CVE-2023-33966
Rust vulnerability analysis and mitigation

Overview

Deno, a runtime for JavaScript and TypeScript, introduced a security vulnerability in version 1.34.0 and deno_runtime 0.114.0. The vulnerability (CVE-2023-33966) was discovered on May 31, 2023, where outbound HTTP requests made using the built-in node:http or node:https modules incorrectly bypassed the network permission allow list (--allow-net) check (Vendor Advisory).

Technical details

The vulnerability stems from an improper privilege management issue (CWE-269) where the built-in Node.js compatibility modules (node:http and node:https) failed to enforce network permission checks. The vulnerability received a CVSS v3.1 base score of 9.8 (CRITICAL) from NIST, with a vector string of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H (NVD).

Impact

The vulnerability allows applications to make unauthorized network requests, bypassing Deno's security permissions system. This could potentially lead to unauthorized data exfiltration or communication with malicious servers, even when the application is run without explicit network permissions.

Mitigation and workarounds

The vulnerability has been patched in Deno v1.34.1 and deno_runtime 0.114.1. Users are strongly recommended to upgrade to these versions or later. No alternative workarounds are available for this security issue (Release Notes).

Additional resources


SourceThis report was generated using AI

Related Rust vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-66627HIGH8.4
  • RustRust
  • wasmi
NoYesDec 09, 2025
GHSA-xrv8-2pf5-f3q7MEDIUM6
  • RustRust
  • nitro-tpm-pcr-compute
NoYesDec 05, 2025
CVE-2025-67487MEDIUM5.5
  • RustRust
  • static-web-server
NoYesDec 09, 2025
CVE-2025-66622LOW1.3
  • RustRust
  • matrix-sdk-base
NoYesDec 09, 2025
RUSTSEC-2025-0135N/AN/A
  • RustRust
  • matrix-sdk-base
NoYesDec 08, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management