Medium severity5.2GHSA Advisory· Published Jun 23, 2026· Updated Jun 29, 2026
CVE-2026-49859
CVE-2026-49859
Description
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, when fetch() was called, Deno checked the destination hostname against --deny-net rules but did not re-check the IP addresses that hostname resolved to. An attacker-controlled script could use a specially crafted domain name that passes the hostname check yet resolves to a denied IP, bypassing the network restriction entirely. This vulnerability is fixed in 2.8.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
denocrates.io | < 2.8.1 | 2.8.1 |
Affected products
2Patches
Vulnerability mechanics
References
3- github.com/advisories/GHSA-cpgj-f7g3-2pp2ghsaADVISORY
- github.com/denoland/deno/security/advisories/GHSA-cpgj-f7g3-2pp2nvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2026-49859ghsaADVISORY
News mentions
1- Deno: Nine CVEs Disclosed in 24 Hours — Sandbox Bypasses, Command Injection, and Crypto FlawVypr Intelligence · Jun 17, 2026