CVE Tools

Denoland

20 CVEs tracked since 2024. Since Mar 2024, none of them reached CISA KEV.

Denoland CVEs per month

Mar 2024 to Jun 2026. Point at a month, or focus the strip and use the arrow keys.
Denoland CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2024-0360
2024-04null or fewer
2024-05null or fewer
2024-06null or fewer
2024-07null or fewer
2024-08null or fewer
2024-09null or fewer
2024-10null or fewer
2024-11null or fewer
2024-12null or fewer
2025-01null or fewer
2025-02null or fewer
2025-03null or fewer
2025-04null or fewer
2025-05null or fewer
2025-0640
2025-07null or fewer
2025-08null or fewer
2025-09null or fewer
2025-10null or fewer
2025-11null or fewer
2025-12null or fewer
2026-01null or fewer
2026-02null or fewer
2026-03null or fewer
2026-04null or fewer
2026-05null or fewer
2026-06100

Products

The products that kept showing up in Denoland's monthly top three, with their CVEs summed over those months.

  1. Deno203 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Denoland.

  1. CVE-2026-55517Deno: Denial of service via non-ASCII bytes in WebSocket response headers4.3
  2. CVE-2026-44726Deno: TLS retry copies stale upgrade hook, risking plaintext traffic7.4
  3. CVE-2026-49401Deno Permission Bypass via Unicode Normalization Mismatch on macOS (APFS)7.3
  4. CVE-2026-49402Deno: Command Injection via spawnSync & spawn on Windows8.1
  5. CVE-2026-49406Deno: BYONM module resolution allows `package.json` main path traversal to bypass `--allow-read` restrictions5.5
  6. CVE-2026-49411Deno Node TCPWrap numeric hostname aliases bypass --deny-net resolved-IP deny checks6.5
  7. CVE-2026-49983Deno: process.loadEnvFile() bypasses env permission checks and mutates process.env with only read access5.2
  8. CVE-2026-49860Deno: WebSocket API sandbox bypass via missing post-DNS check5.2
  9. CVE-2026-49859Deno: `fetch()` API sandbox bypass via missing DNS resolution check5.2
  10. CVE-2026-49440Deno: Miller-Rabin Primality Test Allows Zero Rounds7.4
  11. CVE-2026-32260Command Injection via incomplete shell metacharacter blocklist in node:child_process (bypass of CVE-2026-27190 fix)8.1
  12. CVE-2026-27190Deno has a Command Injection via Incomplete shell metacharacter blocklist in node:child_process8.1
  13. CVE-2026-22864Deno has an incomplete fix for command-injection prevention on Windows — case-insensitive extension bypass8.1
  14. CVE-2026-22863Deno node:crypto doesn't finalize cipher7.5
  15. CVE-2025-61787Deno is Vulnerable to Command Injection on Windows During Batch File Execution8.1

The record

Peak rank
#130 in Mar 2024
Busiest month shown
Jun 2026, 10 CVEs
Months with a KEV entry
0 since Mar 2024
Monthly snapshots
3 since 2024
Denoland's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store