CVE-2026-44289
EUVD-2026-3002713.05.2026, 16:16
protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs could recurse without a depth limit while decoding nested protobuf data. This affected both skipping unknown group fields and generated decoding of nested message fields. A crafted protobuf binary payload could cause the JavaScript call stack to be exhausted during decoding. This vulnerability is fixed in 7.5.6 and 8.0.2.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| protobufjs_project | protobufjs | 𝑥 < 7.5.6 |
| protobufjs_project | protobufjs | 8.0.0 ≤ 𝑥 < 8.0.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration