Executive brief
A vulnerability in the protobufjs library, which is used to handle data communication in JavaScript applications, could allow an attacker to cause a service to consume excessive amounts of memory. By sending specially crafted messages containing many "unknown" data fields, an attacker can force the application to store significantly more data than expected. This can lead to slowed performance, service crashes, or system instability, potentially disrupting business operations.
Technical details
The vulnerability is classified as CWE-770 (Allocation of Resources Without Limits or Throttling). Between versions 8.2.0 and 8.4.2, protobufjs automatically preserved unknown wire elements in the 'message.$unknowns' property without providing a mechanism to discard them during the decoding process. An attacker can exploit this by sending a crafted protobuf payload with a high density of unknown fields, causing the decoded object to occupy substantially more memory than the original input size. This is a network-reachable attack requiring no authentication. The issue was addressed in version 8.5.0 by adding 'discardUnknown' options, and version 8.6.2 changed the default behavior to discard unknown fields unless explicitly opted in.
Affected products
- protobufjs protobuf.js >=8.2.0, < 8.5.0
Timeline
- 2026-06-12: advisory: GitHub Security Advisory published
- 2026-06-22: disclosed: NVD publication date