Beveiligingsadvies

CVE-2026-59877

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-07-08 15:28:07
Laatst bijgewerkt 2026-07-08 15:49:27
Toegewezen door GitHub_M
CVSS-score 5.3
Status PUBLISHED

Beschrijving

protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.6.5 and 8.6.6, protobufjs parsed option names by advancing through schema tokens until reaching an = token without checking for end of input, so a crafted .proto schema that opens an option declaration and ends prematurely can cause parse, Root.load, or Root.loadSync to loop indefinitely. This issue is fixed in versions 7.6.5 and 8.6.6.