The Lab · 2026-04-17 08:22:52 · GitHub Issues
A critical security vulnerability enabling arbitrary code execution has been patched within the CesiumJS project's dependency chain. The flaw, tracked as CVE GHSA-xq3m-2v4x-88gg, resided in the `protobufjs` library, a core component for data serialization used by `@cesium/engine`. Versions below 7.5.5 were exposed, cre...
The Lab · 2026-05-12 21:48:32 · GitHub Issues
A critical denial-of-service vulnerability has been identified in protobufjs, the widely-used Protocol Buffers implementation for JavaScript. Tracked as CVE-2026-44294 (GHSA-2pr8-phx7-x9h3), the flaw allows attackers to trigger service disruptions through crafted field names in generated code.
The vulnerability stems ...
The Lab · 2026-05-13 17:18:24 · Mastodon:mastodon.social:#infosec
A high-severity vulnerability has been identified in protobufjs, a widely-used JavaScript library for compiling Protocol Buffer definitions into executable functions. The flaw, tracked as CVE-2026-44289 with a CVSS score of 7.5 (High), stems from a critical weakness in how the library handles nested protobuf data durin...
The Lab · 2026-05-13 17:18:25 · Mastodon:mastodon.social:#infosec
A code generation vulnerability in protobufjs-cli, the command line add-on for protobuf.js, exposes applications to risks through the emission of unsafe JavaScript identifiers. The flaw, tracked as CVE-2026-44295 and rated 8.7 on the CVSS scale (High severity), resides in pbjs static code generation functionality that ...