logo

Critical Deno Flaws Risk Secrets (CVE-2026-22863) & Execution (CVE-2026-22864)

ID: 5e91ffeb-e04c-5e46-8596-9dfc3049fff8

STIX ID: report--5e91ffeb-e04c-5e46-8596-9dfc3049fff8

Feed Name: securityonline.info

Threat Score
82/100

Date Published: 2026-01-19

Date Updated: 2026-04-23

Author: Ddos

...
...

Deno has two serious vulnerabilities: CVE-2026-22863 (critical, CVSS 9.2) in the node:crypto compatibility layer that fails to finalize ciphers and can leak server secrets or enable brute-force attacks, and CVE-2026-22864, a Windows subprocess/.bat handling bypass that allows argument injection and arbitrary code execution; proofs-of-concept are provided and users are urged to upgrade to Deno v2.6.0 or later.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.