Six Proto6 Vulnerabilities in protobuf.js Expose Node.js Apps to RCE and DoS
Researchprotobuf.jsprotobufjs-cliOur summary
Researchers disclosed six security issues in protobuf.js (often used with Google Cloud client libraries, Baileys, and CI/CD workflows), collectively dubbed Proto6. The vulnerabilities affect Node.js services that deserialize attacker-controlled Protobuf data or generate code from schemas, enabling remote code execution and denial-of-service conditions. Affected CVEs include CVE-2026-44289, CVE-2026-44290, CVE-2026-44291, CVE-2026-44292, CVE-2026-44294, and CVE-2026-44295, with the most critical RCE risk tied to CVE-2026-44291; patches are available in protobufjs 7.5.6 and 8.0.2, and protobufjs-cli 1.2.1 and 2.0.2.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.