GHSA-wrqv-pf6j-mqjp · Severity: high · Ecosystem: rust — Deno's Node.js Compatibility Runtime has Cross-Session Data Contamination
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Starting in version 1.35.1 and prior to version 1.36.3, a vulnerability in Deno's Node.js compatibility runtime allows for cross-session data contamination during simultaneous asynchronous reads from Node.js streams sourced from sockets or files. The issue arises from the re-use of a global buffer (BUF) in stream_wrap.ts used as a performance optimization to limit allocations during these asynchronous read operations. This can lead to data intended for one session being received by another session, potentially resulting in data corruption and unexpected behavior. This affects all users of Deno that use the node.js compatibility layer for network communication or other streams, including packages that may require node.js libraries indirectly. Version 1.36.3 contains a patch for this issue.
Conclusion & alert: CVE-2024-27935 is rated High Exploit Risk (65/100): CVSS High severity, with medium exploitation likelihood (EPSS 0.40%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-03-25 | 0.30% | 0.40% | +0.09% |
| 2 | 2025-09-30 | 0.17% | 0.30% | +0.13% |
| 3 | 2025-05-04 | — | 0.17% | — |
Full EPSS history (10 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.2 | 3.1 | HIGH |
|
3.9 | 2.7 | [email protected] |
| 8.3 | 3.1 | HIGH |
|
3.9 | 3.7 | [email protected] |
GHSA-wrqv-pf6j-mqjp · Severity: high · Ecosystem: rust — Deno's Node.js Compatibility Runtime has Cross-Session Data Contamination
| URL | Tags |
|---|---|
| https://github.com/denoland/deno/commit/3e9fb8aafd9834ebacd27734cea4310caaf794c6 | Patch |
| https://github.com/denoland/deno/issues/20188 | Exploit Issue Tracking |
| https://github.com/denoland/deno/security/advisories/GHSA-wrqv-pf6j-mqjp | Vendor Advisory |