Authentication Tag Validation Issue in Deno Runtime
CVE-2025-24015
7.7HIGH
What is CVE-2025-24015?
Deno, the JavaScript, TypeScript, and WebAssembly runtime, is impacted by a serious issue in versions 1.46.0 through 2.1.6, affecting AES-256-GCM and AES-128-GCM encryption modes. The vulnerability lies in the failure to validate the authentication tag, a critical step in ensuring the integrity of encrypted data. As a result, any tampered ciphertext or incorrect encryption keys may not trigger expected error responses, undermining the protection typically offered by AES-GCM. This flaw also compromises the efficacy of any associated authenticated data checks. Users are urged to upgrade to version 2.1.7 or later to mitigate this risk.
Affected Version(s)
deno >= 1.46.0, < 2.1.7