Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2731▲ 24 respecto a la semana anterior
Críticas / altas1467▲ 357 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 458 respecto a la semana anterior
41 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.2) | 0.52% | — | Elixir ProtobufAI | 17/9/2026 | 24/9/2026 | Elixir protobuf is a pure Elixir implementation of Google Protobuf. From 0.8.0 until 0.16.1, services that decode attacker-controlled protobuf bytes with Protobuf.Decoder can be taken offline when the schema contains a self-referential or cyclic message type. In lib/protobuf/decoder.ex,… | |
| Pendiente de análisis | Alta (8.7) | 0.28% | — | Google ProtobufAI | 17/9/2026 | 18/9/2026 | google-protobuf contains an unbounded recursion when parsing unknown protobuf group fields. An attacker can send a small crafted payload of deeply nested START_GROUP wire bytes to any Node.js service that calls the generated deserializeBinary() API, causing a RangeError: Maximum call stack size exceeded and crashing… | |
| Analizada | Alta (7.5) | 0.67% | — | Protobufjs Project Protobufjs | 8/7/2026 | 10/7/2026 | protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.6.5 and 8.6.6, protobufjs parsed option names by advancing through schema tokens until reaching an = token without checking for end of input, so a crafted .proto schema that opens an option declaration and ends prematurely can cause… | |
| Analizada | Media (4.8) | 0.35% | — | Protobufjs Project Protobufjs | 8/7/2026 | 13/7/2026 | protobufjs compiles protobuf definitions into JavaScript (JS) functions. From 8.2.0 until 8.6.5, the protobufjs Text Format extension parsed string-keyed map entries using ordinary property assignment, allowing a map entry with key __proto__ to change the prototype of the returned map object instead of creating an own… | |
| Analizada | Alta (8.2) | 0.30% | — | Protobufjs Project Protobufjs-cli | 22/6/2026 | 24/6/2026 | protobufjs-cli is the command line add-on for protobuf.js. Prior to 1.3.2 and 2.5.0, a previous fix for unsafe name handling in pbjs static / static-module code generation was incomplete. Affected versions of protobufjs-cli could still emit unsafe JavaScript references when generating static output from crafted JSON… | |
| Analizada | Media (5.3) | 0.40% | — | Protobufjs Project Protobufjs | 22/6/2026 | 24/6/2026 | protobufjs compiles protobuf definitions into JavaScript (JS) functions. From 8.2.0 to 8.4.2, protobufjs preserved unknown wire elements in message.$unknowns and did not provide a decode-time option to discard unknown fields before retaining them. A crafted protobuf payload containing many unknown fields could… | |
| Analizada | Media (5.3) | 0.40% | — | Protobufjs Project ProtobufjsProtobufjs Project Protobufjs-cli | 22/6/2026 | 24/6/2026 | protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 8.6.0 and 7.6.3, protobufjs accepted certain schema-derived names that could collide with properties used by protobufjs runtime helpers. The known affected names are fields named hasOwnProperty, field or oneof names such as $type when… | |
| Analizada | Alta (7.5) | 0.46% | — | Protobufjs Project Protobufjs | 22/6/2026 | 26/6/2026 | protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.6.1 and 8.4.1, protobufjs could recurse without a depth limit while converting decoded messages to plain objects or JSON. This affected generated toObject() conversion and the custom google.protobuf.Any JSON conversion path. A crafted… | |
| Analizada | Alta (7.5) | 0.46% | — | Protobufjs Project Protobufjs | 13/5/2026 | 17/6/2026 | protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.8 and 8.2.0, protobufjs could recurse without a depth limit while expanding nested JSON descriptors through Root.fromJSON() and Namespace.addJSON(). A crafted JSON descriptor with deeply nested namespace definitions could cause the… | |
| Analizada | Alta (8.7) | 0.36% | — | Protobufjs Project Protobufjs-cli | 13/5/2026 | 17/6/2026 | protobufjs-cli is the command line add-on for protobuf.js. Prior to 1.2.1 and 2.0.2, pbjs static code generation could emit unsafe JavaScript identifiers derived from schema-controlled names. When generating static JavaScript from a crafted schema or JSON descriptor, certain namespace, enum, service, or derived full… | |
| Analizada | Media (5.3) | 0.40% | — | Protobufjs Project Protobufjs | 13/5/2026 | 17/6/2026 | protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs generated JavaScript property accessors from schema-controlled field and oneof names. Certain control characters in field names were not escaped before being embedded into generated function bodies. A crafted… | |
| Modificada | Alta (7.7) | 0.73% | — | Protobufjs Project Protobufjs | 13/5/2026 | 9/9/2026 | protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs generated JavaScript for toObject conversion could include an unsafe expression derived from a schema-controlled bytes field default value. A crafted descriptor with a non-string default value for a bytes… | |
