Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5

Количество 5

redhat логотип

CVE-2026-44291

3 месяца назад

protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs used plain objects with inherited prototypes for internal type lookup tables used by generated encode and decode functions. If Object.prototype had already been polluted, those lookup tables could resolve attacker-controlled inherited properties as valid protobuf type information. This could cause attacker-controlled strings to be emitted into generated JavaScript code. This vulnerability is fixed in 7.5.6 and 8.0.2.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2026-44291

3 месяца назад

protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs used plain objects with inherited prototypes for internal type lookup tables used by generated encode and decode functions. If Object.prototype had already been polluted, those lookup tables could resolve attacker-controlled inherited properties as valid protobuf type information. This could cause attacker-controlled strings to be emitted into generated JavaScript code. This vulnerability is fixed in 7.5.6 and 8.0.2.

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2026-44291

3 месяца назад

protobufjs compiles protobuf definitions into JavaScript (JS) function ...

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-75px-5xx7-5xc7

3 месяца назад

protobuf.js: Code generation gadget after prototype pollution

CVSS3: 8.1
EPSS: Низкий
fstec логотип

BDU:2026-09089

3 месяца назад

Уязвимость функции JavaScript (JS) библиотеки для работы с протоколом Protocol Buffers (Protobuf) protobufjs, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2026-44291

protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs used plain objects with inherited prototypes for internal type lookup tables used by generated encode and decode functions. If Object.prototype had already been polluted, those lookup tables could resolve attacker-controlled inherited properties as valid protobuf type information. This could cause attacker-controlled strings to be emitted into generated JavaScript code. This vulnerability is fixed in 7.5.6 and 8.0.2.

CVSS3: 8.1
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-44291

protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs used plain objects with inherited prototypes for internal type lookup tables used by generated encode and decode functions. If Object.prototype had already been polluted, those lookup tables could resolve attacker-controlled inherited properties as valid protobuf type information. This could cause attacker-controlled strings to be emitted into generated JavaScript code. This vulnerability is fixed in 7.5.6 and 8.0.2.

CVSS3: 8.1
0%
Низкий
3 месяца назад
debian логотип
CVE-2026-44291

protobufjs compiles protobuf definitions into JavaScript (JS) function ...

CVSS3: 8.1
0%
Низкий
3 месяца назад
github логотип
GHSA-75px-5xx7-5xc7

protobuf.js: Code generation gadget after prototype pollution

CVSS3: 8.1
0%
Низкий
3 месяца назад
fstec логотип
BDU:2026-09089

Уязвимость функции JavaScript (JS) библиотеки для работы с протоколом Protocol Buffers (Protobuf) protobufjs, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.1
0%
Низкий
3 месяца назад

Уязвимостей на страницу