CVE-2026-22863: 
Rust vulnerability analysis and mitigation

Overview

CVE-2026-22863 is a missing cryptographic step vulnerability in Deno's node:crypto module that allows an attacker to perform infinite encryption operations without proper cipher finalization. It affects all Deno versions up to and including 2.5.6, and was disclosed on January 15, 2026, with a fix released in Deno 2.6.0. The vulnerability carries a CVSS v3.1 score of 7.5 (High) and a CVSS v4.0 score of 9.2 (Critical) (GitHub Advisory, Deno Security Advisory).

Technical details

The root cause is classified as CWE-325 (Missing Cryptographic Step): Deno's implementation of node:crypto fails to properly finalize cipher operations after cipher.final() is called, leaving the cipher object in an active, non-terminated state. In a correct implementation, calling cipher.final() should mark the cipher as finalized and prevent further use; however, in affected Deno versions, the cipher remains operational, enabling repeated encryption calls without the expected termination boundary. A public proof-of-concept is included in the advisory, demonstrating that after calling cipher.final() on an AES-256-CBC cipher, the object retains full stream state rather than being finalized (Deno Security Advisory). No authentication or special privileges are required to trigger this condition — any code path using node:crypto cipher objects is potentially affected (GitHub Advisory).

Impact

The primary impact is a high confidentiality risk: by exploiting the non-finalized cipher, an attacker can conduct unlimited encryption attempts against a target, enabling both naive brute-force attacks and more sophisticated cryptanalytic attacks aimed at recovering server secrets or cryptographic keys. Integrity and availability are not directly impacted by this vulnerability. In security-sensitive deployments — such as servers handling encrypted tokens, session keys, or sensitive user data — successful exploitation could lead to unauthorized decryption and exposure of confidential information (Deno Security Advisory, GitHub Advisory).

Exploitability

A proof-of-concept exploit is publicly available in the official security advisory, demonstrating the missing finalization behavior with a minimal code snippet (Deno Security Advisory). There is no evidence of active in-the-wild exploitation at this time, and the vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.017% (1st percentile), indicating a low near-term exploitation probability (GitHub Advisory). No specific threat actor attribution has been reported.

Exploitation steps

  1. Identify target: Determine that the target application is running Deno version 2.5.6 or earlier and uses the node:crypto module for cipher operations (e.g., AES encryption of sensitive data).
  2. Craft exploit code: Write or adapt the published PoC to interact with the vulnerable cipher interface:
import crypto from "node:crypto";
const key = crypto.randomBytes(32);
const iv = crypto.randomBytes(16);
const cipher = crypto.createCipheriv("aes-256-cbc", key, iv);
cipher.final(); // Should finalize, but does not in affected versions
// Cipher remains active — continue encrypting
  1. Perform repeated encryptions: Because cipher.final() does not terminate the cipher, submit multiple plaintext inputs to the same cipher object, collecting ciphertext outputs for analysis.
  2. Conduct cryptanalytic attack: Use the collected ciphertext/plaintext pairs to attempt brute-force key recovery or apply more refined chosen-plaintext attacks to deduce server secrets or session keys.
  3. Extract secrets: Leverage recovered cryptographic material to decrypt sensitive server-side data, forge tokens, or impersonate authenticated sessions (Deno Security Advisory).

Indicators of compromise

  • Logs: Unusually high volumes of encryption/decryption operations logged by the application, particularly repeated calls to cipher functions without corresponding finalization events.
  • Application Behavior: Cipher objects remaining in an active stream state after cipher.final() is called (observable via application-level debugging or instrumentation in Deno versions ≤ 2.5.6).
  • Network: Anomalous patterns of repeated, structurally similar requests to endpoints that perform cryptographic operations, potentially indicative of chosen-plaintext attack attempts.
  • Runtime: Deno process version reported as 2.5.6 or earlier in server banners, health endpoints, or process metadata, confirming exposure to the vulnerability (Deno Security Advisory).

Mitigation and workarounds

The only recommended remediation is to upgrade Deno to version 2.6.0 or later, which includes the fix fix(ext/node): prevent cipher operations after finalize (#31533) (Deno v2.6.0 Release). No configuration-based workaround is available for affected versions. Organizations should audit all systems running Deno versions prior to 2.6.0 that handle sensitive encrypted data and prioritize patching for any internet-facing or security-critical deployments (GitHub Advisory).

Community reactions

Security news outlet SecurityOnline.info covered the vulnerability alongside a companion Deno flaw (CVE-2026-22864), highlighting the risk to server secrets (SecurityOnline). The vulnerability was noted in the weekly threat landscape digest for Week 4 of 2026 by Hawk-Eye threat intelligence (Hawk-Eye). Community reaction has been moderate, with the advisory credited to three independent finders (davidebombelli, vdata1, reallyTG), suggesting coordinated responsible disclosure (Deno Security Advisory).

Additional resources


Source: This report was generated using AI

Related Rust vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-6w6g-hm98-mhgmHIGH8.7
  • Rust logoRust
  • hickory-resolver
NoYesOct 05, 2026
GHSA-5j98-2g5x-46v6HIGH7.5
  • Rust logoRust
  • hickory-resolver
NoYesOct 05, 2026
GHSA-cjcg-cxmh-9wcrHIGH7.5
  • Rust logoRust
  • praxis-proxy
NoYesOct 02, 2026
GHSA-6f2x-v7q7-m7m5MEDIUM6.9
  • Rust logoRust
  • hickory-resolver
NoYesOct 05, 2026
GHSA-6g2r-675j-hx59LOW2.3
  • Rust logoRust
  • xxhash-rust
NoYesOct 02, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management