Vulnerabilità · 111 giorni fa
Il punto debole non è solo l’uso diretto di protobuf.js. È il perimetro di fiducia attorno a schema e metadati, perché input controllato da un attacker può essere trasformato in JavaScript generato ed eseguito all’interno del processo Node.js.
CVE in questo aggiornamento
6 CVE
Distribuite tra Secure Connect Gateway, Ansible Automation Platform.
0 critiche · 4 alte · 2 medie · 0 basse
0 in CISA KEV · 0 con EPSS sopra 1%
Severità più alta: CVE-2026-44295 · 8.7 HIGH
EPSS più alto: CVE-2026-44289 · 0,68%
2 fonti che coprono questa storia
Six Proto6 Vulnerabilities in protobuf.js Expose Node.js Apps to RCE and DoS
Six Proto6 flaws in protobuf.js enable RCE and DoS attacks; patched in versions 7.5.6 and 8.0.2 to protect Node.js services.
Protocol Buffers schemas expose remote code execution risk
Researchers at Cyera found six vulnerabilities in protobuf.js, including a flaw that can turn attacker-controlled schema data into executable code and expose downstream software supply chains.
Part of the PlainSec briefing for 2026-06-11