CVE-2026-44292: Protobufjs Project Protobufjs
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs generated message constructors copied enumerable properties from a provided properties object without filtering the __proto__ key. If an application constructed a message from an attacker-controlled plain object, an own enumerable __proto__ property could alter the prototype of that individual message instance. This vulnerability is fixed in 7.5.6 and 8.0.2.
Affected products
- Protobufjs Project Protobufjs: before 7.5.6 (fixed in 7.5.6); from 8.0.0, before 8.0.2 (fixed in 8.0.2)
Published 2026-05-13. Last modified 2026-06-17.