Description
protobufjs could recurse without a depth limit while decoding nested protobuf data. This affected both skipping unknown group fields and generated decoding of nested message fields.
A crafted protobuf binary payload could cause the JavaScript call stack to be exhausted during decoding.
Recommendation
Update the protobufjs package to the latest compatible version. Followings are version details:
Affected version(s): **>= 8.0.0, <= 8.0.1 <= 7.5.5** Patched version(s): **8.0.2 7.5.6**
References
Could your website be exposed too?
SmartScanner can check your website for protobuf.js: Denial of service through unbounded protobuf recursion and gives you actionable findings to investigate.
Start a free scanRelated Issues
- protobuf.js: Process-wide denial of service through unsafe option paths - CVE-2026-44290
- protobufjs: Denial of service through unbounded Any expansion during JSON conversion - CVE-2026-48712
- protobuf.js: Denial of service from crafted field names in generated code - CVE-2026-44294
- protobufjs: Denial of Service via unbounded recursive JSON descriptor expansion - CVE-2026-45740


