Intel

AIKIDO-2026-639460

@bufbuild/protobuf is vulnerable to Denial of Service (DoS)

Denial of Service (DoS)GHSA-2jv8-p43h-h66g Published 2 days ago

53

Medium Risk

This Affects:

JS@bufbuild/protobuf
0.0.1 - 2.12.0
Fixed in 2.12.1
Are you affected? Scan for Free

TL;DR

BinaryReader.skip() in @bufbuild/protobuf recurses once per nested StartGroup wire type tag with no depth limit. A roughly 4.5 KB crafted binary payload sent to any fromBinary() call pushes thousands of stack frames and exhausts the V8 call stack, crashing the Node.js process with an uncaught RangeError. The crash is reachable without authentication or schema knowledge against any server that deserializes untrusted protobuf binary data over Connect-RPC, gRPC-Web, or Twirp-TS. The fix adds a depth limit to group skipping in the binary reader.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

@bufbuild/protobuf is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 2.12.0.

How to fix this

Upgrade the @bufbuild/protobuf library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform