CVE-2026-41242
protobufjs protobuf.js, Red Hat Developer Hub 1.8, Red Hat Developer Hub 1.9 취약점
protobufjs compiles protobuf definitions into JavaScript (JS) functions. In versions prior to 8.0.1 and 7.5.5, attackers can inject arbitrary code in the "type" fields of protobuf definitions, which will then execute during object decoding using that definition. Versions 8.0.1 and 7.5.5 patch the issue.
- 대응 우선순위
- 점검
- CVSS
- 9.4
- EPSS
- 0.74% 백분위 51.2% · 2026.08.04 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2026.04.19