{"id":"CVE-2026-48712","aliases":["GHSA-wcpc-wj8m-hjx6"],"title":"protobufjs: Denial of service through unbounded Any expansion during JSON conversion","summary":"protobufjs: Denial of service through unbounded Any expansion during JSON conversion","severity":"high","cvss":7.5,"cwe":["CWE-674"],"vendor":"protobufjs","product":"protobufjs","ecosystem":"npm","affected":["protobufjs <= 7.6.0","protobufjs >= 8.0.0, <= 8.4.0"],"patched":["protobufjs 7.6.1","protobufjs 8.4.1"],"published":"2026-06-15","updated":"2026-06-15","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-wcpc-wj8m-hjx6","references":[{"url":"https://github.com/protobufjs/protobuf.js/security/advisories/GHSA-wcpc-wj8m-hjx6"},{"url":"https://github.com/advisories/GHSA-wcpc-wj8m-hjx6"}],"tags":["ghsa","npm"],"epss":0.0046,"epssPercentile":0.39042,"ingestedAt":"2026-07-07T15:41:58.736Z","slug":"CVE-2026-48712","body":"## Overview\n\n## Summary\n\nprotobufjs could recurse without a depth limit while converting decoded messages to plain objects or JSON. This affected generated `toObject()` conversion and the custom `google.protobuf.Any` JSON conversion path.\n\nA crafted protobuf binary payload containing deeply nested `Any` values could cause the JavaScript call stack to be exhausted during conversion to JSON.\n\n## Impact\n\nAn attacker who can provide protobuf binary data decoded by an application may be able to crash the process or otherwise cause message conversion to fail with a stack overflow.\n\nThis affects applications that decode untrusted protobuf input containing `google.protobuf.Any` values and then convert decoded messages to JSON or plain objects with JSON conversion enabled, for example through `JSON.stringify(message)`, `Message#toJSON()`, or `Type.toObject(message, { json: true })`.\n\nApplications that only decode and re-encode protobuf binary data without converting decoded messages to JSON are not directly affected by this issue.\n\n## Preconditions\n\n* The application must decode protobuf binary data influenced by an attacker.\n* The application schema must include `google.protobuf.Any`, and the referenced `type_url` must resolve to a message type in the loaded protobuf root.\n* The application must convert the decoded message to JSON or a plain object through an affected conversion path.\n* The crafted input must contain deeply nested `Any` values that are expanded during conversion.\n\n## Workarounds\n\nAvoid converting untrusted protobuf messages containing `google.protobuf.Any` values to JSON with affected versions. If immediate upgrade is not possible, reject or limit messages with deeply nested `Any` payloads at an outer protocol boundary where feasible, avoid JSON conversion of untrusted `Any` values, or isolate message conversion in a process that can be safely restarted.\n\n## Affected packages\n\n- `protobufjs <= 7.6.0`\n- `protobufjs >= 8.0.0, <= 8.4.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `protobufjs 7.6.1`\n- `protobufjs 8.4.1`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}