>= 8.0.0, < 8.0.1
>= 7.0.0, < 7.2.5
HIGH8.1CVE-2026-44291protobuf.js: Code generation gadget after prototype pollution from 0, < 7.5.6
HIGH7.5protobufjs: Denial of service through unbounded Any expansion during JSON conversion
from 0, < 7.6.1
HIGH7.5protobuf.js: Process-wide denial of service through unsafe option paths
from 0, < 7.5.6
HIGH7.5protobuf.js: Denial of service through unbounded protobuf recursion
from 0, < 7.5.6
HIGH7.5Prototype Pollution in protobufjs
>= 6.11.0, < 6.11.3
MEDIUM5.5Denial of Service in protobufjs
>= 6.0.0, < 6.8.6
MEDIUM5.3protobufjs: Denial of Service via infinite loop in .proto option parsing
>= 7.5.0, < 7.6.5
MEDIUM5.3protobufjs: Memory amplification from preserved unknown fields in binary decode
>= 8.2.0, < 8.5.0
MEDIUM5.3protobufjs : Schema-derived names can shadow runtime-significant properties
from 0, < 7.6.3
MEDIUM5.3protobufjs: Denial of Service via unbounded recursive JSON descriptor expansion
from 0, < 7.5.8
MEDIUM5.3protobuf.js: Denial of service from crafted field names in generated code
from 0, < 7.5.6
MEDIUM5.3protobuf.js: Prototype injection in generated message constructors
from 0, < 7.5.6
MEDIUM5.3protobufjs has overlong UTF-8 decoding
from 0, < 7.5.6
MEDIUM4.8protobufjs: Text Format string map parsing can mutate returned map object prototype
>= 8.2.0, < 8.6.5
—protobuf.js: Code injection through bytes field defaults in generated toObject code
from 0, < 7.5.6