← Zurück zur CVE-Suche

CVE-2026-59877

protobufjs

Beschreibung

protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.6.5 and 8.6.6, protobufjs parsed option names by advancing through schema tokens until reaching an = token without checking for end of input, so a crafted .proto schema that opens an option declaration and ends prematurely can cause parse, Root.load, or Root.loadSync to loop indefinitely. This issue is fixed in versions 7.6.5 and 8.6.6.

CVSS 5.3EPSS 0.37%Risiko 0.55
Quelle öffnen
Veröffentlicht
2026-07-08 16:16:34
Betroffene Versionen
<7.6.5,<8.6.6
Typ
Bibliothek
Vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L