logo

Six Proto6 Vulnerabilities in protobuf.js Expose Node.js Apps to RCE and DoS

ID: 119ee2b4-f57a-52c4-94c8-c43b3e6142cf

STIX ID: report--119ee2b4-f57a-52c4-94c8-c43b3e6142cf

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-06-10

Date Updated: 2026-06-10

Author: [email protected] (The Hacker News)

...
...

Researchers disclosed six vulnerabilities in protobuf.js (Proto6) that can cause RCE and DoS in Node.js applications. The report lists CVE-2026-44289, CVE-2026-44290, CVE-2026-44291, CVE-2026-44292, CVE-2026-44294, and CVE-2026-44295, affected package versions, exploitation scenarios (including prototype pollution leading to code generation exploits), and available patches (protobufjs 7.5.6/8.0.2 and protobufjs-cli 1.2.1/2.0.2); it highlights potential wide impact on CI/CD, cloud SDKs, messaging frameworks, and AI/data ecosystems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.