---
id: CVE-2026-59877
title: >-
  protobufjs: protobufjs: Denial of Service via crafted .proto schema
  (CVE-2026-59877)
summary: >-
  A flaw was found in protobufjs, a JavaScript (JS) library for compiling
  protobuf definitions. A remote attacker could exploit this vulnerability by
  providing a specially crafted .proto schema. This schema, designed to
  prematurely end an op…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cvssSource: vendor
cwe: CWE-835
vendor: Red Hat
product: Red Hat OpenShift Service Mesh 3.3
affected:
  - openshift_pipelines
  - ansible_automation_platform 2
  - build_of_podman_desktop
  - ceph_storage 9
  - enterprise_linux_ai_rhel_ai 3
  - hardened_images
  - openshift_data_foundation 4
  - cryostat_4_on_rhel 9
  - enterprise_linux_extensions_channel_v_10
  - ansible_automation_platform 2.1
  - ansible_automation_platform 2.2
  - ansible_automation_platform 2.6
  - ansible_automation_platform 2.7
  - developer_hub 1.10
  - developer_hub 1.9
  - openshift_container_platform 4.21
  - openshift_container_platform 4.22
  - openshift_dev_spaces 3.30
  - openshift_service_mesh 3.3
  - openshift_service_mesh 3.4
patched:
  - cryostat_4_on_rhel 9
  - enterprise_linux_extensions_channel_v_10
  - ansible_automation_platform 2.1
  - ansible_automation_platform 2.2
  - ansible_automation_platform 2.6
  - ansible_automation_platform 2.7
  - developer_hub 1.10
  - developer_hub 1.9
  - openshift_container_platform 4.21
  - openshift_container_platform 4.22
  - openshift_dev_spaces 3.30
  - openshift_service_mesh 3.3
  - openshift_service_mesh 3.4
published: '2026-07-08'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T06:01:28+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59877.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59877.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-59877'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2498127'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-59877'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-59877'
  - url: >-
      https://github.com/protobufjs/protobuf.js/commit/10fba6d54815ceecca8a06b9a6db490c8f5d2217
  - url: >-
      https://github.com/protobufjs/protobuf.js/commit/fa5c73add738ceb471e74da8cc2f3727c3d0a69f
  - url: 'https://github.com/protobufjs/protobuf.js/pull/2352'
  - url: 'https://github.com/protobufjs/protobuf.js/releases/tag/protobufjs-v7.6.5'
  - url: 'https://github.com/protobufjs/protobuf.js/releases/tag/protobufjs-v8.6.6'
  - url: >-
      https://github.com/protobufjs/protobuf.js/security/advisories/GHSA-j3f2-48v5-ccww
  - url: 'https://access.redhat.com/errata/RHSA-2026:68333'
  - url: 'https://access.redhat.com/errata/RHSA-2026:57590'
  - url: 'https://access.redhat.com/errata/RHSA-2026:50850'
  - url: 'https://access.redhat.com/errata/RHSA-2026:50839'
  - url: 'https://access.redhat.com/errata/RHSA-2026:51162'
  - url: 'https://access.redhat.com/errata/RHSA-2026:71179'
  - url: 'https://access.redhat.com/errata/RHSA-2026:67279'
  - url: 'https://access.redhat.com/errata/RHSA-2026:48126'
  - url: 'https://access.redhat.com/errata/RHSA-2026:49642'
  - url: 'https://access.redhat.com/errata/RHSA-2026:52768'
  - url: 'https://access.redhat.com/errata/RHSA-2026:60477'
  - url: 'https://access.redhat.com/errata/RHSA-2026:57365'
  - url: 'https://access.redhat.com/errata/RHSA-2026:62260'
  - url: 'https://access.redhat.com/errata/RHSA-2026:49680'
  - url: 'https://access.redhat.com/errata/RHSA-2026:49735'
  - url: 'https://github.com/advisories/GHSA-j3f2-48v5-ccww'
tags:
  - csaf
  - vex
  - red-hat
  - ghsa
  - npm
  - score-dispute
epss: 0.00365
epssPercentile: 0.30414
aliases:
  - GHSA-j3f2-48v5-ccww
ecosystem: npm
scores:
  vendor: 7.5
  ghsa: 5.3
ingestedAt: '2026-07-20T22:43:35.207Z'
---

## Overview

A flaw was found in protobufjs, a JavaScript (JS) library for compiling protobuf definitions. A remote attacker could exploit this vulnerability by providing a specially crafted .proto schema. This schema, designed to prematurely end an option declaration, can cause the library's parsing functions to loop indefinitely. This leads to a Denial of Service (DoS), making the affected system unresponsive.

