protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.6.5 and 8.6.6, protobufjs parsed option names by advancing through schema tokens until reaching an = token without checking for end of input, so a crafted .proto schema that opens an option declaration and ends prematurely can cause parse, Root.load, or Root.loadSync to loop indefinitely. This issue is fixed in versions 7.6.5 and 8.6.6.
References
| Link | Resource |
|---|---|
| https://github.com/protobufjs/protobuf.js/commit/10fba6d54815ceecca8a06b9a6db490c8f5d2217 | Patch |
| https://github.com/protobufjs/protobuf.js/commit/fa5c73add738ceb471e74da8cc2f3727c3d0a69f | Patch |
| https://github.com/protobufjs/protobuf.js/pull/2352 | Issue Tracking Patch |
| https://github.com/protobufjs/protobuf.js/releases/tag/protobufjs-v7.6.5 | Product Release Notes |
| https://github.com/protobufjs/protobuf.js/releases/tag/protobufjs-v8.6.6 | Product Release Notes |
| https://github.com/protobufjs/protobuf.js/security/advisories/GHSA-j3f2-48v5-ccww | Mitigation Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-07-08 16:16
Updated : 2026-07-10 18:53
NVD link : CVE-2026-59877
Mitre link : CVE-2026-59877
CVE.ORG link : CVE-2026-59877
JSON object : View
Products Affected
protobufjs_project
- protobufjs
CWE
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
