Protobufjs is a widely embedded JavaScript implementation of protocol buffers that sits within the serialization and data-handling path of numerous applications, despite representing a focused single-product footprint. The vendor's vulnerability profile skews toward serious outcomes, concentrating in weakness classes such as code injection, prototype pollution, uncontrolled recursion, and improper resource handling that arise from the parser's role in processing untrusted data structures. Defenders should track this vendor's releases closely, particularly for applications that deserialize untrusted protobuf messages from external sources; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Protobufjs Project over time
Signals from CVEs in this vendor scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-41242CRITICAL protobufjs compiles protobuf definitions into JavaScript (JS) functions. In versions prior to 8.0.1 and 7.5.5, attackers can inject arbitrary code in the "type" fields of protobuf | Apr 18, 2026 | 9.8 | 39 | NO | NO |
CVE-2026-44293HIGH protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs generated JavaScript for toObject conversion could include an unsafe e | May 13, 2026 | 8.8 | 36 | NO | NO |
CVE-2026-44295HIGH protobufjs-cli is the command line add-on for protobuf.js. Prior to 1.2.1 and 2.0.2, pbjs static code generation could emit unsafe JavaScript identifiers derived from schema-contro | May 13, 2026 | 8.7 | 34 | NO | NO |
CVE-2026-59877HIGH protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.6.5 and 8.6.6, protobufjs parsed option names by advancing through schema tokens until reaching | Jul 8, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-54271HIGH protobufjs-cli is the command line add-on for protobuf.js. Prior to 1.3.2 and 2.5.0, a previous fix for unsafe name handling in pbjs static / static-module code generation was inco | Jun 22, 2026 | 8.2 | 33 | NO | NO |
CVE-2026-44291HIGH protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs used plain objects with inherited prototypes for internal type lookup | May 13, 2026 | 8.1 | 32 | NO | NO |
CVE-2026-44289HIGH protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs could recurse without a depth limit while decoding nested protobuf dat | May 13, 2026 | 7.5 | 32 | NO | NO |
CVE-2026-48712HIGH protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.6.1 and 8.4.1, protobufjs could recurse without a depth limit while converting decoded messages | Jun 22, 2026 | 7.5 | 31 | NO | NO |
CVE-2023-36665CRITICAL "protobuf.js (aka protobufjs) 6.10.0 through 7.x before 7.2.5 allows Prototype Pollution, a different vulnerability than CVE-2022-25878. A user-controlled protobuf message can be u | Jul 5, 2023 | 9.8 | 31 | NO | NO |
CVE-2026-44290HIGH protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs allowed certain schema option paths to traverse through inherited obje | May 13, 2026 | 7.5 | 29 | NO | NO |
Signals from CVEs in this vendor scope (20 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Protobufjs Project.
Media articles that mention a CVE ID that affects a product developed by Protobufjs Project — matched by CVE ID, not by vendor name.