Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-59876

Опубликовано: 08 июл. 2026
Источник: redhat
CVSS3: 4.8
EPSS Низкий

Описание

protobufjs compiles protobuf definitions into JavaScript (JS) functions. From 8.2.0 until 8.6.5, the protobufjs Text Format extension parsed string-keyed map entries using ordinary property assignment, allowing a map entry with key proto to change the prototype of the returned map object instead of creating an own map entry in protobufjs/ext/textformat. This issue is fixed in version 8.6.5.

A flaw was found in protobufjs. The Text Format extension, responsible for compiling protobuf definitions into JavaScript functions, improperly parsed string-keyed map entries. This allowed a specially crafted map entry with the key __proto__ to modify the prototype of the returned map object. An attacker could exploit this to alter object behavior, potentially leading to information disclosure or other impacts.

Отчет

This Moderate-impact flaw in protobufjs allows an attacker to perform prototype pollution by providing specially crafted input to the Text Format extension. This could lead to information disclosure or other impacts by altering the behavior of JavaScript objects within applications utilizing protobufjs to process protobuf definitions.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 4grafana-infinity-datasource-npmUnder investigation
OpenShift Pipelinesopenshift-pipelines/pipelines-console-plugin-pf5-rhel9Not affected
OpenShift Pipelinesopenshift-pipelines/pipelines-console-plugin-rhel8Not affected
OpenShift Pipelinesopenshift-pipelines/pipelines-console-plugin-rhel9Not affected
OpenShift Service Mesh 3openshift-service-mesh/kiali-ossmc-rhel9Under investigation
OpenShift Service Mesh 3openshift-service-mesh/kiali-rhel9Under investigation
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/gateway-rhel9Under investigation
Red Hat Ansible Automation Platform 2ansible-automation-platform-27/gateway-rhel9Under investigation
Red Hat Ansible Automation Platform 2automation-platform-uiUnder investigation
Red Hat Build of Podman Desktoprh-podman-desktop.gitUnder investigation

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-915
https://bugzilla.redhat.com/show_bug.cgi?id=2498129protobufjs: protobufjs: Prototype pollution vulnerability in Text Format extension

EPSS

Процентиль: 13%
0.00219
Низкий

4.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.8
nvd
26 дней назад

protobufjs compiles protobuf definitions into JavaScript (JS) functions. From 8.2.0 until 8.6.5, the protobufjs Text Format extension parsed string-keyed map entries using ordinary property assignment, allowing a map entry with key __proto__ to change the prototype of the returned map object instead of creating an own map entry in protobufjs/ext/textformat. This issue is fixed in version 8.6.5.

CVSS3: 4.8
debian
26 дней назад

protobufjs compiles protobuf definitions into JavaScript (JS) function ...

CVSS3: 4.8
github
14 дней назад

protobufjs: Text Format string map parsing can mutate returned map object prototype

EPSS

Процентиль: 13%
0.00219
Низкий

4.8 Medium

CVSS3

Уязвимость CVE-2026-59876