Количество 5
Количество 5
CVE-2026-44289
protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs could recurse without a depth limit while decoding nested protobuf data. This affected both skipping unknown group fields and generated decoding of nested message fields. A crafted protobuf binary payload could cause the JavaScript call stack to be exhausted during decoding. This vulnerability is fixed in 7.5.6 and 8.0.2.
CVE-2026-44289
protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs could recurse without a depth limit while decoding nested protobuf data. This affected both skipping unknown group fields and generated decoding of nested message fields. A crafted protobuf binary payload could cause the JavaScript call stack to be exhausted during decoding. This vulnerability is fixed in 7.5.6 and 8.0.2.
CVE-2026-44289
protobufjs compiles protobuf definitions into JavaScript (JS) function ...
GHSA-685m-2w69-288q
protobuf.js: Denial of service through unbounded protobuf recursion
BDU:2026-09107
Уязвимость декодера библиотеки для работы с протоколом Protocol Buffers (Protobuf) protobufjs, позволяющая нарушителю вызвать отказ в обслуживании
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-44289 protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs could recurse without a depth limit while decoding nested protobuf data. This affected both skipping unknown group fields and generated decoding of nested message fields. A crafted protobuf binary payload could cause the JavaScript call stack to be exhausted during decoding. This vulnerability is fixed in 7.5.6 and 8.0.2. | CVSS3: 7.5 | 1% Низкий | 3 месяца назад | |
CVE-2026-44289 protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs could recurse without a depth limit while decoding nested protobuf data. This affected both skipping unknown group fields and generated decoding of nested message fields. A crafted protobuf binary payload could cause the JavaScript call stack to be exhausted during decoding. This vulnerability is fixed in 7.5.6 and 8.0.2. | CVSS3: 7.5 | 1% Низкий | 3 месяца назад | |
CVE-2026-44289 protobufjs compiles protobuf definitions into JavaScript (JS) function ... | CVSS3: 7.5 | 1% Низкий | 3 месяца назад | |
GHSA-685m-2w69-288q protobuf.js: Denial of service through unbounded protobuf recursion | CVSS3: 7.5 | 1% Низкий | 3 месяца назад | |
BDU:2026-09107 Уязвимость декодера библиотеки для работы с протоколом Protocol Buffers (Protobuf) protobufjs, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 7.5 | 1% Низкий | 3 месяца назад |
Уязвимостей на страницу