NIXPKGS-2026-0018
published on
by @LeSuisse Activity log
- Created automatic suggestion
- @LeSuisse removed package speech-denoiser
- @LeSuisse removed package openimagedenoise
- @LeSuisse removed package terraform-providers.deno
- @LeSuisse removed package python312Packages.denonavr
- @LeSuisse removed package python313Packages.denonavr
- @LeSuisse removed package haskellPackages.pandoc-sidenote
- @LeSuisse removed package terraform-providers.denoland_deno
- @LeSuisse removed package gnomeExtensions.denon-avr-controler
- @LeSuisse removed package python312Packages.bnunicodenormalizer
- @LeSuisse removed package python313Packages.bnunicodenormalizer
- @LeSuisse removed package vscode-extensions.denoland.vscode-deno
- @LeSuisse removed package home-assistant-component-tests.denonavr
- @LeSuisse accepted
- @LeSuisse published on GitHub
Deno node:crypto doesn't finalize cipher
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Before 2.6.0, node:crypto doesn't finalize cipher. The vulnerability allows an attacker to have infinite encryptions. This can lead to naive attempts at brute forcing, as well as more refined attacks with the goal to learn the server secrets. This vulnerability is fixed in 2.6.0.
References
-
https://github.com/denoland/deno/security/advisories/GHSA-5379-f5hf-w38v x_refsource_CONFIRM
-
https://github.com/denoland/deno/releases/tag/v2.6.0 x_refsource_MISC
-
https://github.com/denoland/deno/security/advisories/GHSA-5379-f5hf-w38v x_refsource_CONFIRM
-
https://github.com/denoland/deno/releases/tag/v2.6.0 x_refsource_MISC
Affected products
deno
- ==< 2.6.0
Package maintainers
-
@ofalvai Olivér Falvai <ofalvai@gmail.com>
-
@06kellyjac Jack <hello+nixpkgs@j-k.io>