VulnSea

protobufjs_project has 4 CVEs on record. 1 was published in the last 90 days. The median CVSS is 8.2 (high), with 1 rated critical.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
8.2
Publish → KEV
Last 90 days
1 prev 3

Products

  • protobufjs 4
4
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

protobufjs_project vulnerabilities

CVEs affecting protobufjs_project, newest first. Open any entry for full detail, references, and exploit status.

4 CVEsRSS

CVE-2026-59876Medium· 4.8
2mo ago

protobufjs compiles protobuf definitions into JavaScript (JS) functions

protobufjs compiles protobuf definitions into JavaScript (JS) functions. From 8.2.0 until 8.6.5, the protobufjs Text Format extension parsed string-keyed map entries using ordinary property assignment, allowing a map entry with key __pro…

Sunlitprotobufjs_project · protobufjsEPSS 0.35%via NVD
CVE-2026-44293High· 8.8
4mo ago

protobufjs compiles protobuf definitions into JavaScript (JS) functions

protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs generated JavaScript for toObject conversion could include an unsafe expression derived from a schema-controlled bytes field de…

Twilightprotobufjs_project · protobufjsEPSS 0.41%via NVD
CVE-2026-44289High· 7.5
4mo ago

protobufjs compiles protobuf definitions into JavaScript (JS) functions

protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs could recurse without a depth limit while decoding nested protobuf data. This affected both skipping unknown group fields and g…

Twilightprotobufjs_project · protobufjsEPSS 0.63%via NVD
CVE-2026-41242Critical· 9.8PoC
5mo ago

protobufjs compiles protobuf definitions into JavaScript (JS) functions

protobufjs compiles protobuf definitions into JavaScript (JS) functions. In versions prior to 8.0.1 and 7.5.5, attackers can inject arbitrary code in the "type" fields of protobuf definitions, which will then execute during object decodi…

Abyssalprotobufjs_project · protobufjsEPSS 0.77%via NVD
protobufjs_project vulnerabilities (CVEs) · VulnSea