Security Advisory

CVE-2026-59877

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-08 15:28:07
Last updated 2026-07-08 15:49:27
Assigner GitHub_M
CVSS score 5.3
State PUBLISHED

Description

protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.6.5 and 8.6.6, protobufjs parsed option names by advancing through schema tokens until reaching an = token without checking for end of input, so a crafted .proto schema that opens an option declaration and ends prematurely can cause parse, Root.load, or Root.loadSync to loop indefinitely. This issue is fixed in versions 7.6.5 and 8.6.6.