CVE-2026-59876
EUVD-2026-4231108.07.2026, 16:16
protobufjs compiles protobuf definitions into JavaScript (JS) functions. From 8.2.0 until 8.6.5, the protobufjs Text Format extension parsed string-keyed map entries using ordinary property assignment, allowing a map entry with key __proto__ to change the prototype of the returned map object instead of creating an own map entry in protobufjs/ext/textformat. This issue is fixed in version 8.6.5.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| protobufjs_project | protobufjs | 8.2.0 ≤ 𝑥 < 8.6.5 |
𝑥
= Vulnerable software versions
References