Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
CVE-2026-59876
  • github.com/protobufjs/protobuf.js
protobufjs: Text Format string map parsing can mutate returned map object prototype 08 Jul
  • Fix available
  • Severity - 4.8 (Medium)
CVE-2026-59877
  • github.com/protobufjs/protobuf.js
protobufjs: Denial of Service via infinite loop in .proto option parsing 08 Jul
  • Fix available
  • Severity - 5.3 (Medium)
CVE-2026-54269
  • github.com/protobufjs/protobuf.js
protobufjs: Schema-derived names can shadow runtime-significant properties 22 Jun
  • Fix available
  • Severity - 5.3 (Medium)
CVE-2026-48712
  • github.com/protobufjs/protobuf.js
protobufjs: Denial of service through unbounded Any expansion during JSON conversion 22 Jun
  • Fix available
  • Severity - 7.5 (High)
CVE-2026-54270
  • github.com/protobufjs/protobuf.js
protobufjs: Memory amplification from preserved unknown fields in binary decode 22 Jun
  • Fix available
  • Severity - 5.3 (Medium)
CVE-2026-54271
  • github.com/protobufjs/protobuf.js
protobufjs-cli: Code injection in pbjs static output from crafted JSON descriptor names 22 Jun
  • Fix available
  • Severity - 8.2 (High)
CVE-2026-44295
  • github.com/protobufjs/protobuf.js
protobufjs-cli: Code injection in pbjs static output from crafted schema names 13 May
  • Fix available
  • Severity - 8.7 (High)
CVE-2026-42290
  • github.com/protobufjs/protobuf.js
protobufjs-cli: OS Command Injection 13 May
  • Fix available
  • Severity - 7.8 (High)
CVE-2026-45740
  • github.com/protobufjs/protobuf.js
protobufjs: Denial of Service via unbounded recursive JSON descriptor expansion 13 May
  • Fix available
  • Severity - 5.3 (Medium)
CVE-2026-44294
  • github.com/protobufjs/protobuf.js
protobufjs: Denial of service from crafted field names in generated code 13 May
  • Fix available
  • Severity - 5.3 (Medium)
CVE-2026-44293
  • github.com/protobufjs/protobuf.js
protobufjs: Code injection through bytes field defaults in generated toObject code 13 May
  • Fix available
  • Severity - 7.7 (High)
CVE-2026-44292
  • github.com/protobufjs/protobuf.js
protobufjs: Prototype injection in generated message constructors 13 May
  • Fix available
  • Severity - 5.3 (Medium)
CVE-2026-44291
  • github.com/protobufjs/protobuf.js
protobufjs: Code generation gadget after prototype pollution 13 May
  • Fix available
  • Severity - 8.1 (High)
CVE-2026-44290
  • github.com/protobufjs/protobuf.js
protobufjs: Process-wide denial of service through unsafe option paths 13 May
  • Fix available
  • Severity - 7.5 (High)
CVE-2026-44289
  • github.com/protobufjs/protobuf.js
protobufjs: Denial of service through unbounded protobuf recursion 13 May
  • Fix available
  • Severity - 7.5 (High)
CVE-2026-44288
  • github.com/protobufjs/protobuf.js
protobufjs: Overlong UTF-8 decoding 13 May
  • Fix available
  • Severity - 5.3 (Medium)