## Vendor advisories

- **RHSA-2026:68333** · Red Hat · fixed in: Cryostat 4 on RHEL 9 · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68333)
- **RHSA-2026:57590** · Red Hat · fixed in: Red Hat Enterprise Linux Extensions Channel (v. 10) · released 2026-08-20 · [advisory](https://access.redhat.com/errata/RHSA-2026:57590)
- **RHSA-2026:50850** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.1 · released 2026-08-05 · [advisory](https://access.redhat.com/errata/RHSA-2026:50850)
- **RHSA-2026:50839** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.2 · released 2026-08-05 · [advisory](https://access.redhat.com/errata/RHSA-2026:50839)
- **RHSA-2026:51162** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.2 · released 2026-08-06 · [advisory](https://access.redhat.com/errata/RHSA-2026:51162)
- **RHSA-2026:71179** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:71179)
- **RHSA-2026:67279** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.7 · released 2026-09-14 · [advisory](https://access.redhat.com/errata/RHSA-2026:67279)
- **RHSA-2026:48126** · Red Hat · fixed in: Red Hat Developer Hub 1.10 · released 2026-07-29 · [advisory](https://access.redhat.com/errata/RHSA-2026:48126)
- **RHSA-2026:49642** · Red Hat · fixed in: Red Hat Developer Hub 1.10 · released 2026-08-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:49642)
- **RHSA-2026:52768** · Red Hat · fixed in: Red Hat Developer Hub 1.9 · released 2026-08-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:52768)
- **RHSA-2026:60477** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.21 · released 2026-09-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:60477)
- **Red Hat VEX** · Important · affected: OpenShift Pipelines, Red Hat Ansible Automation Platform 2, Red Hat Build of Podman Desktop, Red Hat Ceph Storage 9, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Hardened Images, … · no fix planned: OpenShift Pipelines, Red Hat Ceph Storage 9, Red Hat Ansible Automation Platform 2, Red Hat Build of Podman Desktop, … · updated 2026-09-24 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59877.json)
- **RHSA-2026:57365** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.22 · released 2026-08-25 · [advisory](https://access.redhat.com/errata/RHSA-2026:57365)
- **RHSA-2026:62260** · Red Hat · fixed in: Red Hat OpenShift Dev Spaces 3.30 · released 2026-09-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:62260)

**protobufjs: protobufjs: Denial of Service via crafted .proto schema** — rated Important by Red Hat. Released 2026-07-08, updated 2026-09-24.

Affected:

- OpenShift Pipelines
- Red Hat Ansible Automation Platform 2
- Red Hat Build of Podman Desktop
- Red Hat Ceph Storage 9
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat Hardened Images
- Red Hat Openshift Data Foundation 4

Fixed:

- Cryostat 4 on RHEL 9
- Red Hat Enterprise Linux Extensions Channel (v. 10)
- Red Hat Ansible Automation Platform 2.1
- Red Hat Ansible Automation Platform 2.2
- Red Hat Ansible Automation Platform 2.6
- Red Hat Ansible Automation Platform 2.7
- Red Hat Developer Hub 1.10
- Red Hat Developer Hub 1.9
- Red Hat OpenShift Container Platform 4.21
- Red Hat OpenShift Container Platform 4.22
- Red Hat OpenShift Dev Spaces 3.30
- Red Hat OpenShift Service Mesh 3.3
- Red Hat OpenShift Service Mesh 3.4

No fix planned:

- OpenShift Pipelines
- Red Hat Ceph Storage 9
- Red Hat Ansible Automation Platform 2
- Red Hat Build of Podman Desktop
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat Hardened Images
- Red Hat Openshift Data Foundation 4

Not affected:

- Cryostat 4 on RHEL 9
- Red Hat Ansible Automation Platform 2.6
- Red Hat Ansible Automation Platform 2.7
- Red Hat Developer Hub 1.10
- Red Hat Developer Hub 1.9
- Red Hat OpenShift Container Platform 4.21
- Red Hat OpenShift Container Platform 4.22
- Red Hat OpenShift Dev Spaces 3.30
- Red Hat OpenShift Service Mesh 3.4
- Red Hat Enterprise Linux 8

## Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:68333
For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:57590
For more about Ansible plugins for Red Hat Developer Hub, see References links https://access.redhat.com/errata/RHSA-2026:50850

Workarounds / mitigations:

- Applications that only encode or decode protobuf messages using trusted schemas are not directly affected. Until patched protobufjs packages (7.6.5 / 8.6.6) are available, do not parse .proto schema text from untrusted sources via parse, Root.load, or Root.loadSync. Where untrusted schema input cannot be avoided, isolate .proto parsing in a dedicated worker thread or subprocess and enforce an explicit timeout so a non-returning parse cannot block the main event loop. Optional process-manager co…

## Package advisory (CVE-2026-59877)

Affected packages:

- `protobufjs >= 7.5.0, <= 7.6.4`
- `protobufjs >= 8.0.0, <= 8.6.5`

Patched in:

- `protobufjs 7.6.5`
- `protobufjs 8.6.6`

Source: https://github.com/advisories/GHSA-j3f2-48v5-ccww
