Deno is a modern JavaScript and TypeScript runtime that presents a narrowly scoped but strategically important product footprint centered on its core runtime, standard modules, and serialization components. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes, concentrated in weakness classes including incorrect authorization, OS command injection, improper privilege management, race conditions, and improper input validation—issues characteristic of a runtime environment's need to enforce security boundaries between untrusted code and the host system. The exposure reflects structural risks inherent to Deno's design goals around sandboxing and permission controls, where flaws in enforcement can undermine the entire security model; defenders relying on Deno's isolation guarantees should track and apply its advisories promptly. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Deno over time
Signals from CVEs in this vendor scope (39 CVEs).
39 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-44726CRITICAL Deno is a JavaScript, TypeScript, and WebAssembly runtime. From 2.0.0 until 2.7.8, a flaw in Deno's Node.js tls compatibility layer could cause a TLS client to transmit application | Jun 23, 2026 | 9.1 | 34 | NO | NO |
CVE-2026-49402HIGH Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.10, Deno's node:child_process implementation provided an escapeShellArg() helper used when callers passed sh | Jun 23, 2026 | 8.1 | 34 | NO | NO |
CVE-2026-22864CRITICAL Deno is a JavaScript, TypeScript, and WebAssembly runtime. Before 2.5.6, a prior patch aimed to block spawning Windows batch/shell files by returning an error when a spawned path’s | Jan 15, 2026 | 9.8 | 33 | NO | NO |
CVE-2026-49401HIGH Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.14, Deno's permission system enforces filesystem and execution restrictions by comparing the requested path | Jun 23, 2026 | 8.4 | 32 | NO | NO |
CVE-2026-27190CRITICAL Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.6.8, a command injection vulnerability exists in Deno's node:child_process implementation. This vulnerability | Feb 20, 2026 | 9.8 | 32 | NO | NO |
CVE-2026-49440HIGH Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, node:crypto.checkPrime(candidate[, options][, callback]) and crypto.checkPrimeSync(candidate[, options]) | Jun 23, 2026 | 7.4 | 31 | NO | NO |
CVE-2026-32260CRITICAL Deno is a JavaScript, TypeScript, and WebAssembly runtime. From 2.7.0 to 2.7.1, A command injection vulnerability exists in Deno's node:child_process polyfill (shell: true mode) t | Mar 12, 2026 | 9.8 | 31 | NO | NO |
CVE-2022-24783CRITICAL Deno is a runtime for JavaScript and TypeScript. The versions of Deno between release 1.18.0 and 1.20.2 (inclusive) are vulnerable to an attack where a malicious actor controlling | Mar 25, 2022 | 10.0 | 31 | NO | NO |
CVE-2021-42139CRITICAL Deno Standard Modules before 0.107.0 allows Code Injection via an untrusted YAML file in certain configurations. | Oct 11, 2021 | 9.8 | 31 | NO | NO |
CVE-2023-28445CRITICAL Deno is a runtime for JavaScript and TypeScript that uses V8 and is built in Rust. Resizable ArrayBuffers passed to asynchronous functions that are shrunk during the asynchronous o | Mar 24, 2023 | 9.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (39 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Deno.
Media articles that mention a CVE ID that affects a product developed by Deno — matched by CVE ID, not by vendor name.