CVE-2026-49860: Deno: WebSocket API sandbox bypass via missing post-DNS check

Published Jun 16, 2026
·
Updated

Summary

When a WebSocket connection was opened, Deno checked the destination hostname against --deny-net rules but did not re-check the IP addresses that hostname resolved to. An attacker-controlled script could use a specially crafted domain name that passes the hostname check yet resolves to a denied IP, bypassing the network restriction entirely.

Impact

Code running under --deny-net could connect to hosts that the user intended to block. In practice this means network isolation rules — for example, blocking access to localhost or internal services — could be silently circumvented by a malicious or compromised dependency.

Deno.connect and fetch() were not affected by this specific issue (a companion advisory covers fetch()).

Who is affected

Users who:

- run untrusted or third-party code with deno run, and - rely on --deny-net to restrict which hosts that code can reach.

If you do not use --deny-net, or if you only run fully trusted code, you are not affected.

Workaround

No workaround is available short of upgrading. If upgrading immediately is not possible, avoid granting --allow-net to untrusted code that also has --deny-net restrictions you depend on for security.

Other sources

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, when a WebSocket connection was opened, Deno checked the destination hostname against --deny-net rules but did not re-check the IP addresses that hostname resolved to. An attacker-controlled script could use a specially crafted domain name that passes the hostname check yet resolves to a denied IP, bypassing the network restriction entirely. This vulnerability is fixed in 2.8.1.

— MITRE

Affected Software

2 affected componentsFixes available
rust/deno<=2.8.0
2.8.1
Deno Deno<2.8.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade rust/deno to a version that resolves this vulnerability.

    Fixed in 2.8.1
  2. Upgrade

    Upgrade deno to a version that resolves this vulnerability.

    Fixed in 2.8.1
  3. Configuration

    Avoid granting `--allow-net` to untrusted code that would otherwise rely on `--deny-net` for security, since the issue involves bypassing `--deny-net` via hostname resolution during WebSocket connections (fixed in Deno 2.8.1).

    Deno runtime (network access controls) --allow-net = do not grant --allow-net to untrusted code that also has network-deny rules
  4. Configuration

    Workaround described: rely on `--deny-net` to restrict which hosts code can reach; note that in versions prior to 2.8.1 a WebSocket opened could bypass this restriction due to missing post-DNS IP re-check.

    Deno runtime --deny-net = use to restrict which hosts untrusted code can reach (but note bypass is fixed only by upgrading)

Event History

Jun 16, 2026
Advisory Published
via GitHub·07:04 PM
Data Sourced
via GitHub·07:04 PM
DescriptionSeverityWeaknessAffected Software
Jun 23, 2026
CVE Published
via MITRE·05:15 PM
Data Sourced
via MITRE·05:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:18 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-49860?

The severity of CVE-2026-49860 is medium with a score of 5.2.

2

How does CVE-2026-49860 affect Deno's WebSocket connections?

CVE-2026-49860 allows an attacker-controlled script to potentially exploit the WebSocket connection by using a crafted domain name that bypasses hostname checks.

3

What is the potential risk associated with CVE-2026-49860?

CVE-2026-49860 is classified as a Server-Side Request Forgery (SSRF) vulnerability, which can lead to unauthorized access to sensitive information.

4

How can I mitigate the risks of CVE-2026-49860?

To mitigate CVE-2026-49860, ensure that WebSocket connections are configured to validate resolved IP addresses against your specified network access rules.

5

When was CVE-2026-49860 published?

CVE-2026-49860 was published on June 16, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203