CVE-2026-41242
protobufjs compiles protobuf definitions into JavaScript (JS) functions. In versions prior to 8.0.1 and 7.5.5, attackers can inject arbitrary code in the "type" fields of protobuf definitions, which will then execute during object decoding using that definition. Versions 8.0.1 and 7.5.5 patch the issue.
CVSS
- Versión: 4.0
- Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Puntuación base: 9.4
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.99%
- Percentil entre todas las CVEs puntuadas: 61
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1210Exploitation of Remote Serviceslateral movement75 % - Impacto principal
T1059Command and Scripting Interpreterexecution85 % - Impacto secundario
T1565Data Manipulationimpact60 %
AV:N/PR:L sin UI:R indica explotación remota con privilegios (T1210). CWE-94 (code injection) en campos 'type' permite ejecución arbitraria de código JS durante decodificación (T1059). Potencial manipulación de datos decodificados (T1565).
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-94
- CWE-94
Referencias
- https://github.com/protobufjs/protobuf.js/commit/535df444ac060243722ac5d672db205e5c531d75
- https://github.com/protobufjs/protobuf.js/commit/ff7b2afef8754837cc6dc64c864cd111ab477956
- https://github.com/protobufjs/protobuf.js/releases/tag/protobufjs-v7.5.5
- https://github.com/protobufjs/protobuf.js/releases/tag/protobufjs-v8.0.1
- https://github.com/protobufjs/protobuf.js/security/advisories/GHSA-xq3m-2v4x-88gg
- https://access.redhat.com/errata/RHSA-2026:21338
- https://access.redhat.com/errata/RHSA-2026:24977
- https://access.redhat.com/errata/RHSA-2026:26234
- https://access.redhat.com/errata/RHSA-2026:37275
- https://access.redhat.com/errata/RHSA-2026:62260
- https://access.redhat.com/security/cve/CVE-2026-41242
- https://bugzilla.redhat.com/show_bug.cgi?id=2459442
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41242.json
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-41242",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-41242",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "yes"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2026-04-20T16:03:39.054181Z"
}
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
},
{
"type": "Secondary",
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "NOT_DEFINED",
"baseScore": 9.4,
"Automatable": "NOT_DEFINED",
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"exploitMaturity": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"privilegesRequired": "LOW",
"subIntegrityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "HIGH",
"vulnAvailabilityImpact": "HIGH",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "protobufjs",
"product": "protobuf.js",
"versions": [
{
"status": "affected",
"version": "< 7.5.5"
},
{
"status": "affected",
"version": ">= 8.0.0-experimental, < 8.0.1"
}
]
}
]
},
{
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
"affectedData": [
{
"cpes": [
"cpe:/a:redhat:rhdh:1.8::el9"
],
"vendor": "Red Hat",
"product": "Red Hat Developer Hub 1.8",
"versions": [
{
"status": "unaffected",
"version": "1779841586",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "rhdh/rhdh-hub-rhel9",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:rhdh:1.9::el9"
],
"vendor": "Red Hat",
"product": "Red Hat Developer Hub 1.9",
"versions": [
{
"status": "unaffected",
"version": "1781187342",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "rhdh/rhdh-hub-rhel9",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_ai:2.25::el9"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift AI 2.25",
"versions": [
{
"status": "unaffected",
"version": "1780467029",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "rhoai/odh-dashboard-rhel9",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_ai:2.25::el9"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift AI 2.25",
"versions": [
{
"status": "unaffected",
"version": "1780467147",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "rhoai/odh-mod-arch-model-registry-rhel9",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_ai:3.3::el9"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift AI 3.3",
"versions": [
{
"status": "unaffected",
"version": "1783082680",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "rhoai/odh-mod-arch-maas-rhel9",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_devspaces:3.30::el9"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift Dev Spaces 3.30",
"versions": [
{
"status": "unaffected",
"version": "1787762793",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "devspaces/code-rhel9",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:cryostat:4"
],
"vendor": "Red Hat",
"product": "Cryostat 4",
"packageName": "grafana-infinity-datasource-npm",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_pipelines:1"
],
"vendor": "Red Hat",
"product": "OpenShift Pipelines",
"packageName": "openshift-pipelines/pipelines-console-plugin-rhel8",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_pipelines:1"
],
"vendor": "Red Hat",
"product": "OpenShift Pipelines",
"packageName": "openshift-pipelines/pipelines-console-plugin-rhel9",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:service_mesh:3"
],
"vendor": "Red Hat",
"product": "OpenShift Service Mesh 3",
"packageName": "openshift-service-mesh/kiali-ossmc-rhel9",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "unaffected"
},
{
"cpes": [
"cpe:/a:redhat:service_mesh:3"
],
