cargo package report

Is deno_node safe?

1 known vulnerability, worst severity HIGH.

cvss
7.7

how bad it is if exploited, out of 10

epss
0.30%

chance of exploitation in the next 30 days

xyz score
3.3

CyberXYZ composite, out of 10

fig. 01 — GHSA-2x3r-hwv5-p32x, the advisory selected below

// advisories

GHSA-2x3r-hwv5-p32x

HIGHCVE-2025-24015

This affects AES-256-GCM and AES-128-GCM in Deno, introduced by commit [0d1beed](https://github.com/denoland/deno/commit/0d1beed). Specifically, the authentication tag is not being validated. This means tampered ciphertexts or incorrect keys might not be detected, which breaks the guarantees expected from AES-GCM. Older versions of Deno correctly threw errors in such cases, as does Node.js.

Affected
>= 0.102.0, < 0.125.0
Fixed in
0.125.0
Weakness
CWE-347
Published
2025-06-04
Source
github

GHSANVDMITREreferencereferencereferencereferencereference


// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so cargo packages are not covered.


Checked 2026-09-22 at 00:38 UTC. The most recent advisory here was published 2025-06-04. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is deno_node safe? cargo package security report | CyberXYZ