Vulnerability index

Browse CVEs

35 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Deno MEDIUM 5.2
CVE-2026-49860

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, when a WebSocket connection was opened, Deno checked the destination hostn…

Fix: 2.8.1+
Fix from $1,600 2026-06-23
Deno MEDIUM 5.2
CVE-2026-49983

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, environment access is gated by the env permission. You can deny it with --…

Fix: 2.8.1+
Fix from $1,600 2026-06-23
Deno HIGH 8.4
CVE-2026-49401

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.14, Deno's permission system enforces filesystem and execution restrictions b…

Fix: 2.7.14+
Fix from $1,950 2026-06-23
Deno HIGH 8.1
CVE-2026-49402

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.10, Deno's node:child_process implementation provided an escapeShellArg() hel…

Fix: 2.7.10+
Fix from $1,950 2026-06-23
Deno HIGH 7.4
CVE-2026-49440

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, node:crypto.checkPrime(candidate[, options][, callback]) and crypto.checkP…

Fix: 2.8.1+
Fix from $1,950 2026-06-23
Deno MEDIUM 6.5
CVE-2026-49411

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.0, the Node.js compatibility TCP path checked the permission against the orig…

Fix: 2.8.0+
Fix from $1,600 2026-06-23
Deno MEDIUM 5.5
CVE-2026-49406

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.12, when Deno was run in BYONM mode (nodeModulesDir: "manual"), the module re…

Fix: 2.7.12+
Fix from $1,600 2026-06-23
Deno MEDIUM 5.2
CVE-2026-49859

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, when fetch() was called, Deno checked the destination hostname against --d…

Fix: 2.8.1+
Fix from $1,600 2026-06-23
Deno CRITICAL 9.1
CVE-2026-44726

Deno is a JavaScript, TypeScript, and WebAssembly runtime. From 2.0.0 until 2.7.8, a flaw in Deno's Node.js tls compatibility layer could cause a TLS…

Fix: 2.7.8+
Fix from $2,300 2026-06-23
Deno CRITICAL 9.8
CVE-2026-32260

Deno is a JavaScript, TypeScript, and WebAssembly runtime. From 2.7.0 to 2.7.1, A command injection vulnerability exists in Deno's node:child_proces…

Fix: 2.7.2+
Fix from $2,300 2026-03-12
Deno CRITICAL 9.8
CVE-2026-27190

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.6.8, a command injection vulnerability exists in Deno's node:child_process impl…

Fix: 2.6.8+
Fix from $2,300 2026-02-20
Deno CRITICAL 9.8
CVE-2026-22864

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Before 2.5.6, a prior patch aimed to block spawning Windows batch/shell files by returning…

Fix: 2.5.6+
Fix from $2,300 2026-01-15
Deno HIGH 7.5
CVE-2026-22863

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Before 2.6.0, node:crypto doesn't finalize cipher. The vulnerability allows an attacker to…

Fix: 2.6.0+
Fix from $1,950 2026-01-15
Deno HIGH 8.1
CVE-2025-61787

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Versions prior to 2.5.3 and 2.2.15 are vulnerable to Command Line Injection attacks on Win…

Fix: 2.5.3+
Fix from $1,950 2025-10-08
Deno CRITICAL 9.1
CVE-2025-48935

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Starting in version 2.2.0 and prior to versions 2.2.5, it is possible to bypass Deno's per…

Fix: 2.2.5+
Fix from $2,300 2025-06-04
Deno MEDIUM 5.3
CVE-2025-48934

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to versions 2.1.13 and 2.2.13, the `Deno.env.toObject` method ignores any variables …

Fix: 2.1.13 / 2.2.13+
Fix from $1,600 2025-06-04
Deno MEDIUM 5.3
CVE-2025-48888

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Starting in version 1.41.3 and prior to versions 2.1.13, 2.2.13, and 2.3.2, `deno run --al…

Fix: 2.1.13 / 2.2.13+
Fix from $1,600 2025-06-04
Deno MEDIUM 5.3
CVE-2025-24015

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Versions 1.46.0 through 2.1.6 have an issue that affects AES-256-GCM and AES-128-GCM in De…

Fix: 2.1.7+
Fix from $1,600 2025-06-03
Deno MEDIUM 6.5
CVE-2024-37150

An issue in `.npmrc` support in Deno 1.44.0 was discovered where Deno would send `.npmrc` credentials for the scope to the tarball URL when the regis…

Patch available
Fix from $1,600 2024-06-06
Deno CRITICAL 9.0
CVE-2024-34346

Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults. The Deno sandbox may be unexpectedly weakened by allowing file read/w…

Fix: 1.43.1+
Fix from $2,300 2024-05-07
Deno HIGH 7.4
CVE-2024-32477

Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults. By using ANSI escape sequences and a race between `libc::tcflush(0, l…

Fix: 1.42.2+
Fix from $1,950 2024-04-18
Deno HIGH 8.8
CVE-2024-27933

Deno is a JavaScript, TypeScript, and WebAssembly runtime. In version 1.39.0, use of raw file descriptors in `op_node_ipc_pipe()` leads to premature …

Patch available
Fix from $1,950 2024-03-21
Deno HIGH 8.8
CVE-2024-27934

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Starting in version 1.36.2 and prior to version 1.40.3, use of inherently unsafe `*const c…

Fix: 1.40.3+
Fix from $1,950 2024-03-21
Deno HIGH 8.3
CVE-2024-27935

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Starting in version 1.35.1 and prior to version 1.36.3, a vulnerability in Deno's Node.js …

Fix: 1.36.3+
Fix from $1,950 2024-03-21
Deno Runtime MEDIUM 6.5
CVE-2024-27936

Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults. Starting in version 1.32.1 and prior to version 1.41.0 of the deno li…

Fix: 0.147.0 / 1.41.0+
Fix from $1,600 2024-03-21
Deno MEDIUM 6.5
CVE-2024-27931

Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults. Insufficient validation of parameters in `Deno.makeTemp*` APIs would …

Fix: 1.41.1+
Fix from $1,600 2024-03-05
Deno Runtime CRITICAL 9.8
CVE-2023-33966

Deno is a runtime for JavaScript and TypeScript. In deno 1.34.0 and deno_runtime 0.114.0, outbound HTTP requests made using the built-in `node:http` …

Mitigation only
Fix from $2,300 2023-05-31
Deno HIGH 8.8
CVE-2023-28446

Deno is a simple, modern and secure runtime for JavaScript and TypeScript that uses V8 and is built in Rust. Arbitrary program names without any ANSI…

Fix: 1.31.2+
Fix from $1,950 2023-03-24
Deno Runtime CRITICAL 9.8
CVE-2023-28445

Deno is a runtime for JavaScript and TypeScript that uses V8 and is built in Rust. Resizable ArrayBuffers passed to asynchronous functions that are s…

Patch available
Fix from $2,300 2023-03-24
Deno HIGH 7.5
CVE-2023-26103

Versions of the package deno before 1.31.0 are vulnerable to Regular Expression Denial of Service (ReDoS) due to the upgradeWebSocket function, which…

Fix: 1.31.0+
Fix from $1,950 2023-02-25