Protobufjs
by Protobufjs
npm: protobufjs
Source repositories
CVEs (23)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-59876 | Med | 0.24 | 4.8 | 0.00 | Jul 8, 2026 | protobufjs compiles protobuf definitions into JavaScript (JS) functions. From 8.2.0 until 8.6.5, the protobufjs Text Format extension parsed string-keyed map entries using ordinary property assignment, allowing a map entry with key __proto__ to change the prototype of the… | ||
| CVE-2022-48468 | Med | 0.00 | 5.5 | 0.00 | Apr 13, 2023 | protobuf-c before 1.4.1 has an unsigned integer overflow in parse_required_member. | ||
| CVE-2022-33070 | Med | 0.00 | 5.5 | 0.01 | Jun 23, 2022 | Protobuf-c v1.4.0 was discovered to contain an invalid arithmetic shift via the function parse_tag_and_wiretype in protobuf-c/protobuf-c.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via unspecified vectors. |
- risk 0.24cvss 4.8epss 0.00
protobufjs compiles protobuf definitions into JavaScript (JS) functions. From 8.2.0 until 8.6.5, the protobufjs Text Format extension parsed string-keyed map entries using ordinary property assignment, allowing a map entry with key __proto__ to change the prototype of the…
- risk 0.00cvss 5.5epss 0.00
protobuf-c before 1.4.1 has an unsigned integer overflow in parse_required_member.
- risk 0.00cvss 5.5epss 0.01
Protobuf-c v1.4.0 was discovered to contain an invalid arithmetic shift via the function parse_tag_and_wiretype in protobuf-c/protobuf-c.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via unspecified vectors.
Page 2 of 2