CVE-2026-59877

MEDIUM

protobufjs: Denial of Service via infinite loop in .proto option parsing

Title source: cna
STIX 2.1

Description

protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.6.5 and 8.6.6, protobufjs parsed option names by advancing through schema tokens until reaching an = token without checking for end of input, so a crafted .proto schema that opens an option declaration and ends prematurely can cause parse, Root.load, or Root.loadSync to loop indefinitely. This issue is fixed in versions 7.6.5 and 8.6.6.

Scores

CVSS v3 5.3
EPSS 0.0037
EPSS Percentile 29.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-835
Status published
Products (5)
npm/protobufjs 7.5.0 - 7.6.5npm
npm/protobufjs 8.0.0 - 8.6.6npm
protobufjs/protobuf.js >= 7.5.0, < 7.6.5
protobufjs/protobuf.js >= 8.0.0, < 8.6.6
protobufjs_project/protobufjs < 7.6.5
Published Jul 08, 2026
Tracked Since Jul 08, 2026