protobufjs: Code injection through bytes field defaults in generated toObject code
Published May 13, 2026
7.7
HIGHCVSS 4.0
EPSS 0.73%
Description
protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs generated JavaScript for toObject conversion could include an unsafe expression derived from a schema-controlled bytes field default value. A crafted descriptor with a non-string default value for a bytes field could cause attacker-controlled code to be emitted into the generated conversion function. This vulnerability is fixed in 7.5.6 and 8.0.2.
Affected products
-
- Version < 7.5.6StatusaffectedConstraints-
- Version >= 8.0.0, < 8.0.2StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Protobufjs | Protobuf.js | n/a |
|
- < 7.5.6
- ≥ 8.0.0 · < 8.0.2
No data.
Red Hat Ansible Automation Platform 2.6
ansible-automation-platform-26/gateway-rhel9:1782761510
Fixed · RHSA-2026:34374
Red Hat Ansible Automation Platform 2.6 for RHEL 9
automation-platform-ui-0:2.6.10-1.el9ap
Fixed · RHSA-2026:34160
Red Hat Developer Hub 1.9
rhdh/rhdh-hub-rhel9:1781187342
Fixed · RHSA-2026:26234
Red Hat Enterprise Linux 10
rh-podman-desktop-0:1.1.1-1.el10_2
Fixed · RHSA-2026:37385
Red Hat OpenShift AI 3.4
rhoai/odh-dashboard-rhel9:1787347991
Fixed · RHSA-2026:60520
Red Hat OpenShift AI 3.4
rhoai/odh-mod-arch-automl-rhel9:1787250508
Fixed · RHSA-2026:60520
Red Hat OpenShift AI 3.4
rhoai/odh-mod-arch-autorag-rhel9:1787251550
Fixed · RHSA-2026:60520
Red Hat OpenShift AI 3.4
rhoai/odh-mod-arch-gen-ai-rhel9:1786611759
Fixed · RHSA-2026:60520
Red Hat OpenShift AI 3.4
rhoai/odh-mod-arch-maas-rhel9:1787251250
Fixed · RHSA-2026:60520
Red Hat OpenShift AI 3.4
rhoai/odh-mod-arch-mlflow-rhel9:1786612219
Fixed · RHSA-2026:60520
Red Hat OpenShift AI 3.4
rhoai/odh-mod-arch-model-registry-rhel9:1787250617
Fixed · RHSA-2026:60520
Red Hat OpenShift Container Platform 4.18
openshift4/ose-console-rhel9:1787031447
Fixed · RHSA-2026:57487
Red Hat OpenShift Container Platform 4.19
openshift4/ose-console-rhel9:1786486822
Fixed · RHSA-2026:54555
Red Hat OpenShift Container Platform 4.20
openshift4/ose-console-rhel9:1783602326
Fixed · RHSA-2026:37628
Red Hat OpenShift Container Platform 4.21
openshift4/ose-console-rhel9:1783502338
Fixed · RHSA-2026:37186
Red Hat OpenShift Container Platform 4.22
openshift4/ose-console-rhel9:1782224390
Fixed · RHSA-2026:29795
Red Hat OpenShift Service Mesh 3.3
openshift-service-mesh/kiali-ossmc-rhel9:1780997382
Fixed · RHSA-2026:26090
Red Hat OpenShift Service Mesh 3.3
openshift-service-mesh/kiali-rhel9:1780997438
Fixed · RHSA-2026:26090
OpenShift Pipelines
openshift-pipelines/pipelines-console-plugin-rhel8
Not affected
OpenShift Pipelines
openshift-pipelines/pipelines-console-plugin-rhel9
Not affected
Red Hat Build of Podman Desktop
rh-podman-desktop.git
Affected
Red Hat Enterprise Linux 8
grafana
Not affected
Red Hat Enterprise Linux 9
grafana
Will not fix
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-cuda-rhel9
Affected
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-gaudi-rhel9
Affected
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-rocm-rhel9
Affected
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/disk-image-cuda-rhel9
Affected
Red Hat Hardened Images
dotnet9.0
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-mod-arch-eval-hub-rhel9
Affected
Red Hat OpenShift Container Platform 4
openshift3/ose-console
Affected
Red Hat OpenShift Container Platform 4
openshift4/ose-console
Not affected
Red Hat Openshift Data Foundation 4
odf4/mcg-core-rhel9
Affected
Self-service automation portal 2
ansible-automation-platform/automation-portal
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Ansible Automation Platform 2.6 | ansible-automation-platform-26/gateway-rhel9:1782761510 | Fixed | RHSA-2026:34374 |
| Red Hat Ansible Automation Platform 2.6 for RHEL 9 | automation-platform-ui-0:2.6.10-1.el9ap | Fixed | RHSA-2026:34160 |
| Red Hat Developer Hub 1.9 | rhdh/rhdh-hub-rhel9:1781187342 | Fixed | RHSA-2026:26234 |
| Red Hat Enterprise Linux 10 | rh-podman-desktop-0:1.1.1-1.el10_2 | Fixed | RHSA-2026:37385 |
| Red Hat OpenShift AI 3.4 | rhoai/odh-dashboard-rhel9:1787347991 | Fixed | RHSA-2026:60520 |
| Red Hat OpenShift AI 3.4 | rhoai/odh-mod-arch-automl-rhel9:1787250508 | Fixed | RHSA-2026:60520 |
| Red Hat OpenShift AI 3.4 | rhoai/odh-mod-arch-autorag-rhel9:1787251550 | Fixed | RHSA-2026:60520 |
| Red Hat OpenShift AI 3.4 | rhoai/odh-mod-arch-gen-ai-rhel9:1786611759 | Fixed | RHSA-2026:60520 |
