Protobufjs Project
Protobufjs Project Protobufjs: vulnerabilidades y CVE
Protobufjs Project Protobufjs tiene 17 vulnerabilidades publicadas, 14 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE17
Últimos 12 meses14
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-59877 | Alta (7.5) | 0.67% | — | 8 jul 2026 | protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.6.5 and 8.6.6, protobufjs parsed option names by advancing through schema tokens until reaching an = token without checking for end of… |
| CVE-2026-59876 | Media (4.8) | 0.35% | — | 8 jul 2026 | protobufjs compiles protobuf definitions into JavaScript (JS) functions. From 8.2.0 until 8.6.5, the protobufjs Text Format extension parsed string-keyed map entries using ordinary property assignment, allowing a map… |
| CVE-2026-54270 | Media (5.3) | 0.40% | — | 22 jun 2026 | protobufjs compiles protobuf definitions into JavaScript (JS) functions. From 8.2.0 to 8.4.2, protobufjs preserved unknown wire elements in message.$unknowns and did not provide a decode-time option to discard unknown… |
| CVE-2026-54269 | Media (5.3) | 0.40% | — | 22 jun 2026 | protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 8.6.0 and 7.6.3, protobufjs accepted certain schema-derived names that could collide with properties used by protobufjs runtime helpers.… |
| CVE-2026-48712 | Alta (7.5) | 0.46% | — | 22 jun 2026 | protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.6.1 and 8.4.1, protobufjs could recurse without a depth limit while converting decoded messages to plain objects or JSON. This affected… |
| CVE-2026-45740 | Alta (7.5) | 0.46% | — | 13 may 2026 | protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.8 and 8.2.0, protobufjs could recurse without a depth limit while expanding nested JSON descriptors through Root.fromJSON() and… |
| CVE-2026-44294 | Media (5.3) | 0.40% | — | 13 may 2026 | protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs generated JavaScript property accessors from schema-controlled field and oneof names. Certain control… |
| CVE-2026-44293 | Alta (7.7) | 0.73% | — | 13 may 2026 | protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs generated JavaScript for toObject conversion could include an unsafe expression derived from a… |
| CVE-2026-44292 | Media (5.3) | 0.34% | — | 13 may 2026 | protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs generated message constructors copied enumerable properties from a provided properties object without… |
| CVE-2026-44291 | Alta (8.1) | 0.42% | — | 13 may 2026 | protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs used plain objects with inherited prototypes for internal type lookup tables used by generated encode and… |
| CVE-2026-44290 | Alta (7.5) | 0.50% | — | 13 may 2026 | protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs allowed certain schema option paths to traverse through inherited object properties while applying options. A… |
| CVE-2026-44289 | Alta (7.5) | 0.68% | — | 13 may 2026 | protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs could recurse without a depth limit while decoding nested protobuf data. This affected both skipping unknown… |
| CVE-2026-44288 | Media (5.3) | 0.33% | — | 13 may 2026 | protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs includes a minimal UTF-8 decoder that accepted overlong UTF-8 byte sequences and decoded them to their… |
| CVE-2026-41242 | Crítica (9.4) | 0.99% | — | 18 abr 2026 | protobufjs compiles protobuf definitions into JavaScript (JS) functions. In versions prior to 8.0.1 and 7.5.5, attackers can inject arbitrary code in the "type" fields of protobuf definitions, which will then execute… |
| CVE-2023-36665 | Crítica (9.8) | 1.7% | — | 5 jul 2023 | "protobuf.js (aka protobufjs) 6.10.0 through 7.x before 7.2.5 allows Prototype Pollution, a different vulnerability than CVE-2022-25878. A user-controlled protobuf message can be used by an attacker to pollute the… |
| CVE-2022-25878 | Alta (7.5) | 2.4% | — | 27 may 2022 | The package protobufjs before 6.11.3 are vulnerable to Prototype Pollution which can allow an attacker to add/modify properties of the Object.prototype. This vulnerability can occur in multiple ways: 1. by providing… |
| CVE-2018-3738 | Media (5.5) | 0.96% | — | 7 jun 2018 | protobufjs is vulnerable to ReDoS when parsing crafted invalid .proto files. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.