@bufbuild/protobuf is vulnerable to Denial of Service (DoS)
53
Medium Risk
BinaryReader.skip() in @bufbuild/protobuf recurses once per nested StartGroup wire type tag with no depth limit. A roughly 4.5 KB crafted binary payload sent to any fromBinary() call pushes thousands of stack frames and exhausts the V8 call stack, crashing the Node.js process with an uncaught RangeError. The crash is reachable without authentication or schema knowledge against any server that deserializes untrusted protobuf binary data over Connect-RPC, gRPC-Web, or Twirp-TS. The fix adds a depth limit to group skipping in the binary reader.
You are affected if you are using a version that falls within the vulnerable range.
@bufbuild/protobuf is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 2.12.0.
Upgrade the @bufbuild/protobuf library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.