CVE-2026-22863
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Before 2.6.0, node:crypto doesn't finalize cipher. The vulnerability allows an attacker to have infinite encryptions. This can lead to naive attempts at brute forcing, as well as more refined attacks with the goal to learn the server secrets. This vulnerability is fixed in 2.6.0.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.2
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
- EPSS probability
- 0.20%
- CWE
- CWE-325
- Published
- 2026-01-15
- Last modified
- 2026-03-12
Affected products
- denoland deno
Weakness type
Related vulnerabilities
- CVE-2026-25250 — EAZ EazyFix 12.9 allows a Security Feature Bypass related to a "Missing Cryptographic Step"...
- CVE-2026-76784 — Insufficient Cryptographic Protections in Local Device Communication Protocol on Multiple TP-Link Kasa Smart Home Devices
- CVE-2026-59776 — Missing Cryptographic Step (CWE-325) vulnerability exists in certain FeliCa IC chips shipped in or...
- CVE-2026-58638 — Windows Boot Loader Security Feature Bypass Vulnerability
- CVE-2026-55144 — Windows Cryptography API: Next Generation (CNG) Tampering Vulnerability
- CVE-2026-6458 — AES-256-GCM Authentication Tag Does Not Cover First Ciphertext Blocks When AAD Is Empty
- CVE-2026-49440 — Deno: Miller-Rabin Primality Test Allows Zero Rounds
- CVE-2026-9266 — A Missing Required Cryptographic Step vulnerability has been identified in Moxa's embedded Linux...