← Voltar à pesquisa de CVEs

CVE-2026-59877

protobufjs

Descrição

protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.6.5 and 8.6.6, protobufjs parsed option names by advancing through schema tokens until reaching an = token without checking for end of input, so a crafted .proto schema that opens an option declaration and ends prematurely can cause parse, Root.load, or Root.loadSync to loop indefinitely. This issue is fixed in versions 7.6.5 and 8.6.6.

CVSS 5.3EPSS 0.37%Risco 0.55
Ver fonte
Publicação
2026-07-08 16:16:34
Versões afetadas
<7.6.5,<8.6.6
Tipo
Biblioteca
Vetor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L