Catalog / Deno

Deno security advisories

All 40 advisories Deno has published with an identifier, newest first. Severity is the one its publisher assigned, and the fix is the release the publisher named. Nothing on this page is our judgement.

Advisories
4040 carry a CVE
critical
4
high
19
medium
14
low
3
Fix in the archive
17of 40 matched to a release
Oldest
20 May 20215.3 years ago

23 of these point at a version older than anything the archive holds, so there is no release page to link. That is a gap in what was collected, not evidence that the fix does not exist. This page is a copy of what the publisher published, kept for reference. The authoritative source for a security question is the publisher, and an advisory missing from here is not evidence that none exists. What this page does and does not tell you sets out the limits in full.

Newest first

Every product
CVE-2026-49406medium

BYONM module resolution allows `package.json` main path traversal to bypass `--allow-read` restrictions

GHSA-968w-xfqw-vp9qFixed in 2.7.12
CVE-2026-49411medium

Deno Node TCPWrap numeric hostname aliases bypass --deny-net resolved-IP deny checks

GHSA-v8fw-85r8-5m23Fixed in 2.8.0
CVE-2026-49983medium

process.loadEnvFile() bypasses env permission checks and mutates process.env with only read access

GHSA-4c8g-jvcx-v4hvFixed in 2.8.1
CVE-2026-32260high

Command Injection via incomplete shell metacharacter blocklist in node:child_process (bypass of CVE-2026-27190 fix)

GHSA-4c96-w8v2-p28jFixed in 2.7.2
CVE-2026-27190high

Command Injection via Incomplete shell metacharacter blocklist in `node:child_process`

GHSA-hmh4-3xvx-q5hrFixed in 2.6.8
CVE-2026-22864high

Incomplete fix for command-injection prevention on Windows — case-insensitive extension bypass

GHSA-m3c4-prhw-mrx6Fixed in 2.5.6
CVE-2025-61786low

Deno.FsFile.prototype.stat and Deno.FsFile.prototype.statSyn --deny-read permission bypass

GHSA-qq26-84mh-26j9Fixed in 2.2.15
CVE-2025-61785low

Deno.FsFile.prototype.utime and Deno.FsFile.prototype.utimeSync --deny-write permission bypass

GHSA-vg2r-rmgp-cgqjFixed in 2.2.15
CVE-2024-21486medium

Exposure of sensitive information using static imports

GHSA-jv4x-jv3h-qff5Fixed in 2.0.0, not held here
CVE-2025-24015medium

AES GCM authentication tags are not verified

GHSA-2x3r-hwv5-p32xFixed in 2.1.7, not held here
CVE-2025-48935high

--allow-read / --allow-write permission bypass in `node:sqlite`

GHSA-8vxj-4cph-c596Fixed in 2.2.5, not held here
CVE-2025-48934medium

Deno.env.toObject() ignores the variables listed in --deny-env and returns all environment variables

GHSA-7w8p-chxq-2789Fixed in 2.1.13, not held here
CVE-2025-48888low

deno run with --allow-read and --deny-read flags results in allowed

GHSA-xqxc-x6p3-w683Fixed in 2.1.13, not held here
CVE-2025-21620high

fetch: Authorization headers not dropped when redirecting cross-origin

GHSA-f27p-cmv8-xhm6Fixed in 0.204.0, not held here
CVE-2024-32468medium

Improper neutralization of input during web page generation ("Cross-site Scripting") in deno_doc HTML generator

GHSA-qqwr-j9mm-fhw6Fixed in 0.119.0, not held here
CVE-2024-37150high

Private npm registry support used scope auth token for downloading tarballs

GHSA-rfc6-h225-3vxvFixed in 1.44.1, not held here
CVE-2024-34346high

Permission escalation via open of privileged files with missing `--deny` flag

GHSA-23rx-c3g5-hv9wFixed in 1.43.1, not held here
CVE-2024-32477high

Race condition when flushing input stream leads to permission prompt bypass

GHSA-95cj-3hr2-7j5jFixed in 1.42.2, not held here
CVE-2024-27936high

Interactive permission prompt spoofing via improper ANSI stripping

GHSA-m4pq-fv2w-6hrwFixed in 0.147.0, not held here
CVE-2024-27935high

Cross-Session Data Contamination in Deno's Node.js Compatibility Runtime

GHSA-wrqv-pf6j-mqjpFixed in 1.36.3, not held here
CVE-2024-27934medium

*const c_void / ExternalPointer unsoundness leading to use-after-free

GHSA-3j27-563v-28wf
CVE-2024-27933high

Arbitrary file descriptor close via `op_node_ipc_pipe()` leading to permission prompt bypass

GHSA-6q4w-9x56-rmwqFixed in 1.39.1, not held here
CVE-2024-27932medium

Improper suffix match testing for DENO_AUTH_TOKENS

GHSA-5frw-4rwq-xhcrFixed in 1.40.4, not held here
CVE-2024-27931medium

Insufficient permission checking in `Deno.makeTemp*` APIs

GHSA-hrqr-jv8w-v9jhFixed in 1.41.1, not held here
CVE-2023-33966high

Missing "--allow-net" permission check for built-in Node modules

GHSA-vc52-gwm3-8v2fFixed in 1.34.1, not held here
CVE-2023-28446high

Interactive `run` permission prompt spoofing via improper ANSI neutralization

GHSA-vq67-rp93-65qfFixed in 1.31.2, not held here
CVE-2023-26103medium

Regular Expression Denial of Service in Deno.upgradeWebSocket API

GHSA-jc97-h3h9-7xh6Fixed in 1.31.0, not held here
CVE-2023-28445critical

Improper handling of resizable ArrayBuffer in async built-in functions

GHSA-c25x-cm9x-qqgxFixed in 1.32.1, not held here
CVE-2023-22499high

Interactive permission prompt spoofing

GHSA-mc52-jpm2-cqh6Fixed in 1.29.3, not held here
CVE-2022-24783critical

Sandbox bypass leading to arbitrary code execution

GHSA-838h-jqp6-cf2fFixed in 1.20.3, not held here
CVE-2021-32619critical

Static imports inside dynamically imported modules do not adhere to permission checks

GHSA-xpwj-7v8q-mcgjFixed in 1.10.2, not held here