protobufjs: Denial of Service via infinite loop in .proto option parsing
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.3epss 0.4%
exploitation probability
0.4%top 70% of all CVEs
observed exploitation
nono source reports it
protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.6.5 and 8.6.6, protobufjs parsed option names by advancing through schema tokens until reaching an = token without checking for end of input, so a crafted .proto schema that opens an option declaration and ends prematurely can cause parse, Root.load, or Root.loadSync to loop indefinitely. This issue is fixed in versions 7.6.5 and 8.6.6.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Affected products
protobufjs · protobuf.jsReferences
https://github.com/protobufjs/protobuf.js/commit/10fba6d54815ceecca8a06b9a6db490c8f5d2217https://github.com/protobufjs/protobuf.js/commit/fa5c73add738ceb471e74da8cc2f3727c3d0a69fhttps://github.com/protobufjs/protobuf.js/pull/2352https://github.com/protobufjs/protobuf.js/releases/tag/protobufjs-v7.6.5https://github.com/protobufjs/protobuf.js/releases/tag/protobufjs-v8.6.6https://github.com/protobufjs/protobuf.js/security/advisories/GHSA-j3f2-48v5-ccww