Medium severity4.3NVD Advisory· Published Jun 23, 2026· Updated Jun 29, 2026
CVE-2026-55517
CVE-2026-55517
Description
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.5, a Deno program that opens a client WebSocket connection could be crashed by the remote server. While handling the WebSocket handshake response, Deno parsed the Sec-WebSocket-Protocol and Sec-WebSocket-Extensions response headers in a way that assumed their bytes were always printable ASCII. A response header containing non-visible-ASCII bytes (0x80-0xFF) caused a panic that aborted the entire Deno process. This vulnerability is fixed in 2.7.5.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
denocrates.io | < 2.7.5 | 2.7.5 |
Affected products
3Patches
Vulnerability mechanics
References
2- github.com/advisories/GHSA-x2qc-cmh9-f4hfghsaADVISORY
- github.com/denoland/deno/security/advisories/GHSA-x2qc-cmh9-f4hfnvdMitigationVendor AdvisoryWEB
News mentions
1- Deno: Nine CVEs Disclosed in 24 Hours — Sandbox Bypasses, Command Injection, and Crypto FlawVypr Intelligence · Jun 17, 2026