High severity7.5GHSA Advisory· Published May 13, 2026· Updated May 14, 2026
CVE-2026-44290
CVE-2026-44290
Description
protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs allowed certain schema option paths to traverse through inherited object properties while applying options. A crafted protobuf schema or JSON descriptor could cause option handling to write to properties on global JavaScript constructors, corrupting process-wide built-in functionality. This vulnerability is fixed in 7.5.6 and 8.0.2.
Affected products
1- Range: >= 8.0.0, <= 8.0.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- github.com/advisories/GHSA-jvwf-75h9-cwggghsaADVISORY
- github.com/protobufjs/protobuf.js/security/advisories/GHSA-jvwf-75h9-cwggnvdMitigationVendor Advisory
- github.com/protobufjs/protobuf.js/releases/tag/protobufjs-v7.5.6ghsa
- github.com/protobufjs/protobuf.js/releases/tag/protobufjs-v8.0.2ghsa
- nvd.nist.gov/vuln/detail/CVE-2026-44290ghsa
News mentions
0No linked articles in our index yet.