Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2210071
AlmaLinux
5931
Alpaquita
16087
Alpine
4608
Android
3677
Azure Linux
17651
BellSoft Hardened Containers
754
Bitnami
9325
Chainguard
1030749
CleanStart
3846
CRAN
14
crates.io
2738
Debian
68472
Echo
7444
GHC
3
GIT
108258
GitHub Actions
55
Go
9245
Hackage
33
Hex
364
Julia
1713
Linux
29974
Mageia
6232
Maven
7044
MinimOS
144672
npm
228850
NuGet
1869
opam
29
openEuler
8800
openSUSE
14480
OSS-Fuzz
4013
Packagist
7098
Pub
11
PyPI
25181
Red Hat
23387
Rocky Linux
4305
Root
19583
RubyGems
5326
SUSE
23350
SwiftURL
60
TuxCare
9606
Ubuntu
65406
VSCode
21
Wolfi
289807
ID
Packages
Summary
Published
arrow_upward
Attributes
CVE-2026-59876
github.com/protobufjs/protobuf.js
protobufjs: Text Format string map parsing can mutate returned map object prototype
08 Jul
Fix available
Severity - 4.8 (Medium)
CVE-2026-59877
github.com/protobufjs/protobuf.js
protobufjs: Denial of Service via infinite loop in .proto option parsing
08 Jul
Fix available
Severity - 5.3 (Medium)
CVE-2026-54269
github.com/protobufjs/protobuf.js
protobufjs: Schema-derived names can shadow runtime-significant properties
22 Jun
Fix available
Severity - 5.3 (Medium)
CVE-2026-48712
github.com/protobufjs/protobuf.js
protobufjs: Denial of service through unbounded Any expansion during JSON conversion
22 Jun
Fix available
Severity - 7.5 (High)
CVE-2026-54270
github.com/protobufjs/protobuf.js
protobufjs: Memory amplification from preserved unknown fields in binary decode
22 Jun
Fix available
Severity - 5.3 (Medium)
CVE-2026-54271
github.com/protobufjs/protobuf.js
protobufjs-cli: Code injection in pbjs static output from crafted JSON descriptor names
22 Jun
Fix available
Severity - 8.2 (High)
CVE-2026-44295
github.com/protobufjs/protobuf.js
protobufjs-cli: Code injection in pbjs static output from crafted schema names
13 May
Fix available
Severity - 8.7 (High)
CVE-2026-42290
github.com/protobufjs/protobuf.js
protobufjs-cli: OS Command Injection
13 May
Fix available
Severity - 7.8 (High)
CVE-2026-45740
github.com/protobufjs/protobuf.js
protobufjs: Denial of Service via unbounded recursive JSON descriptor expansion
13 May
Fix available
Severity - 5.3 (Medium)
CVE-2026-44294
github.com/protobufjs/protobuf.js
protobufjs: Denial of service from crafted field names in generated code
13 May
Fix available
Severity - 5.3 (Medium)
CVE-2026-44293
github.com/protobufjs/protobuf.js
protobufjs: Code injection through bytes field defaults in generated toObject code
13 May
Fix available
Severity - 7.7 (High)
CVE-2026-44292
github.com/protobufjs/protobuf.js
protobufjs: Prototype injection in generated message constructors
13 May
Fix available
Severity - 5.3 (Medium)
CVE-2026-44291
github.com/protobufjs/protobuf.js
protobufjs: Code generation gadget after prototype pollution
13 May
Fix available
Severity - 8.1 (High)
CVE-2026-44290
github.com/protobufjs/protobuf.js
protobufjs: Process-wide denial of service through unsafe option paths
13 May
Fix available
Severity - 7.5 (High)
CVE-2026-44289
github.com/protobufjs/protobuf.js
protobufjs: Denial of service through unbounded protobuf recursion
13 May
Fix available
Severity - 7.5 (High)
CVE-2026-44288
github.com/protobufjs/protobuf.js
protobufjs: Overlong UTF-8 decoding
13 May
Fix available
Severity - 5.3 (Medium)
Load more...
Vulnerability Database - OSV