Junglewise Threat Intelligence

CVE-2026-45740: protobufjs uncontrolled recursion in JSON descriptor expansion

CVE-2026-45740 · Severity: medium · CVSS 5.3 · Published 2026-05-13

Vendors: Protobufjs.

Executive brief

A vulnerability in the protobufjs library, which is used to handle data serialization, can allow an attacker to crash an application. By providing a specially crafted data schema with excessive nesting, an attacker can cause the software to stop responding or shut down unexpectedly. This impacts the availability of services that process untrusted data schemas.

Technical details

The protobufjs library fails to implement a depth limit during the expansion of nested JSON descriptors within the Root.fromJSON() and Namespace.addJSON() methods. An attacker can exploit this by providing a crafted JSON descriptor containing deeply nested 'nested' namespace objects. This leads to a stack overflow (CWE-674) as the JavaScript call stack is exhausted during recursive processing. The vulnerability can be triggered remotely if the application loads descriptors from untrusted sources. Patches are available in versions 7.5.8 and 8.2.0.

Affected products

  • protobufjs protobufjs <= 7.5.7, >= 8.0.0 < 8.2.0

Timeline

  • 2026-05-13: disclosed: NVD publication date
  • 2026-05-19: advisory: GitHub Advisory published

References