Cipher Vulnerability in Deno Runtime Affects Multiple Versions
CVE-2026-22863
9.2CRITICAL
What is CVE-2026-22863?
The Deno runtime, which supports JavaScript, TypeScript, and WebAssembly, is susceptible to a vulnerability in its node:crypto module prior to version 2.6.0. This flaw allows an attacker to execute an infinite number of encryptions, creating opportunities for brute force attacks and advanced techniques aimed at uncovering sensitive server information. The issue has been remedied in version 2.6.0, highlighting the importance of updating to secure server applications.
Affected Version(s)
deno < 2.6.0
