Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-44288

Опубликовано: 13 мая 2026
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs includes a minimal UTF-8 decoder that accepted overlong UTF-8 byte sequences and decoded them to their canonical characters instead of replacing them. An attacker who can provide protobuf binary data decoded through the affected UTF-8 path may be able to bypass application-level checks that inspect raw bytes before protobuf string decoding. For example, bytes that do not contain certain ASCII characters could decode to strings containing those characters. This vulnerability is fixed in 7.5.6 and 8.0.2.

A flaw was found in protobufjs, a library that compiles protobuf definitions into JavaScript functions. An attacker who can provide specially crafted protobuf binary data containing overlong UTF-8 (Unicode Transformation Format - 8-bit) byte sequences may be able to bypass application-level checks. This occurs because the minimal UTF-8 decoder in protobufjs incorrectly decodes these sequences to their canonical characters instead of rejecting them. This could lead to unexpected data interpretation and potentially allow an attacker to circumvent security controls.

Отчет

Moderate: A flaw in protobufjs, as used in Red Hat products, allows an attacker to bypass application-level security checks. By providing specially crafted protobuf binary data with overlong UTF-8 sequences, an attacker could cause incorrect data interpretation, potentially circumventing security controls that inspect raw bytes before string decoding. This could lead to unintended behavior or access within applications relying on protobufjs for data processing.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Pipelinesopenshift-pipelines/pipelines-console-plugin-rhel8Fix deferred
OpenShift Pipelinesopenshift-pipelines/pipelines-console-plugin-rhel9Fix deferred
OpenShift Service Mesh 3openshift-service-mesh/kiali-ossmc-rhel9Fix deferred
OpenShift Service Mesh 3openshift-service-mesh/kiali-rhel9Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/gateway-rhel9Fix deferred
Red Hat Ansible Automation Platform 2automation-platform-uiFix deferred
Red Hat Build of Podman Desktoprh-podman-desktop.gitFix deferred
Red Hat Ceph Storage 9rhceph/alloy-rhel10Fix deferred
Red Hat Developer Hubrhdh/rhdh-hub-rhel9Fix deferred
Red Hat Enterprise Linux 8grafanaFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-76
https://bugzilla.redhat.com/show_bug.cgi?id=2477083protobufjs: protobufjs: Security control bypass due to improper handling of overlong UTF-8 sequences

EPSS

Процентиль: 22%
0.00301
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
3 месяца назад

protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs includes a minimal UTF-8 decoder that accepted overlong UTF-8 byte sequences and decoded them to their canonical characters instead of replacing them. An attacker who can provide protobuf binary data decoded through the affected UTF-8 path may be able to bypass application-level checks that inspect raw bytes before protobuf string decoding. For example, bytes that do not contain certain ASCII characters could decode to strings containing those characters. This vulnerability is fixed in 7.5.6 and 8.0.2.

CVSS3: 5.3
debian
3 месяца назад

protobufjs compiles protobuf definitions into JavaScript (JS) function ...

CVSS3: 5.3
github
3 месяца назад

protobufjs has overlong UTF-8 decoding

CVSS3: 5.3
fstec
3 месяца назад

Уязвимость декодера UTF-8 библиотеки для работы с протоколом Protocol Buffers (Protobuf) protobufjs, позволяющая нарушителю обойти существующие механизмы безопасности

EPSS

Процентиль: 22%
0.00301
Низкий

5.3 Medium

CVSS3