deno
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 42 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from May 28, 2021 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Deno 2.7.0 through 2.9.7 Command Injection via node:child_process
Deno: Denial of service via non-ASCII bytes in WebSocket response headers
Deno Permission Bypass via Unicode Normalization Mismatch on macOS (APFS)
Deno: BYONM module resolution allows `package.json` main path traversal to bypass `--allow-read` restrictions
Deno Node TCPWrap numeric hostname aliases bypass --deny-net resolved-IP deny checks
Deno: Miller-Rabin Primality Test Allows Zero Rounds
Deno: Command Injection via spawnSync & spawn on Windows
Deno: process.loadEnvFile() bypasses env permission checks and mutates process.env with only read access
Deno: WebSocket API sandbox bypass via missing post-DNS check
Deno: `fetch()` API sandbox bypass via missing DNS resolution check
Monitor deno in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.