PT-2026-3145 · Deno · Deno

Davidebombelli

+2

·

Published

2026-01-15

·

Updated

2026-04-14

·

CVE-2026-22863

CVSS v4.0

9.2

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Deno versions prior to 2.6.0
Description Deno is a JavaScript, TypeScript, and WebAssembly runtime. A flaw in the node:crypto polyfill allows cryptographic handles to persist beyond their intended lifespan. This results in the possibility of infinite encryption rounds, potentially enabling attackers to attempt brute-force attacks or learn server secrets. The issue stems from the node:crypto module not finalizing ciphers correctly.
Recommendations Upgrade to Deno version 2.6.0 or newer.

Exploit

Fix

Weakness Enumeration

Related Identifiers

BDU:2026-00636
CVE-2026-22863
GHSA-5379-F5HF-W38V
JLSEC-2026-114

Affected Products

Deno