VDB
CVE-2026-44293
CVE-2026-44293
PUBLISHED
CVSS 7.699999809265137 HIGH
protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs generated JavaScript for toObject conversion could include an unsafe expression derived from a schema-controlled bytes field default value. A crafted descriptor with a non-string default value for a bytes field could cause attacker-controlled code to be emitted into the generated conversion function. This vulnerability is fixed in 7.5.6 and 8.0.2.
EPSS 0.06% · 18.3th percentile
Risk Scores
CVSS v4.0
7.699999809265137
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS Score
0.06%
18.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| npm | protobufjs | 0, 8.0.0 |
| protobufjs_project | protobufjs | 0, 8.0.0 |
| protobufjs | protobuf.js | < 7.5.6, * |
Timeline
- May 12, 2026 CVE Published
- May 15, 2026 Security Advisory
- May 18, 2026 EPSS Score
- May 19, 2026 EPSS Score
- May 20, 2026 EPSS Score
- May 21, 2026 EPSS Score
- May 22, 2026 EPSS Score
- May 23, 2026 EPSS Score
- May 24, 2026 EPSS Score
- May 25, 2026 EPSS Score
- May 26, 2026 EPSS Score
- May 27, 2026 EPSS Score