GHSA-762f-c2wg-m8c8
GitHub Security Advisory
Denial of Service in protobufjs
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
Versions of `protobufjs` before 5.0.3 and 6.8.6 are vulnerable to a regular expression denial of service when parsing crafted invalid *.proto files.
## Recommendation
Update to version 5.0.3, 6.8.6 or later.
Affected Packages
npm
protobufjs
Affected versions:
6.0.0
(fixed in 6.8.6)
npm
protobufjs
Affected versions:
0
(fixed in 5.0.3)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: July 2, 2025 6:26 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.