-
Notifications
You must be signed in to change notification settings - Fork 5.7k
Security: denoland/deno
Security Navigation
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
deno run with --allow-read and --deny-read flags results in allowedGHSA-xqxc-x6p3-w683 published
Jun 3, 2025 by bartlomiejuLow -
Deno.env.toObject() ignores the variables listed in --deny-env and returns all environment variablesGHSA-7w8p-chxq-2789 published
Jun 3, 2025 by bartlomiejuModerate -
--allow-read / --allow-write permission bypass in `node:sqlite`GHSA-8vxj-4cph-c596 published
Jun 3, 2025 by bartlomiejuHigh -
AES GCM authentication tags are not verifiedGHSA-2x3r-hwv5-p32x published
Jun 3, 2025 by bartlomiejuModerate -
fetch: Authorization headers not dropped when redirecting cross-originGHSA-f27p-cmv8-xhm6 published
Jan 6, 2025 by bartlomiejuHigh -
Private npm registry support used scope auth token for downloading tarballsGHSA-rfc6-h225-3vxv published
Jun 6, 2024 by bartlomiejuHigh -
Improper neutralization of input during web page generation ("Cross-site Scripting") in deno_doc HTML generatorGHSA-qqwr-j9mm-fhw6 published
Nov 25, 2024 by bartlomiejuModerate -
Race condition when flushing input stream leads to permission prompt bypassGHSA-95cj-3hr2-7j5j published
Apr 18, 2024 by mmastracHigh -
Permission escalation via open of privileged files with missing `--deny` flagGHSA-23rx-c3g5-hv9w published
May 7, 2024 by mmastracHigh -
Insufficient permission checking in `Deno.makeTemp*` APIsGHSA-hrqr-jv8w-v9jh published
Mar 5, 2024 by mmastracModerate