Improper privilege management in Deno - CVE-2023-33966
Published: May 30, 2023 / Updated: April 23, 2026
Deno
Deno Land
Description
The vulnerability allows a remote attacker to bypass network access restrictions.
The vulnerability exists due to improper privilege management in built-in "node:http" and "node:https" modules when making outbound HTTP requests. A remote attacker can cause the application to use these built-in modules to bypass network access restrictions.
Dependencies relying on these built-in modules are also affected. Deno Deploy users are unaffected.