Количество 5
Количество 5
CVE-2026-44288
protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs includes a minimal UTF-8 decoder that accepted overlong UTF-8 byte sequences and decoded them to their canonical characters instead of replacing them. An attacker who can provide protobuf binary data decoded through the affected UTF-8 path may be able to bypass application-level checks that inspect raw bytes before protobuf string decoding. For example, bytes that do not contain certain ASCII characters could decode to strings containing those characters. This vulnerability is fixed in 7.5.6 and 8.0.2.
CVE-2026-44288
protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs includes a minimal UTF-8 decoder that accepted overlong UTF-8 byte sequences and decoded them to their canonical characters instead of replacing them. An attacker who can provide protobuf binary data decoded through the affected UTF-8 path may be able to bypass application-level checks that inspect raw bytes before protobuf string decoding. For example, bytes that do not contain certain ASCII characters could decode to strings containing those characters. This vulnerability is fixed in 7.5.6 and 8.0.2.
CVE-2026-44288
protobufjs compiles protobuf definitions into JavaScript (JS) function ...
GHSA-q6x5-8v7m-xcrf
protobufjs has overlong UTF-8 decoding
BDU:2026-09104
Уязвимость декодера UTF-8 библиотеки для работы с протоколом Protocol Buffers (Protobuf) protobufjs, позволяющая нарушителю обойти существующие механизмы безопасности
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-44288 protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs includes a minimal UTF-8 decoder that accepted overlong UTF-8 byte sequences and decoded them to their canonical characters instead of replacing them. An attacker who can provide protobuf binary data decoded through the affected UTF-8 path may be able to bypass application-level checks that inspect raw bytes before protobuf string decoding. For example, bytes that do not contain certain ASCII characters could decode to strings containing those characters. This vulnerability is fixed in 7.5.6 and 8.0.2. | CVSS3: 5.3 | 0% Низкий | 3 месяца назад | |
CVE-2026-44288 protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs includes a minimal UTF-8 decoder that accepted overlong UTF-8 byte sequences and decoded them to their canonical characters instead of replacing them. An attacker who can provide protobuf binary data decoded through the affected UTF-8 path may be able to bypass application-level checks that inspect raw bytes before protobuf string decoding. For example, bytes that do not contain certain ASCII characters could decode to strings containing those characters. This vulnerability is fixed in 7.5.6 and 8.0.2. | CVSS3: 5.3 | 0% Низкий | 3 месяца назад | |
CVE-2026-44288 protobufjs compiles protobuf definitions into JavaScript (JS) function ... | CVSS3: 5.3 | 0% Низкий | 3 месяца назад | |
GHSA-q6x5-8v7m-xcrf protobufjs has overlong UTF-8 decoding | CVSS3: 5.3 | 0% Низкий | 3 месяца назад | |
BDU:2026-09104 Уязвимость декодера UTF-8 библиотеки для работы с протоколом Protocol Buffers (Protobuf) protobufjs, позволяющая нарушителю обойти существующие механизмы безопасности | CVSS3: 5.3 | 0% Низкий | 3 месяца назад |
Уязвимостей на страницу