#protobufjs
CVE-2023-36665 - protobufjs
If an attacker can control the data used to parse or load Protobuf files, they may be able to alter the behavior of JavaScript code by adding or changing functions. This…

Too many irrelevant or confusing CVEs? Use stackflag.com

#protobufjs #rootio #npm #CVE #infosec
CVE-2023-36665: Protobuf.js 6.10.0 to 7.x before 7.2.5 allows malicious data to alter JavaScript code
If an attacker can control the data used to parse or load Protobuf files, they may be able to alter the behavior of JavaScript code by adding or changing.
stackflag.com
September 25, 2026 at 11:30 AM
deps: override form-data, fast-xml-parser and protobufjs past their c…
deps: override form-data, fast-xml-parser and protobufjs past their c… · bluesky-social/atproto@44fa33c
deps: override form-data, fast-xml-parser and protobufjs past their critical advisories (#5532) * 5498 * Comment overrides * add missing override ranges
github.com
September 21, 2026 at 2:07 PM
A new AI review! protobufjs/protobuf.js ⭐3.8/5.0
`protobuf.
https://gitrated.com/protobufjs/protobuf.js
April 1, 2026 at 9:41 PM
September 21, 2026 at 1:38 PM
I'll not be surprised if the following packages will be the target for the next supply chain attack: @parcel/*, core-js, esbuild, protobufjs, vue-demi, spawn-sync, @swc/* unrs-resolver, typescript, shap, exif-reader
May 19, 2026 at 6:00 AM
I'll not be surprised if the following packages will be the target for the next supply chain attack: @parcel/*, core-js, esbuild, protobufjs, vue-demi, spawn-sync, @swc/* unrs-resolver, typescript, shap, exif-reader
May 19, 2026 at 9:00 AM
📌 CVE-2026-44291 - protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs used plain objects with inherited protot... https://www.cyberhub.blog/cves/CVE-2026-44291
CVE-2026-44291
protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs used plain objects with inherited prototypes for internal type lookup tables used by generated encode and decode functions. If Object.prototype had already been polluted, those lookup tables
www.cyberhub.blog
May 14, 2026 at 1:07 PM
rootio's protobufjs package is supposed to protect against exactly the kind of tampering this cve describes
July 4, 2026 at 5:25 AM
🟠 CVE-2026-44289 - High (7.5)

protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2...

https://www.thehackerwire.com/vulnerability/CVE-2026-44289/

#infosec #cybersecurity #CVE #vulnerability #security #patchstack
May 13, 2026 at 4:21 PM
Critical RCE Vulnerability Found in protobufjs Exposes JavaScript Systems to Remote Code Execution Risk

Introduction: A Dangerous Flaw Hidden in a Widely Used JavaScript Library A newly reported cybersecurity issue has revealed a severe remote code execution (RCE) vulnerability in protobuf.js, a…
Critical RCE Vulnerability Found in protobufjs Exposes JavaScript Systems to Remote Code Execution Risk
Introduction: A Dangerous Flaw Hidden in a Widely Used JavaScript Library A newly reported cybersecurity issue has revealed a severe remote code execution (RCE) vulnerability in protobuf.js, a popular JavaScript library used for working with protocol buffers. The flaw allows attackers to execute arbitrary JavaScript code by exploiting unsafe dynamic function creation from schema processing. Security researchers warn that affected versions include protobuf.js ≤ 8.0.0 and ≤ 7.5.4.
undercodenews.com
April 18, 2026 at 7:17 PM
protobuf.js CRITICAL flaw: Code injection (CVSS 9.4) in <7.5.5 & 8.0.0-experimental <8.0.1 risks remote code execution. Patch to 7.5.5 or 8.0.1+ now! https://radar.offseq.com/threat/cve-2026-41242-cwe-94-improper-control-of-generati-3ca40985 #OffSeq #vulnerability #AppSec
CVE-2026-41242: CWE-94: Improper Control of Generation of Code ('Code Injection'
protobufjs compiles protobuf definitions into JavaScript functions. In affected versions (<7.5.5 and >=8.0.0-experimental but <8.0.1), attackers can exploit improper control of code generation (CWE-94) by injecting arbitrary code into the "
radar.offseq.com
April 19, 2026 at 6:00 AM
🚨 EUVD-2026-30031
📊 7.7/10
🏢 protobufjs

