Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-48712

Опубликовано: 22 июн. 2026
Источник: redhat
CVSS3: 7.5

Описание

protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.6.1 and 8.4.1, protobufjs could recurse without a depth limit while converting decoded messages to plain objects or JSON. This affected generated toObject() conversion and the custom google.protobuf.Any JSON conversion path. A crafted protobuf binary payload containing deeply nested Any values could cause the JavaScript call stack to be exhausted during conversion to JSON. This vulnerability is fixed in 7.6.1 and 8.4.1.

A flaw was found in protobufjs. A remote attacker could exploit this by sending a crafted protobuf binary payload containing deeply nested 'Any' values. This uncontrolled recursion could exhaust the JavaScript call stack during conversion to JSON, leading to a Denial of Service (DoS).

Отчет

Red Hat rates this issue as having Low impact for Red Hat Enterprise Linux AI bootc images. Although protobufjs is present as a transitive dependency, the vulnerable parsing path is not exercised in normal product operation.

Меры по смягчению последствий

No specific mitigation required for unaffected runtime paths.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 4grafana-infinity-datasource-npmNot affected
OpenShift Pipelinesopenshift-pipelines/pipelines-console-plugin-pf5-rhel9Not affected
OpenShift Pipelinesopenshift-pipelines/pipelines-console-plugin-rhel8Not affected
OpenShift Pipelinesopenshift-pipelines/pipelines-console-plugin-rhel9Not affected
OpenShift Service Mesh 3openshift-service-mesh/kiali-ossmc-rhel9Not affected
OpenShift Service Mesh 3openshift-service-mesh/kiali-rhel9Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/gateway-rhel9Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-27/gateway-rhel9Not affected
Red Hat Ansible Automation Platform 2automation-platform-uiNot affected
Red Hat Build of Podman Desktoprh-podman-desktop.gitNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-606
https://bugzilla.redhat.com/show_bug.cgi?id=2491451protobufjs: protobufjs: Denial of Service via uncontrolled recursion with crafted protobuf payload

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
около 2 месяцев назад

protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.6.1 and 8.4.1, protobufjs could recurse without a depth limit while converting decoded messages to plain objects or JSON. This affected generated toObject() conversion and the custom google.protobuf.Any JSON conversion path. A crafted protobuf binary payload containing deeply nested Any values could cause the JavaScript call stack to be exhausted during conversion to JSON. This vulnerability is fixed in 7.6.1 and 8.4.1.

CVSS3: 7.5
debian
около 2 месяцев назад

protobufjs compiles protobuf definitions into JavaScript (JS) function ...

CVSS3: 7.5
github
около 2 месяцев назад

protobufjs: Denial of service through unbounded Any expansion during JSON conversion

7.5 High

CVSS3