protobuf.js: Denial of service from crafted field names in generated code
- Severity:
- Medium
Description
protobufjs generated JavaScript property accessors from schema-controlled field and oneof names. Certain control characters in field names were not escaped before being embedded into generated function bodies.
Recommendation
Update the protobufjs package to the latest compatible version. Followings are version details:
Affected version(s): **>= 8.0.0, <= 8.0.1 <= 7.5.5** Patched version(s): **8.0.2 7.5.6**
References
Related Issues
- protobuf.js: Code injection through bytes field defaults in generated toObject code - CVE-2026-44293
- protobuf.js: Denial of service through unbounded protobuf recursion - CVE-2026-44289
- protobuf.js: Process-wide denial of service through unsafe option paths - CVE-2026-44290
- Cube Core is vulnerable to Denial of Service (DoS) via crafted request - CVE-2026-25957
You might also like:
- Tags:
- npm
- protobufjs
Anything's wrong? Let us know Last updated on May 14, 2026


