CVE-2026-44293High· 8.8▾ Twilightprotobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs generated JavaScript for toObject conversion could include an unsafe expression derived from a schema-controlled bytes field de…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Jul 5.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.4%
0.4% → 0.4%
Last analysed / modified upstream
protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs generated JavaScript for toObject conversion could include an unsafe expression derived from a schema-controlled bytes field default value. A crafted descriptor with a non-string default value for a bytes field could cause attacker-controlled code to be emitted into the generated conversion function. This vulnerability is fixed in 7.5.6 and 8.0.2.
protobufjs < 7.5.6protobufjs >= 8.0.0, < 8.0.2Upgrade past the affected range:
protobufjs 8.0.2Connected by shared product, vendor, weakness, or advisory.
CVE-2026-41242Critical· 9.8protobufjs compiles protobuf definitions into JavaScript (JS) functions
CVE-2026-44495High· 7.0Axios is a promise based HTTP client for the browser and Node.js
CVE-2025-14576High· 7.8Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick
CVE-2026-59876Medium· 4.8protobufjs compiles protobuf definitions into JavaScript (JS) functions
CVE-2026-54269Medium· 5.3protobufjs : Schema-derived names can shadow runtime-significant properties
CVE-2026-48712High· 7.5protobufjs: Denial of service through unbounded Any expansion during JSON conversion