Junglewise Threat Intelligence

CVE-2026-49860: Deno sandbox bypass via missing post-DNS check in WebSocket API

CVE-2026-49860 · Severity: medium · CVSS 5.2 · Published 2026-06-23

Technologies: deno (crates.io). Vendors: crates.io.

Executive brief

Deno is a software runtime used to execute JavaScript and TypeScript applications. A security flaw in its WebSocket implementation allowed malicious or untrusted scripts to bypass network restrictions intended to block access to specific internal servers or sensitive local addresses. This could allow an attacker to communicate with restricted internal services, potentially leading to unauthorized data access or internal system interference.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in Deno's WebSocket API due to a missing post-DNS resolution check. While Deno validates the initial hostname against the '--deny-net' blocklist, it fails to verify the resulting IP address after DNS resolution. An attacker can exploit this by using a DNS rebinding-style attack or a specially crafted domain that resolves to a restricted IP (such as 127.0.0.1 or internal metadata services). This allows a script running in the Deno sandbox to establish WebSocket connections to prohibited network destinations. The issue is specific to the WebSocket implementation and does not affect Deno.connect or fetch(). The vulnerability is resolved in version 2.8.1.

Affected products

  • denoland Deno < 2.8.1

Timeline

  • 2026-05-27: advisory: GitHub advisory published by maintainers
  • 2026-06-23: disclosed: CVE published to NVD
  • 2026-06-23: patched: Fix released in version 2.8.1

References

Related threats