CVE-2026-59877

protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.6.5 and 8.6.6, protobufjs parsed option names by advancing through schema tokens until reaching an = token without checking for end of input, so a crafted .proto schema that opens an option declaration and ends prematurely can cause parse, Root.load, or Root.loadSync to loop indefinitely. This issue is fixed in versions 7.6.5 and 8.6.6.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:protobufjs_project:protobufjs:*:*:*:*:*:node.js:*:*
cpe:2.3:a:protobufjs_project:protobufjs:*:*:*:*:*:node.js:*:*

History

No history.

Information

Published : 2026-07-08 16:16

Updated : 2026-07-10 18:53


NVD link : CVE-2026-59877

Mitre link : CVE-2026-59877

CVE.ORG link : CVE-2026-59877


JSON object : View

Products Affected

protobufjs_project

  • protobufjs
CWE
CWE-835

Loop with Unreachable Exit Condition ('Infinite Loop')