CVE-2026-45740: Protobufjs Project Protobufjs
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.8 and 8.2.0, protobufjs could recurse without a depth limit while expanding nested JSON descriptors through Root.fromJSON() and Namespace.addJSON(). A crafted JSON descriptor with deeply nested namespace definitions could cause the JavaScript call stack to be exhausted during descriptor loading. This vulnerability is fixed in 7.5.8 and 8.2.0.
Affected products
- Protobufjs Project Protobufjs: before 7.5.8 (fixed in 7.5.8); from 8.0.0, before 8.2.0 (fixed in 8.2.0)
Published 2026-05-13. Last modified 2026-06-17.