Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 13 May 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 13 May 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.8 and 8.2.0, protobufjs could recurse without a depth limit while expanding nested JSON descriptors through Root.fromJSON() and Namespace.addJSON(). A crafted JSON descriptor with deeply nested namespace definitions could cause the JavaScript call stack to be exhausted during descriptor loading. This vulnerability is fixed in 7.5.8 and 8.2.0. | |
| Title | protobufjs: Denial of Service via unbounded recursive JSON descriptor expansion | |
| Weaknesses | CWE-674 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-13T18:20:12.394Z
Reserved: 2026-05-13T06:54:34.219Z
Link: CVE-2026-45740
Updated: 2026-05-13T18:14:56.640Z
Status : Awaiting Analysis
Published: 2026-05-13T16:17:00.520
Modified: 2026-05-13T16:49:52.277
Link: CVE-2026-45740
No data.
OpenCVE Enrichment
Updated: 2026-05-13T18:15:16Z