Vendorsprotobufjs Projectprotobufjsany version
Vulnerabilities

protobufjs Project protobufjs any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

17CVEs
CVE-2023-36665
"protobuf.js (aka protobufjs) 6.10.0 through 7.x before 7.2.5 allows Prototype Pollution, a different vulnerability than CVE-2022-25878. A user-controlled protobuf message can be used by an attacker to pollute the prototype of Object.prototype by adding and overwriting its data and functions. Exploitation can involve: (1) using the function parse to parse protobuf messages on the fly, (2) loading .proto files by using load/loadSync functions, or (3) providing untrusted input to the functions ReflectionObject.setParsedOption and util.setProperty.
Published 2023-07-05 · Modified
9.8EPSS 0.017
CVE-2026-41242
protobufjs has an arbitrary code execution issue
Published 2026-04-18 · Modified
9.8EPSS 0.010
CVE-2026-44293
protobufjs: Code injection through bytes field defaults in generated toObject code
Published 2026-05-13 · Modified
8.8EPSS 0.007
CVE-2022-25878
Prototype Pollution
Published 2022-05-27 · Modified
8.2EPSS 0.023
CVE-2026-44291
protobufjs: Code generation gadget after prototype pollution
Published 2026-05-13 · Analyzed
8.1EPSS 0.004
CVE-2026-44289
protobufjs: Denial of service through unbounded protobuf recursion
Published 2026-05-13 · Modified
7.5EPSS 0.007
CVE-2026-59877
protobufjs: Denial of Service via infinite loop in .proto option parsing
Published 2026-07-08 · Analyzed
7.5EPSS 0.007
CVE-2026-44290
protobufjs: Process-wide denial of service through unsafe option paths
Published 2026-05-13 · Analyzed
7.5EPSS 0.005
CVE-2026-45740
protobufjs: Denial of Service via unbounded recursive JSON descriptor expansion
Published 2026-05-13 · Analyzed
7.5EPSS 0.005
CVE-2026-48712
protobufjs: Denial of service through unbounded Any expansion during JSON conversion
Published 2026-06-22 · Analyzed
7.5EPSS 0.005
CVE-2018-3738
protobufjs is vulnerable to ReDoS when parsing crafted invalid .proto files.
Published 2018-06-07 · Modified
5.5EPSS 0.010
CVE-2026-44294
protobufjs: Denial of service from crafted field names in generated code
Published 2026-05-13 · Analyzed
5.3EPSS 0.004
CVE-2026-54269
protobufjs: Schema-derived names can shadow runtime-significant properties
Published 2026-06-22 · Analyzed
5.3EPSS 0.004
CVE-2026-54270
protobufjs: Memory amplification from preserved unknown fields in binary decode
Published 2026-06-22 · Analyzed
5.3EPSS 0.004
CVE-2026-44292
protobufjs: Prototype injection in generated message constructors
Published 2026-05-13 · Analyzed
5.3EPSS 0.003
CVE-2026-44288
protobufjs: Overlong UTF-8 decoding
Published 2026-05-13 · Analyzed
5.3EPSS 0.003
CVE-2026-59876
protobufjs: Text Format string map parsing can mutate returned map object prototype
Published 2026-07-08 · Analyzed
4.8EPSS 0.003