VYPR
High severity7.4GHSA Advisory· Published Jun 23, 2026· Updated Jun 26, 2026

CVE-2026-44726

CVE-2026-44726

Description

Deno is a JavaScript, TypeScript, and WebAssembly runtime. From 2.0.0 until 2.7.8, a flaw in Deno's Node.js tls compatibility layer could cause a TLS client to transmit application data in plaintext after a connection retry. When `autoSelectFamily was enabled and the first address-family attempt failed, the socket reinitialization path reused a stale TLS upgrade hook that was bound to the original, failed handle. As a result, the replacement TCP connection was never upgraded to TLS, and any data the application wrote before the secureConnect event travelled over the network unencrypted. A network attacker positioned to cause the initial connection attempt to fail (for example, by dropping IPv6 traffic on a dual-stack host) could deterministically trigger the fallback path and observe or tamper with traffic that the application believed was TLS-protected. This vulnerability is fixed in 2.7.8.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
denocrates.io
>= 2.0.0, < 2.7.82.7.8

Affected products

3
  • Denoland/DenoGHSA2 versions
    >= 2.0.0, < 2.7.8+ 1 more
    • (no CPE)range: >= 2.0.0, < 2.7.8
    • cpe:2.3:a:deno:deno:*:*:*:*:*:*:*:*range: >=2.0.0,<2.7.8
  • ghsa-coords
    Range: >= 2.0.0, < 2.7.8

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.