| Analizada | Media (5.3) | 0.34% | — | Protobufjs Project Protobufjs | 13/5/2026 | 17/6/2026 | protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs generated message constructors copied enumerable properties from a provided properties object without filtering the __proto__ key. If an application constructed a message from an attacker-controlled plain… | |
| Analizada | Alta (8.1) | 0.42% | — | Protobufjs Project Protobufjs | 13/5/2026 | 17/6/2026 | protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs used plain objects with inherited prototypes for internal type lookup tables used by generated encode and decode functions. If Object.prototype had already been polluted, those lookup tables could resolve… | |
| Analizada | Alta (7.5) | 0.50% | — | Protobufjs Project Protobufjs | 13/5/2026 | 17/6/2026 | protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs allowed certain schema option paths to traverse through inherited object properties while applying options. A crafted protobuf schema or JSON descriptor could cause option handling to write to properties on… | |
| Modificada | Alta (7.5) | 0.68% | — | Protobufjs Project Protobufjs | 13/5/2026 | 28/8/2026 | protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs could recurse without a depth limit while decoding nested protobuf data. This affected both skipping unknown group fields and generated decoding of nested message fields. A crafted protobuf binary payload… | |
| Analizada | Media (5.3) | 0.33% | — | Protobufjs Project Protobufjs | 13/5/2026 | 17/6/2026 | protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs includes a minimal UTF-8 decoder that accepted overlong UTF-8 byte sequences and decoded them to their canonical characters instead of replacing them. An attacker who can provide protobuf binary data decoded… | |
| Analizada | Alta (7.8) | 0.19% | — | Protobufjs Project Protobufjs-cli | 13/5/2026 | 17/6/2026 | protobufjs-cli is the command line add-on for protobuf.js. Prior to 1.2.1 and 2.0.2, pbts invoked JSDoc by building a shell command string from input file paths and executing it through child_process.exec. File paths containing shell metacharacters could therefore be interpreted by the shell instead of being passed to… | |
| Modificada | Crítica (9.4) | 0.99% | — | Protobufjs Project Protobufjs | 18/4/2026 | 9/9/2026 | protobufjs compiles protobuf definitions into JavaScript (JS) functions. In versions prior to 8.0.1 and 7.5.5, attackers can inject arbitrary code in the "type" fields of protobuf definitions, which will then execute during object decoding using that definition. Versions 8.0.1 and 7.5.5 patch the issue. | |
| Pendiente de análisis | Alta (7.1) | 0.43% | — | Protobuf PHPAI | 16/4/2026 | 17/6/2026 | A Denial of Service (DoS) vulnerability exists in the Protobuf PHP library during the parsing of untrusted input. Maliciously structured messages—specifically those containing negative varints or deep recursion—can be used to crash the application, impacting service availability. | |
| Modificada | Alta (8.2) | 0.72% | — | Google Protobuf | 23/1/2026 | 1/9/2026 | A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages. Due to missing recursion depth accounting inside the internal Any-handling logic, an attacker can supply deeply… | |
| Aplazada | Media (5.9) | 0.44% | — | ProtobufAI | 5/7/2025 | 17/6/2026 | The protobuf crate before 3.7.2 for Rust allows uncontrolled recursion in the protobuf::coded_input_stream::CodedInputStream::skip_group parsing of unknown fields in untrusted input. | |
| Analizada | Alta (8.2) | 0.26% | — | Google Protobuf-python | 16/6/2025 | 17/6/2026 | Any project that uses Protobuf Pure-Python backend to parse untrusted Protocol Buffers data containing an arbitrary number of recursive groups, recursive messages or a series of SGROUP tags can be corrupted by exceeding the Python recursion limit. This can result in a Denial of service by crashing the application with… | |
| Analizada | Alta (8.7) | 2.8% | — | Google ProtobufGoogle Protobuf-javaGoogle Protobuf-javaliteGoogle Protobuf-kotlin+4 | 19/9/2024 | 17/6/2026 | Any project that parses untrusted Protocol Buffers data containing an arbitrary number of nested groups / series of SGROUP tags can corrupted by exceeding the stack limit i.e. StackOverflow. Parsing nested groups as unknown fields with DiscardUnknownFieldsParser or Java Protobuf Lite parser, or against Protobuf map… | |
| Analizada | Crítica (9.8) | 0.33% | — | Google Protobuf | 3/5/2024 | 17/6/2026 | The JsonToBinaryStream() function is part of the protocol buffers C++ implementation and is used to parse JSON from a stream. If the input is broken up into separate chunks in a certain way, the parser will attempt to read bytes from a chunk that has already been freed. |