VYPR
Medium severity5.3OSV Advisory· Published Jul 8, 2026· Updated Jul 10, 2026

CVE-2026-59877

CVE-2026-59877

Description

protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.6.5 and 8.6.6, protobufjs parsed option names by advancing through schema tokens until reaching an = token without checking for end of input, so a crafted .proto schema that opens an option declaration and ends prematurely can cause parse, Root.load, or Root.loadSync to loop indefinitely. This issue is fixed in versions 7.6.5 and 8.6.6.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
protobufjsnpm
>= 7.5.0, < 7.6.57.6.5
protobufjsnpm
>= 8.0.0, < 8.6.68.6.6

Affected products

24

Patches

Vulnerability mechanics

References

8

News mentions

0

No linked articles in our index yet.