CVE-2026-59877High· 7.5▾ TwilightA flaw was found in protobufjs, a JavaScript (JS) library for compiling protobuf definitions. A remote attacker could exploit this vulnerability by providing a specially crafted .proto schema. This schema, designed to prematurely end an op…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 20.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.4%
5.3 → 7.5
medium → high
Last analysed / modified upstream
A flaw was found in protobufjs, a JavaScript (JS) library for compiling protobuf definitions. A remote attacker could exploit this vulnerability by providing a specially crafted .proto schema. This schema, designed to prematurely end an option declaration, can cause the library's parsing functions to loop indefinitely. This leads to a Denial of Service (DoS), making the affected system unresponsive.
protobufjs: protobufjs: Denial of Service via crafted .proto schema — rated Important by Red Hat. Released 2026-07-08, updated 2026-09-21.
Affected:
Fixed:
No fix planned:
Not affected:
Before applying this update, make sure all previously released errata relevant to your system have been applied.
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:68333 For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:57590 For more about Ansible plugins for Red Hat Developer Hub, see References links https://access.redhat.com/errata/RHSA-2026:50850
Workarounds / mitigations:
Affected packages:
protobufjs >= 7.5.0, <= 7.6.4protobufjs >= 8.0.0, <= 8.6.5Patched in:
protobufjs 7.6.5protobufjs 8.6.6Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-59874High· 7.5tar: Node-tar: Denial of Service via malformed tar archive header (CVE-2026-59874)
CVE-2026-59879Medium· 5.3immutable-js: Immutable.js: Denial of Service due to mishandling of large index values in List operations (CVE-2026-59879)
CVE-2026-90816Medium· 4.3A vulnerability was found in FFmpeg 8.0.x
CVE-2026-89567Medium· 5.5kernel: jbd2: bound shrinker scans by examined checkpoint buffers (CVE-2026-89567)
CVE-2026-80957Medium· 5.5kernel: dm-pcache: detect a cycle in the last-kset chain during replay (CVE-2026-80957)
CVE-2021-33194High· 7.5golang: x/net/html: infinite loop in ParseFragment (CVE-2021-33194)