PT-2026-35035 · Julia · Deno Jll

Published

2026-04-14

·

Updated

2026-04-14

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Versions of the package deno before 1.31.0 are vulnerable to Regular Expression Denial of Service (ReDoS) due to the upgradeWebSocket function, which contains regexes in the form of /s*,s*/, used for splitting the Connection/Upgrade header. A specially crafted Connection/Upgrade header can be used to significantly slow down a web socket server.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

JLSEC-2026-101

Affected Products

Deno Jll