Vulnerabilidades en protobufjs
17 resultadosAnálisis Vexday
O protobufjs apresenta panorama de risco concentrado e recente: 16 das 17 vulnerabilidades foram publicadas nos últimos 90 dias, indicando descobertas em cascata. Embora nenhuma esteja sob exploração ativa conhecida, a fraqueza dominante é execução arbitrária de código (CWE-94), com uma crítica no escopo, exigindo monitoramento atento da adoção de patches.
CVE-2026-41242CRITICALprotobufjs has an arbitrary code execution issueEPSS 0.7%CVE-2026-44289HIGHprotobufjs: Denial of service through unbounded protobuf recursionEPSS 0.6%CVE-2026-44291HIGHprotobufjs: Code generation gadget after prototype pollutionEPSS 0.5%CVE-2026-48712HIGHprotobufjs: Denial of service through unbounded Any expansion during JSON conversionEPSS 0.5%CVE-2026-44294MEDIUMprotobufjs: Denial of service from crafted field names in generated codeEPSS 0.4%CVE-2026-54270MEDIUMprotobufjs: Memory amplification from preserved unknown fields in binary decodeEPSS 0.4%CVE-2026-54269MEDIUMprotobufjs: Schema-derived names can shadow runtime-significant propertiesEPSS 0.4%CVE-2026-44295HIGHprotobufjs-cli: Code injection in pbjs static output from crafted schema namesEPSS 0.4%CVE-2026-44293HIGHprotobufjs: Code injection through bytes field defaults in generated toObject codeEPSS 0.4%CVE-2026-44290HIGHprotobufjs: Process-wide denial of service through unsafe option pathsEPSS 0.4%CVE-2026-59877MEDIUMprotobufjs: Denial of Service via infinite loop in .proto option parsingEPSS 0.4%CVE-2026-54271HIGHprotobufjs-cli: Code injection in pbjs static output from crafted JSON descriptor namesEPSS 0.3%CVE-2026-44288MEDIUMprotobufjs: Overlong UTF-8 decodingEPSS 0.3%CVE-2026-44292MEDIUMprotobufjs: Prototype injection in generated message constructorsEPSS 0.3%CVE-2026-45740MEDIUMprotobufjs: Denial of Service via unbounded recursive JSON descriptor expansionEPSS 0.3%CVE-2026-59876MEDIUMprotobufjs: Text Format string map parsing can mutate returned map object prototypeEPSS 0.2%CVE-2026-42290HIGHprotobufjs-cli: OS Command InjectionEPSS 0.1%