Executive brief
Deno is a software runtime used to execute JavaScript and TypeScript applications. A security flaw allowed malicious or compromised scripts to bypass network security restrictions intended to block access to specific internal servers or sensitive local addresses. This could allow an attacker to access private data or internal services that were supposed to be isolated from the application.
Technical details
A protection mechanism failure (CWE-693) and Server-Side Request Forgery (SSRF) vulnerability exists in Deno's fetch() implementation. While Deno checks the initial hostname against --deny-net blocklists, it fails to perform a post-resolution check on the resulting IP addresses. An attacker can use a DNS rebinding-style attack or a specially crafted domain that resolves to a restricted IP (such as 127.0.0.1 or internal metadata services) to bypass the sandbox. This allows code running with restricted network permissions to reach unauthorized destinations. The issue is resolved in version 2.8.1 by implementing mandatory IP-level validation after DNS resolution.
Affected products
- denoland Deno < 2.8.1
Timeline
- 2026-05-27: advisory: GitHub advisory published by maintainers
- 2026-06-23: disclosed: NVD publication date
- 2026-06-23: patched: Fix confirmed in version 2.8.1