CVE-2026-44290: high-severity vulnerability in protobufjs protobuf.js
protobufjs: Process-wide denial of service through unsafe option paths
Published · Updated
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.5epss 0.5%
exploitation probability
0.5%top 59% of all CVEs
observed exploitation
nono source reports it
protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs allowed certain schema option paths to traverse through inherited object properties while applying options. A crafted protobuf schema or JSON descriptor could cause option handling to write to properties on global JavaScript constructors, corrupting process-wide built-in functionality. This vulnerability is fixed in 7.5.6 and 8.0.2.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
protobufjs · protobuf.jsRelated CVEs — protobufjs protobuf.js
In the same product, most dangerous first.
CVE-2026-41242CRITICALprotobufjs has an arbitrary code execution issueEPSS 1.0%CVE-2026-44293HIGHprotobufjs: Code injection through bytes field defaults in generated toObject codeEPSS 0.7%CVE-2026-44289HIGHprotobufjs: Denial of service through unbounded protobuf recursionEPSS 0.7%CVE-2026-59877MEDIUMprotobufjs: Denial of Service via infinite loop in .proto option parsingEPSS 0.7%CVE-2026-48712HIGHprotobufjs: Denial of service through unbounded Any expansion during JSON conversionEPSS 0.5%CVE-2026-45740MEDIUMprotobufjs: Denial of Service via unbounded recursive JSON descriptor expansionEPSS 0.5%