CVE-2026-59877
protobufjs protobuf.js, protobufjs
protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.6.5 and 8.6.6, protobufjs parsed option names by advancing through schema tokens until reaching an = token without checking for end of input, so a crafted .proto schema that opens an option declaration and ends prematurely can cause parse, Root.load, or Root.loadSync to loop indefinitely. This issue is fixed in versions 7.6.5 and 8.6.6.
- CVSS
- 7.5
- EPSS
- 0.37% 29.2% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.09