PT-2026-3145 · Deno · Deno

·

CVE-2026-22863

·

Published

2026-01-15

·

Updated

2026-04-14

CVSS v4.0

9.2

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Deno versions prior to 2.6.0
Description Deno is a JavaScript, TypeScript, and WebAssembly runtime. A flaw in the node:crypto polyfill allows cryptographic handles to persist beyond their intended lifespan. This results in the possibility of infinite encryption rounds, potentially enabling attackers to attempt brute-force attacks or learn server secrets. The issue stems from the node:crypto module not finalizing ciphers correctly.
Recommendations Upgrade to Deno version 2.6.0 or newer.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-00636
CVE-2026-22863
GHSA-5379-F5HF-W38V
JLSEC-2026-114

Affected Products

Deno