Test Allows Zero Rounds CWE-325 7.4 High2026-06-23
CVE-2026-32260 Command Injection via incomplete shell metacharacter blocklist in node:child_process (bypass of CVE-2026-27190 fix) CWE-78 8.1 High2026-03-12
CVE-2026-27190 Deno has a Command Injection via Incomplete shell metacharacter blocklist in node:child_process CWE-78 8.1 High2026-02-20
CVE-2026-22864 Deno has an incomplete fix for command-injection prevention on Windows — case-insensitive extension bypass CWE-77 8.1 High2026-01-15
CVE-2026-22863 Deno node:crypto doesn't finalize cipher CWE-325 7.5 -2026-01-15
CVE-2025-61787 Deno is Vulnerable to Command Injection on Windows During Batch File Execution CWE-77 8.1 High2025-10-08
CVE-2025-61786 Deno's --deny-read check does not prevent permission bypass CWE-269 3.3 Low2025-10-08
CVE-2025-61785 Deno's --deny-write check does not prevent permission bypass CWE-266 5.3AIMediumAI2025-10-08
CVE-2025-48935 Deno has --allow-read / --allow-write permission bypass in `node:sqlite` CWE-863 8.1AIHighAI2025-06-04
CVE-2025-48934 Deno.env.toObject() ignores the variables listed in --deny-env and returns all environment variables CWE-201 7.5AIHighAI2025-06-04
CVE-2025-48888 Deno run with --allow-read and --deny-read flags results in allowed CWE-863 7.1AIHighAI2025-06-04
CVE-2025-24015 Deno's AES GCM authentication tags are not verified CWE-347 9.8AICriticalAI2025-06-03
CVE-2025-21620 Deno's authorization headers not dropped when redirecting cross-origin CWE-200 7.5 High2025-01-06
CVE-2024-32468 Improper neutralization of input during web page generation ("Cross-site Scripting") in deno_doc HTML generator CWE-79 5.4 Medium2024-11-25
CVE-2024-37150 Private npm registry support used scope auth token for downloading tarballs CWE-200 7.6 High2024-06-06
CVE-2024-34346 Deno contains a permission escalation via open of privileged files with missing `--deny` flag CWE-863 8.5 High2024-05-07
CVE-2024-32477 Race condition when flushing input stream leads to permission prompt bypass CWE-78 7.7 High2024-04-18
CVE-2024-27936 Deno interactive permission prompt spoofing via improper ANSI stripping CWE-150 8.8 High2024-03-06
CVE-2024-27935 Deno's Node.js Compatibility Runtime has Cross-Session Data Contamination CWE-488 7.2 High2024-03-06
CVE-2024-27934 *const c_void / ExternalPointer unsoundness leading to use-after-free CWE-416 8.4 High2024-03-06
CVE-2024-27933 Deno arbitrary file descriptor close via `op_node_ipc_pipe()` leading to permission prompt bypass CWE-863 8.3 High2024-03-06

All 39 known CVE vulnerabilities affecting deno with full Chinese analysis, references, and POCs where available.