Medium severity5.3GHSA Advisory· Published May 13, 2026· Updated May 13, 2026
CVE-2026-44292
CVE-2026-44292
Description
protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs generated message constructors copied enumerable properties from a provided properties object without filtering the __proto__ key. If an application constructed a message from an attacker-controlled plain object, an own enumerable __proto__ property could alter the prototype of that individual message instance. This vulnerability is fixed in 7.5.6 and 8.0.2.
Affected products
1- Range: >= 8.0.0, <= 8.0.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- github.com/advisories/GHSA-fx83-v9x8-x52wghsaADVISORY
- github.com/protobufjs/protobuf.js/security/advisories/GHSA-fx83-v9x8-x52wnvdVendor AdvisoryMitigation
- github.com/protobufjs/protobuf.js/releases/tag/protobufjs-v7.5.6ghsa
- github.com/protobufjs/protobuf.js/releases/tag/protobufjs-v8.0.2ghsa
- nvd.nist.gov/vuln/detail/CVE-2026-44292ghsa
News mentions
0No linked articles in our index yet.