Nixpkgs security tracker

Login with GitHub

Details of issue NIXPKGS-2026-0018

NIXPKGS-2026-0018
published on
updated 2 months, 3 weeks ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed package speech-denoiser
  • @LeSuisse removed package openimagedenoise
  • @LeSuisse removed package terraform-providers.deno
  • @LeSuisse removed package python312Packages.denonavr
  • @LeSuisse removed package python313Packages.denonavr
  • @LeSuisse removed package haskellPackages.pandoc-sidenote
  • @LeSuisse removed package terraform-providers.denoland_deno
  • @LeSuisse removed package gnomeExtensions.denon-avr-controler
  • @LeSuisse removed package python312Packages.bnunicodenormalizer
  • @LeSuisse removed package python313Packages.bnunicodenormalizer
  • @LeSuisse removed package vscode-extensions.denoland.vscode-deno
  • @LeSuisse removed package home-assistant-component-tests.denonavr
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
Deno node:crypto doesn't finalize cipher

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Before 2.6.0, node:crypto doesn't finalize cipher. The vulnerability allows an attacker to have infinite encryptions. This can lead to naive attempts at brute forcing, as well as more refined attacks with the goal to learn the server secrets. This vulnerability is fixed in 2.6.0.

Affected products

deno
  • ==< 2.6.0

Matching in nixpkgs

pkgs.deno

Secure runtime for JavaScript and TypeScript

Package maintainers

Upstream advisory: https://github.com/denoland/deno/security/advisories/GHSA-5379-f5hf-w38v