Executive brief
google-protobuf is a JavaScript library used by Node.js applications to deserialize binary protocol buffer messages. An attacker can send a specially crafted message with deeply nested group fields to crash any Node.js service using the library's standard deserialization API. No authentication is required, and the crash terminates the entire process, causing service unavailability.
Technical details
The vulnerability is an unbounded mutual recursion in BinaryReader.skipGroup() and BinaryReader.skipField() (binary/reader.js:515, 551) when parsing unknown protobuf group fields with wire type START_GROUP (0x0b). The skipGroup() method calls skipField(), which calls skipGroup() again if another START_GROUP is encountered, with no recursion depth limit. An unauthenticated attacker can send a small payload of deeply nested START_GROUP wire bytes to any application calling the generated deserializeBinary() API, exhausting the JavaScript call stack and triggering RangeError: Maximum call stack size exceeded. The vulnerability affects google-protobuf versions <= 4.0.2 and is patched in 4.0.3. The same issue exists in the experimental runtime (experimental/runtime/kernel/tag.js:114–131).
Affected products
- Google google-protobuf <=4.0.2
Timeline
- 2026-09-17: disclosed
- 2026-09-17: patched: patched in version 4.0.3