Junglewise Threat Intelligence

protobufjs denial of service in message parser

Severity: info · Published 2020-08-19

Vendors: Protobufjs.

Executive brief

protobufjs is a popular JavaScript library for working with Protocol Buffer messages, commonly used in web applications and Node.js services for data serialization. A denial of service vulnerability in the message parser allows an attacker to send a specially crafted protobuf message that consumes excessive system resources, potentially crashing the application or making it unresponsive. This could disrupt business operations for applications that rely on protobufjs for message handling.

Technical details

The vulnerability exists in the message parsing logic of protobufjs (specifically in src/parse.js), where insufficient validation or resource limits allow an attacker to craft a protobuf message that triggers computationally expensive operations. The attack vector is network-based if the application accepts protobuf messages from untrusted sources. No authentication is required to exploit this vulnerability—an attacker can simply send a malicious message to trigger the denial of service condition. The vulnerability affects all versions of the 5.x series up to 5.0.3 and the 6.x series from 6.0.0 through 6.8.5. Patches are available in protobufjs 5.0.3 and 6.8.6 or later.

Affected products

  • protobufjs protobufjs 5.x < 5.0.3, 6.0.0 - 6.8.5

Timeline

  • 2020-08-19: disclosed

References