"vendor": "Red Hat",
"product": "OpenShift Service Mesh 3",
"packageName": "openshift-service-mesh/kiali-rhel9",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "unaffected"
},
{
"cpes": [
"cpe:/a:redhat:ansible_automation_platform:2"
],
"vendor": "Red Hat",
"product": "Red Hat Ansible Automation Platform 2",
"packageName": "ansible-automation-platform-26/gateway-rhel9",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "unaffected"
},
{
"cpes": [
"cpe:/a:redhat:ansible_automation_platform:2"
],
"vendor": "Red Hat",
"product": "Red Hat Ansible Automation Platform 2",
"packageName": "automation-platform-ui",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "unaffected"
},
{
"cpes": [
"cpe:/a:redhat:apicurio_registry:3"
],
"vendor": "Red Hat",
"product": "Red Hat build of Apicurio Registry 3",
"packageName": "apicurio/apicurio-studio-ui-rhel8",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:podman_desktop:1"
],
"vendor": "Red Hat",
"product": "Red Hat Build of Podman Desktop",
"packageName": "podman-desktop-macos-1-0",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:podman_desktop:1"
],
"vendor": "Red Hat",
"product": "Red Hat Build of Podman Desktop",
"packageName": "podman-desktop-windows-1-0",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:podman_desktop:1"
],
"vendor": "Red Hat",
"product": "Red Hat Build of Podman Desktop",
"packageName": "rh-podman-desktop.git",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:ceph_storage:9"
],
"vendor": "Red Hat",
"product": "Red Hat Ceph Storage 9",
"packageName": "rhceph/alloy-rhel10",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:rhdh:1"
],
"vendor": "Red Hat",
"product": "Red Hat Developer Hub",
"packageName": "rhdh/backstage-community-plugin-catalog-backend-module-scaffolder-relation-processor",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/o:redhat:enterprise_linux:8"
],
"vendor": "Red Hat",
"product": "Red Hat Enterprise Linux 8",
"packageName": "grafana",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "unaffected"
},
{
"cpes": [
"cpe:/o:redhat:enterprise_linux:9"
],
"vendor": "Red Hat",
"product": "Red Hat Enterprise Linux 9",
"packageName": "grafana",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "unaffected"
},
{
"cpes": [
"cpe:/a:redhat:enterprise_linux_ai:3"
],
"vendor": "Red Hat",
"product": "Red Hat Enterprise Linux AI (RHEL AI) 3",
"packageName": "rhelai3/bootc-cuda-rhel9",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:enterprise_linux_ai:3"
],
"vendor": "Red Hat",
"product": "Red Hat Enterprise Linux AI (RHEL AI) 3",
"packageName": "rhelai3/bootc-gaudi-rhel9",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:enterprise_linux_ai:3"
],
"vendor": "Red Hat",
"product": "Red Hat Enterprise Linux AI (RHEL AI) 3",
"packageName": "rhelai3/bootc-rocm-rhel9",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:enterprise_linux_ai:3"
],
"vendor": "Red Hat",
"product": "Red Hat Enterprise Linux AI (RHEL AI) 3",
"packageName": "rhelai3/disk-image-cuda-rhel9",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:hummingbird:1"
],
"vendor": "Red Hat",
"product": "Red Hat Hardened Images",
"packageName": "dotnet9.0",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "unaffected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_ai"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift AI (RHOAI)",
"packageName": "rhoai/odh-dashboard-rhel8",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "unaffected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_ai"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift AI (RHOAI)",
"packageName": "rhoai/odh-kf-notebook-controller-rhel8",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "unaffected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_ai"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift AI (RHOAI)",
"packageName": "rhoai/odh-mlflow-rhel9",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "unaffected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_ai"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift AI (RHOAI)",
"packageName": "rhoai/odh-mod-arch-gen-ai-rhel9",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_ai"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift AI (RHOAI)",
"packageName": "rhoai/odh-notebook-controller-rhel8",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "unaffected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_ai"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift AI (RHOAI)",
"packageName": "rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_ai"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift AI (RHOAI)",
"packageName": "rhoai/odh-pipeline-runtime-minimal-cpu-py312-rhel9",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_ai"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift AI (RHOAI)",
"packageName": "rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_ai"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift AI (RHOAI)",
"packageName": "rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_ai"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift AI (RHOAI)",
"packageName": "rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_ai"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift AI (RHOAI)",
"packageName": "rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_ai"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift AI (RHOAI)",
