CVE-2026-59876Medium· 4.8▾ Sunlitprotobufjs compiles protobuf definitions into JavaScript (JS) functions. From 8.2.0 until 8.6.5, the protobufjs Text Format extension parsed string-keyed map entries using ordinary property assignment, allowing a map entry with key __pro…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 26.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 13.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
0.2% → 0.3%
protobufjs compiles protobuf definitions into JavaScript (JS) functions. From 8.2.0 until 8.6.5, the protobufjs Text Format extension parsed string-keyed map entries using ordinary property assignment, allowing a map entry with key proto to change the prototype of the returned map object instead of creating an own map entry in protobufjs/ext/textformat. This issue is fixed in version 8.6.5.
protobufjs >= 8.2.0, < 8.6.5Upgrade past the affected range:
protobufjs 8.6.5Connected by shared product, vendor, weakness, or advisory.
CVE-2026-41242Critical· 9.8protobufjs compiles protobuf definitions into JavaScript (JS) functions
CVE-2026-54269Medium· 5.3protobufjs : Schema-derived names can shadow runtime-significant properties
CVE-2026-48712High· 7.5protobufjs: Denial of service through unbounded Any expansion during JSON conversion
CVE-2026-54270Medium· 5.3protobufjs: Memory amplification from preserved unknown fields in binary decode
CVE-2026-44293High· 8.8protobufjs compiles protobuf definitions into JavaScript (JS) functions
CVE-2026-44289High· 7.5protobufjs compiles protobuf definitions into JavaScript (JS) functions