CVE-2026-49859: Deno: `fetch()` API sandbox bypass via missing DNS resolution check
Summary
When fetch() was called, Deno checked the destination hostname against --deny-net rules but did not re-check the IP addresses that hostname resolved to. An attacker-controlled script could use a specially crafted domain name that passes the hostname check yet resolves to a denied IP, bypassing the network restriction entirely.
Impact
Code running under --deny-net could reach hosts that the user intended to block. In practice this means network isolation rules — for example, blocking access to localhost or internal services — could be silently circumvented by a malicious or compromised dependency.
A companion advisory covers the same class of issue in the WebSocket API.
Who is affected
Users who:
- run untrusted or third-party code with deno run, and - rely on --deny-net to restrict which hosts that code can reach.
If you do not use --deny-net, or if you only run fully trusted code, you are not affected.
Workaround
No workaround is available short of upgrading. If upgrading immediately is not possible, avoid granting --allow-net to untrusted code that also has --deny-net restrictions you depend on for security.
Fix
The fetch() DNS resolver now performs a post-resolution check on every IP address before passing it to the HTTP connector, consistent with how Deno.connect already behaved.
Other sources
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, when fetch() was called, Deno checked the destination hostname against --deny-net rules but did not re-check the IP addresses that hostname resolved to. An attacker-controlled script could use a specially crafted domain name that passes the hostname check yet resolves to a denied IP, bypassing the network restriction entirely. This vulnerability is fixed in 2.8.1.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
rust/denoto a version that resolves this vulnerability.Fixed in 2.8.1 - Upgrade
Upgrade
Denoto a version that resolves this vulnerability.Fixed in 2.8.1 - Compensating control
Avoid granting `--allow-net` to untrusted or third-party code; run untrusted/third-party code with `deno run` (as noted) so it cannot bypass network isolation.
- Compensating control
Use `--deny-net` to restrict which hosts the code can reach (workaround noted), but note that this is bypassable without upgrading to 2.8.1.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-49859?
The severity of CVE-2026-49859 is medium with a score of 5.2.
How do I fix CVE-2026-49859?
To fix CVE-2026-49859, ensure that your application correctly checks resolved IP addresses against the --deny-net rules when using fetch().
What type of vulnerability is CVE-2026-49859?
CVE-2026-49859 is categorized as a Server-Side Request Forgery (SSRF) vulnerability.
What kind of impact could CVE-2026-49859 have on my application?
CVE-2026-49859 could allow an attacker to bypass network restrictions and access denied IP addresses indirectly through specially crafted domain names.
In what software does CVE-2026-49859 exist?
CVE-2026-49859 exists in the Rust Deno runtime environment.