📝 protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs generated JavaScript for toObject convers...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-30031

#cybersecurity #infosec #cve #euvd
July 22, 2026 at 2:01 PM
🚨 EUVD-2026-30027
📊 7.5/10
🏢 protobufjs

📝 protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs could recurse without a depth limit while...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-30027

#cybersecurity #infosec #cve #euvd
July 22, 2026 at 2:01 PM
📌 CVE-2026-54271 - protobufjs-cli is the command line add-on for protobuf.js. Prior to 1.3.2 and 2.5.0, a previous fix for unsafe name handling in pbjs static / static-m... https://www.cyberhub.blog/cves/CVE-2026-54271
CVE-2026-54271
protobufjs-cli is the command line add-on for protobuf.js. Prior to 1.3.2 and 2.5.0, a previous fix for unsafe name handling in pbjs static / static-module code generation was incomplete. Affected versions of protobufjs-cli could still emit unsafe JavaScript references when generating static output
www.cyberhub.blog
July 20, 2026 at 7:07 AM
Уязвимость CVE-2026-41242 в protobufjs: угроза безопасности и способы защиты

https://kripta.biz/posts/EEC5C695-613F-441B-8E55-57AC8A6BFED9
July 10, 2026 at 3:54 PM
深度解析CVE-2026-41242漏洞:protobufjs的JavaScript编译风险与安全防护指南

https://qian.cx/posts/BEC02869-4EB9-49D5-943B-51B36F8C18A6
July 10, 2026 at 3:54 PM
CVE-2026-41242 - @rootio/protobufjs
The @rootio/protobufjs package in Root:npm has a data tampering risk. This means that an attacker could manipulate data to deceive users. Root has released a patch to fix…

Too many irrelevant or confusing CVEs? Use stackflag.com

#rootio #Rootnpm #CVE #infosec
July 3, 2026 at 10:10 PM
🟠 CVE-2026-42290 - High (7.8)

protobufjs-cli is the command line add-on for protobuf.js. Prior to 1.2.1 and 2.0.2, pbts invoked...

https://www.thehackerwire.com/vulnerability/CVE-2026-42290/

#infosec #cybersecurity #CVE #vulnerability #security #patchstack
May 13, 2026 at 5:54 PM
🟠 CVE-2026-44291 - High (8.1)

protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2...

https://www.thehackerwire.com/vulnerability/CVE-2026-44291/

#infosec #cybersecurity #CVE #vulnerability #security #patchstack
May 13, 2026 at 4:21 PM
🟠 CVE-2026-44290 - High (7.5)

protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2...

https://www.thehackerwire.com/vulnerability/CVE-2026-44290/

#infosec #cybersecurity #CVE #vulnerability #security #patchstack
May 13, 2026 at 4:21 PM
🟠 CVE-2026-44295 - High (8.7)

protobufjs-cli is the command line add-on for protobuf.js. Prior to 1.2.1 and 2.0.2, pbjs static ...

https://www.thehackerwire.com/vulnerability/CVE-2026-44295/

#infosec #cybersecurity #CVE #vulnerability #security #patchstack
May 13, 2026 at 4:20 PM
[nodejs programmer rant]

What really pisses me off is that dependencies hell still have not been resolved as problem in the nodejs.
The aforementioned version of `google-cloud/datastore depends on vulnerable version of that library protobufjs while other dependencies depends on newer version of […]
Original post on mastodon.online
mastodon.online
September 26, 2025 at 12:00 AM