Executive brief
A vulnerability in the protobufjs library can allow an attacker to crash or freeze a Node.js application. By providing a specially crafted schema file, an attacker can trigger an infinite loop during the parsing process. Because Node.js handles tasks one at a time, this loop blocks all other operations, leading to a complete service outage until the application is manually restarted.
Technical details
An infinite loop vulnerability exists in protobufjs (CWE-835) within the reflection parsing path, specifically affecting the 'parse', 'Root.load', and 'Root.loadSync' methods. The root cause is the option parser's failure to check for the end of input while searching for an assignment operator ('=') in a .proto schema. An attacker can exploit this by providing a crafted schema that initiates an option declaration but terminates prematurely. In single-threaded Node.js environments, this results in a blocked event loop and a persistent Denial of Service. The issue is resolved in versions 7.6.5 and 8.6.6.
Affected products
- protobufjs protobufjs >= 7.5.0, <= 7.6.4
- protobufjs protobufjs >= 8.0.0, <= 8.6.5
Timeline
- 2026-07-04: disclosed: Vulnerability reported to the maintainer
- 2026-07-08: advisory: NVD publication date
- 2026-07-20: advisory: GitHub Advisory published