"packageName": "rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_ai"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift AI (RHOAI)",
"packageName": "rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_ai"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift AI (RHOAI)",
"packageName": "rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_ai"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift AI (RHOAI)",
"packageName": "rhoai/odh-workbench-jupyter-minimal-cpu-py312-rhel9",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_ai"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift AI (RHOAI)",
"packageName": "rhoai/odh-workbench-jupyter-minimal-cuda-py312-rhel9",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_ai"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift AI (RHOAI)",
"packageName": "rhoai/odh-workbench-jupyter-minimal-rocm-py312-rhel9",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_ai"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift AI (RHOAI)",
"packageName": "rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_ai"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift AI (RHOAI)",
"packageName": "rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_ai"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift AI (RHOAI)",
"packageName": "rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_ai"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift AI (RHOAI)",
"packageName": "rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_ai"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift AI (RHOAI)",
"packageName": "rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_ai"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift AI (RHOAI)",
"packageName": "rhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift:4"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift Container Platform 4",
"packageName": "openshift4/ose-console",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "unaffected"
},
{
"cpes": [
"cpe:/a:redhat:openshift:4"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift Container Platform 4",
"packageName": "openshift4/ose-console-rhel9",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift:4"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift Container Platform 4",
"packageName": "redhat-user-workloads/art-images",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_data_foundation:4"
],
"vendor": "Red Hat",
"product": "Red Hat Openshift Data Foundation 4",
"packageName": "odf4/mcg-core-rhel9",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:ansible_portal:2"
],
"vendor": "Red Hat",
"product": "Self-service automation portal 2",
"packageName": "ansible-automation-platform/automation-portal",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
}
]
}
],
"published": "2026-04-18T17:16:13.983",
"references": [
{
"url": "https://github.com/protobufjs/protobuf.js/commit/535df444ac060243722ac5d672db205e5c531d75",
"tags": [
"Patch"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/protobufjs/protobuf.js/commit/ff7b2afef8754837cc6dc64c864cd111ab477956",
"tags": [
"Patch"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/protobufjs/protobuf.js/releases/tag/protobufjs-v7.5.5",
"tags": [
"Product",
"Release Notes"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/protobufjs/protobuf.js/releases/tag/protobufjs-v8.0.1",
"tags": [
"Product",
"Release Notes"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/protobufjs/protobuf.js/security/advisories/GHSA-xq3m-2v4x-88gg",
"tags": [
"Exploit",
"Vendor Advisory"
],
"source": "security-advisories@github.com"
},
{
"url": "https://access.redhat.com/errata/RHSA-2026:21338",
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
},
{
"url": "https://access.redhat.com/errata/RHSA-2026:24977",
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
},
{
"url": "https://access.redhat.com/errata/RHSA-2026:26234",
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
},
{
"url": "https://access.redhat.com/errata/RHSA-2026:37275",
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
},
{
"url": "https://access.redhat.com/errata/RHSA-2026:62260",
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
},
{
"url": "https://access.redhat.com/security/cve/CVE-2026-41242",
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2459442",
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
},
{
"url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41242.json",
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-94"
}
]
},
{
"type": "Secondary",
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
"description": [
{
"lang": "en",
"value": "CWE-94"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "protobufjs compiles protobuf definitions into JavaScript (JS) functions. In versions prior to 8.0.1 and 7.5.5, attackers can inject arbitrary code in the \"type\" fields of protobuf definitions, which will then execute during object decoding using that definition. Versions 8.0.1 and 7.5.5 patch the issue."
}
],
"lastModified": "2026-09-09T13:19:52.820",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:protobufjs_project:protobufjs:*:*:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "B33F3644-D8EE-4332-8792-C4C309241B27",
"versionEndExcluding": "7.5.5"
},
{
"criteria": "cpe:2.3:a:protobufjs_project:protobufjs:8.0.0:*:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "0C88A330-1152-4C46-B3AA-11AA07A9F0A9"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security-advisories@github.com"
}