Security: protobufjs/protobuf.js
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Denial of Service via infinite loop in .proto option parsingGHSA-j3f2-48v5-ccww published
Jul 4, 2026 by alexander-fensterModerate -
Text Format string map parsing can mutate returned map object prototypeGHSA-jfj6-75fj-8934 published
Jul 4, 2026 by dcodeIOModerate -
Certain schema-derived names can shadow runtime-significant propertiesGHSA-f38q-mgvj-vph7 published
Jun 12, 2026 by dcodeIOModerate -
Code injection in pbjs static output from crafted JSON descriptor namesGHSA-pr59-h9ph-3fr8 published
Jun 12, 2026 by dcodeIOHigh -
Memory amplification from preserved unknown fields in binary decodeGHSA-94rc-8x27-4472 published
Jun 12, 2026 by dcodeIOModerate -
Denial of service through unbounded Any expansion during JSON conversionGHSA-wcpc-wj8m-hjx6 published
Jun 9, 2026 by dcodeIOHigh -
Denial of Service via unbounded recursive JSON descriptor expansionGHSA-jggg-4jg4-v7c6 published
May 13, 2026 by dcodeIOModerate -
pbts command injection via crafted input pathsGHSA-f84p-cvgm-xgjj published
May 12, 2026 by dcodeIOHigh -
Code injection through bytes field defaults in generated toObject codeGHSA-66ff-xgx4-vchm published
May 12, 2026 by dcodeIOHigh -
Code injection in pbjs static output from crafted schema namesGHSA-6r35-46g8-jcw9 published
May 12, 2026 by dcodeIOHigh