Cross-Session Data Contamination Vulnerability Affects Deno Versions 1.35.1-1.36.3
CVE-2024-27935
What is CVE-2024-27935?
A vulnerability has been identified in the Deno runtime, specifically affecting its Node.js compatibility layer. This issue results from the reuse of a global buffer during asynchronous read operations from Node.js streams, which can lead to cross-session data contamination. In situations where multiple sessions are accessing streams, data intended for one session may inadvertently be accessed by another. This vulnerability particularly impacts all users employing the Deno runtime for network communications or working with streams that may indirectly utilize Node.js libraries. Users are advised to update to version 1.36.3 or later, where this issue has been resolved.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
deno >= 1.35.1, < 1.36.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