| Red Hat OpenShift AI 3.4 | rhoai/odh-mod-arch-maas-rhel9:1787251250 | Fixed | RHSA-2026:60520 |
| Red Hat OpenShift AI 3.4 | rhoai/odh-mod-arch-mlflow-rhel9:1786612219 | Fixed | RHSA-2026:60520 |
| Red Hat OpenShift AI 3.4 | rhoai/odh-mod-arch-model-registry-rhel9:1787250617 | Fixed | RHSA-2026:60520 |
| Red Hat OpenShift Container Platform 4.18 | openshift4/ose-console-rhel9:1787031447 | Fixed | RHSA-2026:57487 |
| Red Hat OpenShift Container Platform 4.19 | openshift4/ose-console-rhel9:1786486822 | Fixed | RHSA-2026:54555 |
| Red Hat OpenShift Container Platform 4.20 | openshift4/ose-console-rhel9:1783602326 | Fixed | RHSA-2026:37628 |
| Red Hat OpenShift Container Platform 4.21 | openshift4/ose-console-rhel9:1783502338 | Fixed | RHSA-2026:37186 |
| Red Hat OpenShift Container Platform 4.22 | openshift4/ose-console-rhel9:1782224390 | Fixed | RHSA-2026:29795 |
| Red Hat OpenShift Service Mesh 3.3 | openshift-service-mesh/kiali-ossmc-rhel9:1780997382 | Fixed | RHSA-2026:26090 |
| Red Hat OpenShift Service Mesh 3.3 | openshift-service-mesh/kiali-rhel9:1780997438 | Fixed | RHSA-2026:26090 |
| OpenShift Pipelines | openshift-pipelines/pipelines-console-plugin-rhel8 | Not affected | n/a |
| OpenShift Pipelines | openshift-pipelines/pipelines-console-plugin-rhel9 | Not affected | n/a |
| Red Hat Build of Podman Desktop | rh-podman-desktop.git | Affected | n/a |
| Red Hat Enterprise Linux 8 | grafana | Not affected | n/a |
| Red Hat Enterprise Linux 9 | grafana | Will not fix | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-cuda-rhel9 | Affected | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-gaudi-rhel9 | Affected | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-rocm-rhel9 | Affected | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/disk-image-cuda-rhel9 | Affected | n/a |
| Red Hat Hardened Images | dotnet9.0 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-mod-arch-eval-hub-rhel9 | Affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift3/ose-console | Affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-console | Not affected | n/a |
| Red Hat Openshift Data Foundation 4 | odf4/mcg-core-rhel9 | Affected | n/a |
| Self-service automation portal 2 | ansible-automation-platform/automation-portal | Affected | n/a |
protobufjs
npm
Introduced 0 Fixed 7.5.6protobufjs
npm
Introduced 8.0.0 Fixed 8.0.2
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | protobufjs | 0 | 7.5.6 |
| npm | protobufjs | 8.0.0 | 8.0.2 |
Remediation
Red Hat statement
This is an Important flaw affecting Red Hat products that incorporate the protobufjs library. protobufjs is vulnerable to arbitrary code execution when compiling protobuf definitions into JavaScript. During generation of the toObject conversion function, a schema-controlled default value on a bytes field that is not a string can be emitted as unsafe JavaScript code. An attacker who can supply or influence the protobuf descriptor processed by the application (low privileges required) may achieve code execution in the Node.js process context. Fixed upstream in protobufjs 7.5.6 and 8.0.2. Affects Red Hat offerings that bundle protobufjs and process attacker-influenced protobuf schemas at runtime.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
References (20)
- https://access.redhat.com/errata/RHSA-2026:26090
- https://access.redhat.com/errata/RHSA-2026:26234
- https://access.redhat.com/errata/RHSA-2026:29795
- https://access.redhat.com/errata/RHSA-2026:34160
- https://access.redhat.com/errata/RHSA-2026:34374
- https://access.redhat.com/errata/RHSA-2026:37186
- https://access.redhat.com/errata/RHSA-2026:37385
- https://access.redhat.com/errata/RHSA-2026:37628
- https://access.redhat.com/errata/RHSA-2026:54555
- https://access.redhat.com/errata/RHSA-2026:57487
- https://access.redhat.com/errata/RHSA-2026:60520
- https://access.redhat.com/security/cve/CVE-2026-44293 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2477104 Issue Tracking
- https://github.com/advisories/GHSA-66ff-xgx4-vchm Advisory
- https://github.com/protobufjs/protobuf.js/releases/tag/protobufjs-v7.5.6
- https://github.com/protobufjs/protobuf.js/releases/tag/protobufjs-v8.0.2
- https://github.com/protobufjs/protobuf.js/security/advisories/GHSA-66ff-xgx4-vchm x_refsource_CONFIRMMitigationVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-44293
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44293.json
- https://www.cve.org/CVERecord?id=CVE-2026-44293
Change history (0)
No recorded changes yet.