Medium severity4.8OSV Advisory· Published Jul 8, 2026· Updated Jul 13, 2026
CVE-2026-59876
CVE-2026-59876
Description
protobufjs compiles protobuf definitions into JavaScript (JS) functions. From 8.2.0 until 8.6.5, the protobufjs Text Format extension parsed string-keyed map entries using ordinary property assignment, allowing a map entry with key __proto__ to change the prototype of the returned map object instead of creating an own map entry in protobufjs/ext/textformat. This issue is fixed in version 8.6.5.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
protobufjsnpm | >= 8.2.0, < 8.6.5 | 8.6.5 |
Affected products
4protobufjs-v8.6.4, protobufjs-cli-v2.5.5, protobufjs-v8.6.3, …+ 2 more
- (no CPE)range: protobufjs-v8.6.4, protobufjs-cli-v2.5.5, protobufjs-v8.6.3, …
- cpe:2.3:a:protobufjs_project:protobufjs:*:*:*:*:*:node.js:*:*range: >=8.2.0,<8.6.5
- (no CPE)range: <8.6.5
Patches
Vulnerability mechanics
References
6- github.com/protobufjs/protobuf.js/commit/9f97fe413072d3beb52c74e62d88ea8adc9444d8nvdPatchWEB
- github.com/protobufjs/protobuf.js/pull/2335nvdIssue TrackingPatchWEB
- github.com/advisories/GHSA-jfj6-75fj-8934ghsaADVISORY
- github.com/protobufjs/protobuf.js/security/advisories/GHSA-jfj6-75fj-8934nvdMitigationVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2026-59876ghsaADVISORY
- github.com/protobufjs/protobuf.js/releases/tag/protobufjs-v8.6.5nvdProductRelease NotesWEB
News mentions
0No linked articles in our index yet.