-
Notifications
You must be signed in to change notification settings - Fork 5.7k
Security: denoland/deno
Security Navigation
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Improper suffix match testing for DENO_AUTH_TOKENSGHSA-5frw-4rwq-xhcr published
Mar 5, 2024 by mmastracModerate -
Exposure of sensitive information using static importsGHSA-jv4x-jv3h-qff5 published
Jun 3, 2025 by bartlomiejuModerate -
Arbitrary file descriptor close via `op_node_ipc_pipe()` leading to permission prompt bypassGHSA-6q4w-9x56-rmwq published
Mar 5, 2024 by mmastracHigh -
*const c_void / ExternalPointer unsoundness leading to use-after-freeGHSA-3j27-563v-28wf published
Mar 5, 2024 by mmastracModerate -
Cross-Session Data Contamination in Deno's Node.js Compatibility RuntimeGHSA-wrqv-pf6j-mqjp published
Mar 5, 2024 by mmastracHigh -
Missing "--allow-net" permission check for built-in Node modulesGHSA-vc52-gwm3-8v2f published
May 30, 2023 by bartlomiejuHigh -
Interactive permission prompt spoofing via improper ANSI strippingGHSA-m4pq-fv2w-6hrw published
Mar 5, 2024 by mmastracHigh -
Improper handling of resizable ArrayBuffer in async built-in functionsGHSA-c25x-cm9x-qqgx published
Mar 23, 2023 by lucacasonatoCritical -
Regular Expression Denial of Service in Deno.upgradeWebSocket APIGHSA-jc97-h3h9-7xh6 published
Mar 23, 2023 by bartlomiejuModerate -
Interactive `run` permission prompt spoofing via improper ANSI neutralizationGHSA-vq67-rp93-65qf published
Mar 23, 2023 by bartlomiejuHigh