CVE-2026-54270: Protobufjs Project Protobufjs
Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.
protobufjs compiles protobuf definitions into JavaScript (JS) functions. From 8.2.0 to 8.4.2, protobufjs preserved unknown wire elements in message.$unknowns and did not provide a decode-time option to discard unknown fields before retaining them. A crafted protobuf payload containing many unknown fields could therefore cause a decoded message to retain substantially more memory than the input size would suggest, even when unknown-field round-tripping is not needed. protobufjs 8.5.0 added the relevant decode-time options, allowing applications that decode untrusted protobuf data to disable unknown-field retention during decode. protobufjs 8.6.2 flips the default so unknown fields are discarded unless explicitly opted into.
Affected products
- Protobufjs Project Protobufjs: from 8.2.0, before 8.5.0 (fixed in 8.5.0)
Published 2026-06-22. Last modified 2026-06-24.