protobufjs project protobufjs是protobufjs project团队开源的一个ProtocolBuffers解析库。 protobufjs project protobuf.js 8.2.0版本至8.4.2版本存在资源管理错误漏洞,该漏洞源于保留未知有线元素时未提供解码时选项丢弃未知字段,可能导致特制的有效载荷占用大量内存。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| protobufjs | protobuf.js | >=8.2.0, < 8.5.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| protobufjs | protobuf.js | >=8.2.0, < 8.5.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-54271 | 8.2 HIGH | protobufjs-cli: Code injection in pbjs static output from crafted JSON descriptor names |
| CVE-2026-48712 | 7.5 HIGH | protobufjs: Denial of service through unbounded Any expansion during JSON conversion |
| CVE-2026-54269 | 5.3 MEDIUM | protobufjs: Schema-derived names can shadow runtime-significant properties |
No comments yet