CVEs we hold for Denoland
Records whose assigning authority named Denoland as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-55517Deno: Denial of service via non-ASCII bytes in WebSocket response headersdenoland deno
CVE-2026-49983Deno: process.loadEnvFile() bypasses env permission checks and mutates process.env with only read accessdenoland deno
CVE-2026-49411Deno Node TCPWrap numeric hostname aliases bypass --deny-net resolved-IP deny checksdenoland deno
CVE-2026-49406Deno: BYONM module resolution allows `package.json` main path traversal to bypass `--allow-read` restrictionsdenoland deno
CVE-2026-49401Deno Permission Bypass via Unicode Normalization Mismatch on macOS (APFS)denoland deno
CVE-2026-32260Command Injection via incomplete shell metacharacter blocklist in node:child_process (bypass of CVE-2026-27190 fix)denoland deno
CVE-2026-27190Deno has a Command Injection via Incomplete shell metacharacter blocklist in node:child_processdenoland deno
CVE-2026-22864Deno has an incomplete fix for command-injection prevention on Windows — case-insensitive extension bypassdenoland deno
CVE-2025-61787Deno is Vulnerable to Command Injection on Windows During Batch File Executiondenoland deno
CVE-2025-48934Deno.env.toObject() ignores the variables listed in --deny-env and returns all environment variablesdenoland deno
CVE-2024-52793XSS vulnerability in serveDir API of @std/http/file-server on POSIX systemsdenoland std
CVE-2024-37150Private npm registry support used scope auth token for downloading tarballsdenoland deno
CVE-2024-34346Deno contains a permission escalation via open of privileged files with missing `--deny` flagdenoland deno
CVE-2024-32477Race condition when flushing input stream leads to permission prompt bypassdenoland deno
CVE-2024-32468Improper neutralization of input during web page generation ("Cross-site Scripting") in deno_doc HTML generatordenoland deno
CVE-2024-27935Deno's Node.js Compatibility Runtime has Cross-Session Data Contaminationdenoland deno
CVE-2024-27933Deno arbitrary file descriptor close via `op_node_ipc_pipe()` leading to permission prompt bypassdenoland deno
CVE-2023-28446Deno is vulnerable to interactive `run` permission prompt spoofing via improper ANSI neutralizationdenoland deno
CVE-2021-32619Static imports inside dynamically imported modules do not adhere to permission checksdenoland deno
40 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.