CVE-2026-54269: CWE-674: Uncontrolled Recursion in protobufjs protobuf.js
protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 8.6.0 and 7.6.3, protobufjs accepted certain schema-derived names that could collide with properties used by protobufjs runtime helpers. The known affected names are fields named hasOwnProperty, field or oneof names such as $type when loaded through protobufjs JSON/reflection descriptors, and service methods whose generated helper name is rpcCall. When affected message or service types were used, protobufjs could read schema-controlled data where it expected an own-property helper, reflected type metadata, or the base RPC helper. This could cause deterministic exceptions or recursive calls in affected decode post-checks, verification, object conversion, reflected JSON serialization, or protobufjs RPC helper invocation. This vulnerability is fixed in 8.6.0 and 7.6.3.
AI Analysis
Technical Summary
The protobuf.js library contains a vulnerability (CVE-2026-54269) in versions before 7.6.3 and 8.6.0 where naming collisions between schema-derived names and internal runtime helper properties (such as hasOwnProperty, $type, or rpcCall) can cause uncontrolled recursion or deterministic exceptions. This affects decoding, verification, object conversion, JSON serialization, and RPC helper invocation processes. The issue is resolved in protobuf.js versions 7.6.3 and 8.6.0.
Potential Impact
This vulnerability can lead to application instability through uncontrolled recursion or deterministic exceptions, potentially causing denial of service due to crashes or hangs during protobuf.js operations. There is no indication of confidentiality or integrity impact. The CVSS score of 5.3 reflects a medium severity denial of service impact with no required privileges or user interaction.
Mitigation Recommendations
Upgrade protobuf.js to version 7.6.3 or later, or 8.6.0 or later, where this vulnerability is fixed. No other mitigations are indicated. Patch status is confirmed by the version information in the advisory.
CVE-2026-54269: CWE-674: Uncontrolled Recursion in protobufjs protobuf.js
Description
protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 8.6.0 and 7.6.3, protobufjs accepted certain schema-derived names that could collide with properties used by protobufjs runtime helpers. The known affected names are fields named hasOwnProperty, field or oneof names such as $type when loaded through protobufjs JSON/reflection descriptors, and service methods whose generated helper name is rpcCall. When affected message or service types were used, protobufjs could read schema-controlled data where it expected an own-property helper, reflected type metadata, or the base RPC helper. This could cause deterministic exceptions or recursive calls in affected decode post-checks, verification, object conversion, reflected JSON serialization, or protobufjs RPC helper invocation. This vulnerability is fixed in 8.6.0 and 7.6.3.
CVSS v3.1
Score 5.3medium
Affected software
pkg:npm/protobufjs/protobuf.jsRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The protobuf.js library contains a vulnerability (CVE-2026-54269) in versions before 7.6.3 and 8.6.0 where naming collisions between schema-derived names and internal runtime helper properties (such as hasOwnProperty, $type, or rpcCall) can cause uncontrolled recursion or deterministic exceptions. This affects decoding, verification, object conversion, JSON serialization, and RPC helper invocation processes. The issue is resolved in protobuf.js versions 7.6.3 and 8.6.0.
Potential Impact
This vulnerability can lead to application instability through uncontrolled recursion or deterministic exceptions, potentially causing denial of service due to crashes or hangs during protobuf.js operations. There is no indication of confidentiality or integrity impact. The CVSS score of 5.3 reflects a medium severity denial of service impact with no required privileges or user interaction.
Mitigation Recommendations
Upgrade protobuf.js to version 7.6.3 or later, or 8.6.0 or later, where this vulnerability is fixed. No other mitigations are indicated. Patch status is confirmed by the version information in the advisory.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-12T17:13:32.279Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a39735beed863c81e396249
Added to database: 06/22/2026, 17:39:39 UTC
Last enriched: 07/16/2026, 10:51:36 UTC
Last updated: 08/07/2026, 00:41:15 UTC
Views: 64
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.