Description
protobufjs generated JavaScript property accessors from schema-controlled field and oneof names. Certain control characters in field names were not escaped before being embedded into generated function bodies.
Recommendation
Update the protobufjs package to the latest compatible version. Followings are version details:
Affected version(s): **>= 8.0.0, <= 8.0.1 <= 7.5.5** Patched version(s): **8.0.2 7.5.6**
References
Could your website be exposed too?
SmartScanner can check your website for protobuf.js: Denial of service from crafted field names in generated code and gives you actionable findings to investigate.
Start a free scanRelated Issues
- protobuf.js: Code injection through bytes field defaults in generated toObject code - CVE-2026-44293
- protobuf.js: Denial of service through unbounded protobuf recursion - CVE-2026-44289
- protobuf.js: Process-wide denial of service through unsafe option paths - CVE-2026-44290
- Cube Core is vulnerable to Denial of Service (DoS) via crafted request - CVE-2026-25957


