Denial of service via non-ASCII bytes in WebSocket response headers
Deno security advisories
All 40 advisories Deno has published with an identifier, newest first. Severity is the one its publisher assigned, and the fix is the release the publisher named. Nothing on this page is our judgement.
- Advisories
- 4040 carry a CVE
- critical
- 4
- high
- 19
- medium
- 14
- low
- 3
- Fix in the archive
- 17of 40 matched to a release
- Oldest
- 20 May 20215.3 years ago
23 of these point at a version older than anything the archive holds, so there is no release page to link. That is a gap in what was collected, not evidence that the fix does not exist. This page is a copy of what the publisher published, kept for reference. The authoritative source for a security question is the publisher, and an advisory missing from here is not evidence that none exists. What this page does and does not tell you sets out the limits in full.
Newest first
Every productCommand Injection via spawnSync & spawn on Windows
TLS retry copies stale upgrade hook, risking plaintext traffic
BYONM module resolution allows `package.json` main path traversal to bypass `--allow-read` restrictions
Miller-Rabin Primality Test Allows Zero Rounds
Deno Permission Bypass via Unicode Normalization Mismatch on macOS (APFS)
Deno Node TCPWrap numeric hostname aliases bypass --deny-net resolved-IP deny checks
`fetch()` API sandbox bypass via missing DNS resolution check
WebSocket API sandbox bypass via missing post-DNS check
process.loadEnvFile() bypasses env permission checks and mutates process.env with only read access
Command Injection via incomplete shell metacharacter blocklist in node:child_process (bypass of CVE-2026-27190 fix)
Command Injection via Incomplete shell metacharacter blocklist in `node:child_process`
Incomplete fix for command-injection prevention on Windows — case-insensitive extension bypass
`node:crypto` doesn't finalize cipher
Deno.FsFile.prototype.stat and Deno.FsFile.prototype.statSyn --deny-read permission bypass
Deno.FsFile.prototype.utime and Deno.FsFile.prototype.utimeSync --deny-write permission bypass
Command Injection on Windows
Exposure of sensitive information using static imports
AES GCM authentication tags are not verified
--allow-read / --allow-write permission bypass in `node:sqlite`
Deno.env.toObject() ignores the variables listed in --deny-env and returns all environment variables
deno run with --allow-read and --deny-read flags results in allowed
fetch: Authorization headers not dropped when redirecting cross-origin
Improper neutralization of input during web page generation ("Cross-site Scripting") in deno_doc HTML generator
Private npm registry support used scope auth token for downloading tarballs
Permission escalation via open of privileged files with missing `--deny` flag
Race condition when flushing input stream leads to permission prompt bypass
Interactive permission prompt spoofing via improper ANSI stripping
Cross-Session Data Contamination in Deno's Node.js Compatibility Runtime
*const c_void / ExternalPointer unsoundness leading to use-after-free
Arbitrary file descriptor close via `op_node_ipc_pipe()` leading to permission prompt bypass
Improper suffix match testing for DENO_AUTH_TOKENS
Insufficient permission checking in `Deno.makeTemp*` APIs
Missing "--allow-net" permission check for built-in Node modules
Interactive `run` permission prompt spoofing via improper ANSI neutralization
Regular Expression Denial of Service in Deno.upgradeWebSocket API
Improper handling of resizable ArrayBuffer in async built-in functions
Interactive permission prompt spoofing
Sandbox bypass leading to arbitrary code execution
Static imports inside dynamically imported modules do not adhere to permission checks