Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4

Количество 4

redhat логотип

CVE-2026-59877

26 дней назад

protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.6.5 and 8.6.6, protobufjs parsed option names by advancing through schema tokens until reaching an = token without checking for end of input, so a crafted .proto schema that opens an option declaration and ends prematurely can cause parse, Root.load, or Root.loadSync to loop indefinitely. This issue is fixed in versions 7.6.5 and 8.6.6.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-59877

26 дней назад

protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.6.5 and 8.6.6, protobufjs parsed option names by advancing through schema tokens until reaching an = token without checking for end of input, so a crafted .proto schema that opens an option declaration and ends prematurely can cause parse, Root.load, or Root.loadSync to loop indefinitely. This issue is fixed in versions 7.6.5 and 8.6.6.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2026-59877

26 дней назад

protobufjs compiles protobuf definitions into JavaScript (JS) function ...

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-j3f2-48v5-ccww

14 дней назад

protobufjs: Denial of Service via infinite loop in .proto option parsing

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2026-59877

protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.6.5 and 8.6.6, protobufjs parsed option names by advancing through schema tokens until reaching an = token without checking for end of input, so a crafted .proto schema that opens an option declaration and ends prematurely can cause parse, Root.load, or Root.loadSync to loop indefinitely. This issue is fixed in versions 7.6.5 and 8.6.6.

CVSS3: 7.5
0%
Низкий
26 дней назад
nvd логотип
CVE-2026-59877

protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.6.5 and 8.6.6, protobufjs parsed option names by advancing through schema tokens until reaching an = token without checking for end of input, so a crafted .proto schema that opens an option declaration and ends prematurely can cause parse, Root.load, or Root.loadSync to loop indefinitely. This issue is fixed in versions 7.6.5 and 8.6.6.

CVSS3: 5.3
0%
Низкий
26 дней назад
debian логотип
CVE-2026-59877

protobufjs compiles protobuf definitions into JavaScript (JS) function ...

CVSS3: 5.3
0%
Низкий
26 дней назад
github логотип
GHSA-j3f2-48v5-ccww

protobufjs: Denial of Service via infinite loop in .proto option parsing

CVSS3: 5.3
0%
Низкий
14 дней назад

Уязвимостей на страницу