CVE-2026-44289
protobufjs: Denial of service through unbounded protobuf recursion
CVSS Score
7.5
EPSS Score
0.6%
EPSS Percentile
44th
protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs could recurse without a depth limit while decoding nested protobuf data. This affected both skipping unknown group fields and generated decoding of nested message fields. A crafted protobuf binary payload could cause the JavaScript call stack to be exhausted during decoding. This vulnerability is fixed in 7.5.6 and 8.0.2.
| CWE | CWE-674 |
| Vendor | protobufjs |
| Product | protobuf.js |
| Published | May 13, 2026 |
| Last Updated | Aug 7, 2026 |
Stay Ahead of the Next One
Get instant alerts for protobufjs protobuf.js
Be the first to know when new high vulnerabilities affecting protobufjs protobuf.js are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Affected Versions
protobufjs / protobuf.js
< 7.5.6 >= 8.0.0, < 8.0.2
References
github.com: https://github.com/protobufjs/protobuf.js/security/advisories/GHSA-685m-2w69-288q access.redhat.com: https://access.redhat.com/security/cve/CVE-2026-44289 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2477130 security.access.redhat.com: https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44289.json access.redhat.com: https://access.redhat.com/errata/RHSA-2026:42815