Protobufjs-project
10 CVEs tracked since 2026. Since May 2026, none of them reached CISA KEV.
Protobufjs-project CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2026-05 | 10 | 0 |
Products
The products that kept showing up in Protobufjs-project's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Protobufjs-project.
- CVE-2026-59876protobufjs: Text Format string map parsing can mutate returned map object prototype4.8
- CVE-2026-59877protobufjs: Denial of Service via infinite loop in .proto option parsing5.3
- CVE-2026-54269protobufjs: Schema-derived names can shadow runtime-significant properties5.3
- CVE-2026-48712protobufjs: Denial of service through unbounded Any expansion during JSON conversion7.5
- CVE-2026-54270protobufjs: Memory amplification from preserved unknown fields in binary decode5.3
- CVE-2026-54271protobufjs-cli: Code injection in pbjs static output from crafted JSON descriptor names8.2
- CVE-2026-44295protobufjs-cli: Code injection in pbjs static output from crafted schema names8.7
- CVE-2026-42290protobufjs-cli: OS Command Injection7.8
- CVE-2026-45740protobufjs: Denial of Service via unbounded recursive JSON descriptor expansion5.3
- CVE-2026-44294protobufjs: Denial of service from crafted field names in generated code5.3
- CVE-2026-44293protobufjs: Code injection through bytes field defaults in generated toObject code8.8
- CVE-2026-44292protobufjs: Prototype injection in generated message constructors5.3
- CVE-2026-44291protobufjs: Code generation gadget after prototype pollution8.1
- CVE-2026-44290protobufjs: Process-wide denial of service through unsafe option paths7.5
- CVE-2026-44289protobufjs: Denial of service through unbounded protobuf recursion7.5
The record
- Peak rank
- #135 in May 2026
- Busiest month shown
- May 2026, 10 CVEs
- Months with a KEV entry
- 0 since May 2026
- Monthly snapshots
- 1 since 2026