🛡️ CVE-2026-55517 — deno

🟡 CVSS 4.3 — Medium ✅ No Known Exploit CWE-248 OSV
4.3
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Deno: Denial of service via non-ASCII bytes in WebSocket response headers

Summary

A Deno program that opens a client WebSocket connection could be crashed by

the remote server. While handling the WebSocket handshake response, Deno parsed

the Sec-WebSocket-Protocol and Sec-WebSocket-Extensions response headers in

a way that assumed their bytes were always printable ASCII. A response header

containing non-visible-ASCII bytes (0x80-0xFF) caused a panic that aborted

the entire Deno process.

Details

When establishing a client WebSocket connection, Deno read the

Sec-WebSocket-Protocol and Sec-WebSocket-Extensions headers from the

server's 101 Switching Protocols response and converted them to strings

without handling the failure case. HeaderValue::to_str() returns an error for

any value containing bytes outside the visible-ASCII range, so a header carrying

such bytes triggered an unrecoverable error during conversion.

Because the client initiates the outbound connection, the handshake response is

fully controlled by the server. A server that returns bytes such as 0xFF 0xFE

in either header could therefore crash any client that connected to it.

This is purely an availability issue. There is no information disclosure and no

memory-safety impact; the only effect is termination of the current process.

Impact

Remote denial of service. Any Deno application that establishes WebSocket

connections to untrusted or potentially-compromised endpoints could be

terminated by the remote peer. Exploitation requires the victim application to

initiate the outbound WebSocket connection. An attacker who controls the

WebSocket endpoint, or who can man-in-the-middle a plaintext ws:// connection,

could trigger the crash. The effect is confined to crashing the process that

opened the connection.

Patch

The issue is fixed in Deno 2.7.5. The header values are now parsed with

graceful fallbacks: values that cannot be represented as ASCII strings are

skipped instead of aborting the process. A regression test covers a server that

returns non-ASCII bytes in Sec-WebSocket-Protocol.

Users should upgrade to Deno 2.7.5 or later.

Workarounds

Until you can upgrade, only connect to trusted WebSocket endpoints and prefer

wss:// (TLS) over ws://, which prevents a network man-in-the-middle from

injecting malicious header bytes into the handshake response.

How this vulnerability can be exploited

This issue can be reached over the network, attack complexity is low, an attacker needs no privileges on the target. A user must be tricked into taking some action. The scope is unchanged, so the impact stays within the vulnerable component. Rated impact: confidentiality none, integrity none, availability low.

Affected software

CVE-2026-55517 is recorded against 1 package.

  • deno

Timeline and source

Published on 17 June 2026 and last revised on 29 June 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

github.com (Web)
github.com (Package)

Details

Severity MEDIUM
CVSS Score 4.3
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
CWE CWE-248
Public Exploit ✅ No
Source OSV
Published 2026-06-17
Updated 2026-08-12
Modified 2026-06-29
Fix URL N/A

Affected Packages

Software From version Fixed in
deno

Similar Threats

Vulnerability Monitoring

Track new vulnerabilities in deno

CVE-2026-55517 is rated CVSS 4.3 Medium. BotEraser monitors your WordPress installation and notifies you when software you use appears in our vulnerability database.

Set Up Free Alerts →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.