Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

protobufjs — Vulnerabilities & Security Advisories 17

Browse all 17 CVE security advisories affecting protobufjs. AI-powered Chinese analysis, POCs, and references for each vulnerability.

This page aggregates security vulnerabilities associated with the vendor protobufjs, focusing on the library's implementation of the Protocol Buffers serialization framework. It collects reported defects such as denial of service, memory safety issues, and logic errors, covering advisories published over the past decade. Readers can use this resource to track the vendor's security posture, understand specific weakness classes affecting the product, and review the historical vulnerability landscape without needing to search individual databases.

Top products by protobufjs: protobuf.js protobufjs-cli
CVE ID Title CVSS Severity Published
CVE-2026-59876 protobufjs: Text Format string map parsing can mutate returned map object prototype — protobuf.js CWE-1321 4.8 Medium 2026-07-08
CVE-2026-59877 protobufjs: Denial of Service via infinite loop in .proto option parsing — protobuf.js CWE-835 5.3 Medium 2026-07-08
CVE-2026-54269 protobufjs: Schema-derived names can shadow runtime-significant properties — protobuf.js CWE-674 5.3 Medium 2026-06-22
CVE-2026-48712 protobufjs: Denial of service through unbounded Any expansion during JSON conversion — protobuf.js CWE-674 7.5 High 2026-06-22
CVE-2026-54270 protobufjs: Memory amplification from preserved unknown fields in binary decode — protobuf.js CWE-770 5.3 Medium 2026-06-22
CVE-2026-54271 protobufjs-cli: Code injection in pbjs static output from crafted JSON descriptor names — protobufjs-cli CWE-94 8.2 High 2026-06-22
CVE-2026-44295 protobufjs-cli: Code injection in pbjs static output from crafted schema names — protobuf.js CWE-94 8.7 High 2026-05-13
CVE-2026-42290 protobufjs-cli: OS Command Injection — protobuf.js CWE-78 7.8 High 2026-05-13
CVE-2026-45740 protobufjs: Denial of Service via unbounded recursive JSON descriptor expansion — protobuf.js CWE-674 5.3 Medium 2026-05-13
CVE-2026-44294 protobufjs: Denial of service from crafted field names in generated code — protobuf.js CWE-20 5.3 Medium 2026-05-13
CVE-2026-44293 protobufjs: Code injection through bytes field defaults in generated toObject code — protobuf.js CWE-94 7.7 High 2026-05-13
CVE-2026-44292 protobufjs: Prototype injection in generated message constructors — protobuf.js CWE-1321 5.3 Medium 2026-05-13
CVE-2026-44291 protobufjs: Code generation gadget after prototype pollution — protobuf.js CWE-94 8.1 High 2026-05-13
CVE-2026-44290 protobufjs: Process-wide denial of service through unsafe option paths — protobuf.js CWE-1321 7.5 High 2026-05-13
CVE-2026-44289 protobufjs: Denial of service through unbounded protobuf recursion — protobuf.js CWE-674 7.5 High 2026-05-13
CVE-2026-44288 protobufjs: Overlong UTF-8 decoding — protobuf.js CWE-176 5.3 Medium 2026-05-13
CVE-2026-41242 protobufjs has an arbitrary code execution issue — protobuf.js CWE-94 9.4 Critical 2026-04-18

This page lists every published CVE security advisory associated with protobufjs. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.