CVE-2026-22863: Deno node:crypto doesn't finalize cipher
Summary
The vulnerability allows an attacker to have infinite encryptions.
This can lead to naive attempts at brute forcing, as well as more refined attacks with the goal to learn the server secrets.
PoC js import crypto from "node:crypto";
const key = crypto.randomBytes(32); const iv = crypto.randomBytes(16); const cipher = crypto.createCipheriv("aes-256-cbc", key, iv); cipher.final()
console.log(cipher);
Expected Output js Cipheriv { decoder: null, options: undefined, Symbol(kHandle): CipherBase {} }
Actual Output js Cipheriv { events: { close: undefined, error: undefined, prefinish: [Function: prefinish], finish: undefined, drain: undefined, data: undefined, end: undefined, readable: undefined }, readableState: ReadableState { highWaterMark: 65536, buffer: [], bufferIndex: 0, length: 0, pipes: [], awaitDrainWriters: null, [Symbol(kState)]: 1048844 }, writableState: WritableState { highWaterMark: 65536, length: 0, corked: 0, onwrite: [Function: bound onwrite], writelen: 0, bufferedIndex: 0, pendingcb: 0, [Symbol(kState)]: 17580812, [Symbol(kBufferedValue)]: null }, allowHalfOpen: true, final: [Function: final], maxListeners: undefined, transform: [Function: transform], eventsCount: 1, [Symbol(kCapture)]: false, [Symbol(kCallback)]: null }
Mitigations
All users should upgrade to Deno v2.6.0 or newer.
Other sources
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Before 2.6.0, node:crypto doesn't finalize cipher. The vulnerability allows an attacker to have infinite encryptions. This can lead to naive attempts at brute forcing, as well as more refined attacks with the goal to learn the server secrets. This vulnerability is fixed in 2.6.0.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22863?
CVE-2026-22863 has a medium severity as it allows attackers to exploit encryption vulnerabilities.
How do I fix CVE-2026-22863?
To resolve CVE-2026-22863, upgrade to Deno version 2.6.0 or higher.
What software is affected by CVE-2026-22863?
CVE-2026-22863 affects Deno versions prior to 2.6.0.
What impact does CVE-2026-22863 have on security?
CVE-2026-22863 can lead to increased susceptibility to brute force attacks due to infinite encryption.
Is CVE-2026-22863 related to encryption vulnerabilities?
Yes, CVE-2026-22863 specifically involves issues with the finalization of ciphers in the encryption process.