{"id":"CVE-2026-59877","title":"protobufjs: protobufjs: Denial of Service via crafted .proto schema (CVE-2026-59877)","summary":"A flaw was found in protobufjs, a JavaScript (JS) library for compiling protobuf definitions. A remote attacker could exploit this vulnerability by providing a specially crafted .proto schema. This schema, designed to prematurely end an op…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-835","vendor":"Red Hat","product":"Red Hat OpenShift Service Mesh 3.3","affected":["openshift_pipelines","ansible_automation_platform 2","build_of_podman_desktop","ceph_storage 9","enterprise_linux_ai_rhel_ai 3","hardened_images","openshift_data_foundation 4","cryostat_4_on_rhel 9","enterprise_linux_extensions_channel_v_10","ansible_automation_platform 2.1","ansible_automation_platform 2.2","ansible_automation_platform 2.7","developer_hub 1.10","developer_hub 1.9","openshift_container_platform 4.21","openshift_container_platform 4.22","openshift_dev_spaces 3.30","openshift_service_mesh 3.3","openshift_service_mesh 3.4"],"patched":["cryostat_4_on_rhel 9","enterprise_linux_extensions_channel_v_10","ansible_automation_platform 2.1","ansible_automation_platform 2.2","ansible_automation_platform 2.7","developer_hub 1.10","developer_hub 1.9","openshift_container_platform 4.21","openshift_container_platform 4.22","openshift_dev_spaces 3.30","openshift_service_mesh 3.3","openshift_service_mesh 3.4"],"published":"2026-07-08","updated":"2026-09-21","sourceUpdated":"2026-09-21T10:40:30+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59877.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59877.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-59877"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2498127"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-59877"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59877"},{"url":"https://github.com/protobufjs/protobuf.js/commit/10fba6d54815ceecca8a06b9a6db490c8f5d2217"},{"url":"https://github.com/protobufjs/protobuf.js/commit/fa5c73add738ceb471e74da8cc2f3727c3d0a69f"},{"url":"https://github.com/protobufjs/protobuf.js/pull/2352"},{"url":"https://github.com/protobufjs/protobuf.js/releases/tag/protobufjs-v7.6.5"},{"url":"https://github.com/protobufjs/protobuf.js/releases/tag/protobufjs-v8.6.6"},{"url":"https://github.com/protobufjs/protobuf.js/security/advisories/GHSA-j3f2-48v5-ccww"},{"url":"https://access.redhat.com/errata/RHSA-2026:68333"},{"url":"https://access.redhat.com/errata/RHSA-2026:57590"},{"url":"https://access.redhat.com/errata/RHSA-2026:50850"},{"url":"https://access.redhat.com/errata/RHSA-2026:50839"},{"url":"https://access.redhat.com/errata/RHSA-2026:51162"},{"url":"https://access.redhat.com/errata/RHSA-2026:67279"},{"url":"https://access.redhat.com/errata/RHSA-2026:48126"},{"url":"https://access.redhat.com/errata/RHSA-2026:49642"},{"url":"https://access.redhat.com/errata/RHSA-2026:52768"},{"url":"https://access.redhat.com/errata/RHSA-2026:60477"},{"url":"https://access.redhat.com/errata/RHSA-2026:57365"},{"url":"https://access.redhat.com/errata/RHSA-2026:62260"},{"url":"https://access.redhat.com/errata/RHSA-2026:49680"},{"url":"https://access.redhat.com/errata/RHSA-2026:49735"},{"url":"https://github.com/advisories/GHSA-j3f2-48v5-ccww"}],"tags":["csaf","vex","red-hat","ghsa","npm","score-dispute"],"epss":0.00365,"epssPercentile":0.30407,"aliases":["GHSA-j3f2-48v5-ccww"],"ecosystem":"npm","scores":{"vendor":7.5,"ghsa":5.3},"ingestedAt":"2026-07-20T22:43:35.207Z","slug":"CVE-2026-59877","body":"## Overview\n\nA flaw was found in protobufjs, a JavaScript (JS) library for compiling protobuf definitions. A remote attacker could exploit this vulnerability by providing a specially crafted .proto schema. This schema, designed to prematurely end an option declaration, can cause the library's parsing functions to loop indefinitely. This leads to a Denial of Service (DoS), making the affected system unresponsive.\n\n## Vendor advisories\n\n- **RHSA-2026:68333** · Red Hat · fixed in: Cryostat 4 on RHEL 9 · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68333)\n- **RHSA-2026:57590** · Red Hat · fixed in: Red Hat Enterprise Linux Extensions Channel (v. 10) · released 2026-08-20 · [advisory](https://access.redhat.com/errata/RHSA-2026:57590)\n- **RHSA-2026:50850** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.1 · released 2026-08-05 · [advisory](https://access.redhat.com/errata/RHSA-2026:50850)\n- **RHSA-2026:50839** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.2 · released 2026-08-05 · [advisory](https://access.redhat.com/errata/RHSA-2026:50839)\n- **RHSA-2026:51162** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.2 · released 2026-08-06 · [advisory](https://access.redhat.com/errata/RHSA-2026:51162)\n- **RHSA-2026:67279** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.7 · released 2026-09-14 · [advisory](https://access.redhat.com/errata/RHSA-2026:67279)\n- **RHSA-2026:48126** · Red Hat · fixed in: Red Hat Developer Hub 1.10 · released 2026-07-29 · [advisory](https://access.redhat.com/errata/RHSA-2026:48126)\n- **RHSA-2026:49642** · Red Hat · fixed in: Red Hat Developer Hub 1.10 · released 2026-08-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:49642)\n- **RHSA-2026:52768** · Red Hat · fixed in: Red Hat Developer Hub 1.9 · released 2026-08-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:52768)\n- **RHSA-2026:60477** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.21 · released 2026-09-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:60477)\n- **RHSA-2026:57365** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.22 · released 2026-08-25 · [advisory](https://access.redhat.com/errata/RHSA-2026:57365)\n- **Red Hat VEX** · Important · affected: OpenShift Pipelines, Red Hat Ansible Automation Platform 2, Red Hat Build of Podman Desktop, Red Hat Ceph Storage 9, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Hardened Images, … · no fix planned: OpenShift Pipelines, Red Hat Ceph Storage 9, Red Hat Ansible Automation Platform 2, Red Hat Build of Podman Desktop, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59877.json)\n- **RHSA-2026:62260** · Red Hat · fixed in: Red Hat OpenShift Dev Spaces 3.30 · released 2026-09-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:62260)\n\n**protobufjs: protobufjs: Denial of Service via crafted .proto schema** — rated Important by Red Hat. Released 2026-07-08, updated 2026-09-21.\n\nAffected:\n\n- OpenShift Pipelines\n- Red Hat Ansible Automation Platform 2\n- Red Hat Build of Podman Desktop\n- Red Hat Ceph Storage 9\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n- Red Hat Hardened Images\n- Red Hat Openshift Data Foundation 4\n\nFixed:\n\n- Cryostat 4 on RHEL 9\n- Red Hat Enterprise Linux Extensions Channel (v. 10)\n- Red Hat Ansible Automation Platform 2.1\n- Red Hat Ansible Automation Platform 2.2\n- Red Hat Ansible Automation Platform 2.7\n- Red Hat Developer Hub 1.10\n- Red Hat Developer Hub 1.9\n- Red Hat OpenShift Container Platform 4.21\n- Red Hat OpenShift Container Platform 4.22\n- Red Hat OpenShift Dev Spaces 3.30\n- Red Hat OpenShift Service Mesh 3.3\n- Red Hat OpenShift Service Mesh 3.4\n\nNo fix planned:\n\n- OpenShift Pipelines\n- Red Hat Ceph Storage 9\n- Red Hat Ansible Automation Platform 2\n- Red Hat Build of Podman Desktop\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n- Red Hat Hardened Images\n- Red Hat Openshift Data Foundation 4\n\nNot affected:\n\n- Cryostat 4 on RHEL 9\n- Red Hat Ansible Automation Platform 2.7\n- Red Hat Developer Hub 1.10\n- Red Hat Developer Hub 1.9\n- Red Hat OpenShift Container Platform 4.21\n- Red Hat OpenShift Container Platform 4.22\n- Red Hat OpenShift Dev Spaces 3.30\n- Red Hat OpenShift Service Mesh 3.4\n- Red Hat Enterprise Linux 8\n- Red Hat OpenShift Container Platform 4\n\n## Remediation\n\nBefore applying this update, make sure all previously released errata relevant to your system have been applied.\n\nFor details on how to apply this update, refer to:\n\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:68333\nFor details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:57590\nFor more about Ansible plugins for Red Hat Developer Hub, see References links https://access.redhat.com/errata/RHSA-2026:50850\n\nWorkarounds / mitigations:\n\n- Applications that only encode or decode protobuf messages using trusted schemas are not directly affected. Until patched protobufjs packages (7.6.5 / 8.6.6) are available, do not parse .proto schema text from untrusted sources via parse, Root.load, or Root.loadSync. Where untrusted schema input cannot be avoided, isolate .proto parsing in a dedicated worker thread or subprocess and enforce an explicit timeout so a non-returning parse cannot block the main event loop. Optional process-manager co…\n\n## Package advisory (CVE-2026-59877)\n\nAffected packages:\n\n- `protobufjs >= 7.5.0, <= 7.6.4`\n- `protobufjs >= 8.0.0, <= 8.6.5`\n\nPatched in:\n\n- `protobufjs 7.6.5`\n- `protobufjs 8.6.6`\n\nSource: https://github.com/advisories/GHSA-j3f2-48v5-ccww","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":206415,"id":"CVE-2026-59877","ts":1789663226162,"field":"cvss","old":"5.3","new":"7.5"},{"seq":206414,"id":"CVE-2026-59877","ts":1789663226162,"field":"severity","old":"medium","new":"high"}]}