CVE-2026-44289High· 7.5▾ Twilightprotobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs could recurse without a depth limit while decoding nested protobuf data. This affected both skipping unknown group fields and g…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.6%
0.6% → 0.6%
protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs could recurse without a depth limit while decoding nested protobuf data. This affected both skipping unknown group fields and generated decoding of nested message fields. A crafted protobuf binary payload could cause the JavaScript call stack to be exhausted during decoding. This vulnerability is fixed in 7.5.6 and 8.0.2.
protobufjs < 7.5.6protobufjs >= 8.0.0, < 8.0.2Upgrade past the affected range:
protobufjs 8.0.2Connected by shared product, vendor, weakness, or advisory.
CVE-2026-54269Medium· 5.3protobufjs : Schema-derived names can shadow runtime-significant properties
CVE-2026-48712High· 7.5protobufjs: Denial of service through unbounded Any expansion during JSON conversion
CVE-2026-59876Medium· 4.8protobufjs compiles protobuf definitions into JavaScript (JS) functions
CVE-2026-41242Critical· 9.8protobufjs compiles protobuf definitions into JavaScript (JS) functions
CVE-2026-54270Medium· 5.3protobufjs: Memory amplification from preserved unknown fields in binary decode
CVE-2026-44293High· 8.8protobufjs compiles protobuf definitions into JavaScript (JS) functions