Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Deno

First CVE: May 28, 2021Active for: 5 yearsTotal CVEs: 39
39.7
VTI Score
Medium

Deno is a modern JavaScript and TypeScript runtime that presents a narrowly scoped but strategically important product footprint centered on its core runtime, standard modules, and serialization components. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes, concentrated in weakness classes including incorrect authorization, OS command injection, improper privilege management, race conditions, and improper input validation—issues characteristic of a runtime environment's need to enforce security boundaries between untrusted code and the host system. The exposure reflects structural risks inherent to Deno's design goals around sandboxing and permission controls, where flaws in enforcement can undermine the entire security model; defenders relying on Deno's isolation guarantees should track and apply its advisories promptly. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.

FAUCET AI Generated
39
Total CVEs
More Total CVEs than 98% of tracked vendors
1.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
7.4
Avg CVSS Score
Higher Avg CVSS Score than 56% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Deno over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 28, 2021
5 years ago
Most Recent CVE
Jun 23, 2026
31 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (39 CVEs).

39 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-44726CRITICAL
Deno is a JavaScript, TypeScript, and WebAssembly runtime. From 2.0.0 until 2.7.8, a flaw in Deno's Node.js tls compatibility layer could cause a TLS client to transmit application
Jun 23, 20269.134NONO
CVE-2026-49402HIGH
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.10, Deno's node:child_process implementation provided an escapeShellArg() helper used when callers passed sh
Jun 23, 20268.134NONO
CVE-2026-22864CRITICAL
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Before 2.5.6, a prior patch aimed to block spawning Windows batch/shell files by returning an error when a spawned path’s
Jan 15, 20269.833NONO
CVE-2026-49401HIGH
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.14, Deno's permission system enforces filesystem and execution restrictions by comparing the requested path
Jun 23, 20268.432NONO
CVE-2026-27190CRITICAL
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.6.8, a command injection vulnerability exists in Deno's node:child_process implementation. This vulnerability
Feb 20, 20269.832NONO
CVE-2026-49440HIGH
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, node:crypto.checkPrime(candidate[, options][, callback]) and crypto.checkPrimeSync(candidate[, options])
Jun 23, 20267.431NONO
CVE-2026-32260CRITICAL
Deno is a JavaScript, TypeScript, and WebAssembly runtime. From 2.7.0 to 2.7.1, A command injection vulnerability exists in Deno's node:child_process polyfill (shell: true mode) t
Mar 12, 20269.831NONO
CVE-2022-24783CRITICAL
Deno is a runtime for JavaScript and TypeScript. The versions of Deno between release 1.18.0 and 1.20.2 (inclusive) are vulnerable to an attack where a malicious actor controlling
Mar 25, 202210.031NONO
CVE-2021-42139CRITICAL
Deno Standard Modules before 0.107.0 allows Code Injection via an untrusted YAML file in certain configurations.
Oct 11, 20219.831NONO
CVE-2023-28445CRITICAL
Deno is a runtime for JavaScript and TypeScript that uses V8 and is built in Rust. Resizable ArrayBuffers passed to asynchronous functions that are shrunk during the asynchronous o
Mar 24, 20239.830NONO
View all 39 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products39 CVEs
33%
33%
28%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local11 (28.2%)
Network27 (69.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (2.6%)
Attack Complexity
Low34 (87.2%)
High5 (12.8%)
Unknown0 (0.0%)
User Interaction
None33 (84.6%)
Unknown0 (0.0%)
Required6 (15.4%)
Privileges Required
Low14 (35.9%)
High0 (0.0%)
None25 (64.1%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (39 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Deno.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Deno — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Deno's Products

View all 3 CNAs →

Top CWEs