CVE-2026-59877: Protobufjs Project Protobufjs
High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.
protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.6.5 and 8.6.6, protobufjs parsed option names by advancing through schema tokens until reaching an = token without checking for end of input, so a crafted .proto schema that opens an option declaration and ends prematurely can cause parse, Root.load, or Root.loadSync to loop indefinitely. This issue is fixed in versions 7.6.5 and 8.6.6.
Affected products
- Protobufjs Project Protobufjs: before 7.6.5 (fixed in 7.6.5); from 8.0.0, before 8.6.6 (fixed in 8.6.6)
Published 2026-07-08. Last modified 2026-07-10.