Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-41242

Опубликовано: 18 апр. 2026
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

protobufjs compiles protobuf definitions into JavaScript (JS) functions. In versions prior to 8.0.1 and 7.5.5, attackers can inject arbitrary code in the "type" fields of protobuf definitions, which will then execute during object decoding using that definition. Versions 8.0.1 and 7.5.5 patch the issue.

A flaw was found in protobufjs, a JavaScript (JS) library used for compiling protobuf definitions. A remote attacker with low privileges can exploit this vulnerability by injecting arbitrary code into the "type" fields of protobuf definitions. This malicious code will then execute during the object decoding process, leading to arbitrary code execution and potentially full system compromise.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 4grafana-infinity-datasource-npmUnder investigation
OpenShift Pipelinesopenshift-pipelines/pipelines-console-plugin-rhel8Affected
OpenShift Pipelinesopenshift-pipelines/pipelines-console-plugin-rhel9Affected
OpenShift Service Mesh 3openshift-service-mesh/kiali-ossmc-rhel9Under investigation
OpenShift Service Mesh 3openshift-service-mesh/kiali-rhel9Under investigation
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/gateway-rhel9Under investigation
Red Hat Ansible Automation Platform 2automation-platform-uiUnder investigation
Red Hat build of Apicurio Registry 3apicurio/apicurio-studio-ui-rhel8Will not fix
Red Hat Build of Podman Desktoppodman-desktop-macos-1-0Affected
Red Hat Build of Podman Desktoppodman-desktop-windows-1-0Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-94
https://bugzilla.redhat.com/show_bug.cgi?id=2459442protobufjs: protobufjs: Arbitrary code execution via injected protobuf definition type fields

EPSS

Процентиль: 51%
0.00745
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
4 месяца назад

protobufjs compiles protobuf definitions into JavaScript (JS) functions. In versions prior to 8.0.1 and 7.5.5, attackers can inject arbitrary code in the "type" fields of protobuf definitions, which will then execute during object decoding using that definition. Versions 8.0.1 and 7.5.5 patch the issue.

CVSS3: 9.8
nvd
4 месяца назад

protobufjs compiles protobuf definitions into JavaScript (JS) functions. In versions prior to 8.0.1 and 7.5.5, attackers can inject arbitrary code in the "type" fields of protobuf definitions, which will then execute during object decoding using that definition. Versions 8.0.1 and 7.5.5 patch the issue.

CVSS3: 9.8
debian
4 месяца назад

protobufjs compiles protobuf definitions into JavaScript (JS) function ...

CVSS3: 9.8
github
4 месяца назад

Arbitrary code execution in protobufjs

CVSS3: 9.9
fstec
4 месяца назад

Уязвимость библиотеки для работы с протоколом Protocol Buffers (Protobuf) protobufjs, связанная с неверным управлением генерацией кода, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 51%
0.00745
Низкий

8.8 High

CVSS3