Known Vulnerabilities for Protobuf by Google
Listed below are 3 of the newest known vulnerabilities associated with "Protobuf" by "Google".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-54271 json | protobufjs-cli is the command line add-on for protobuf.js. Prior to 1.3.2 and 2.5.0, a previous fix for unsafe name handling ... | Not Provided | 2026-06-22 | 2026-06-22 |
| CVE-2026-54270 json | protobufjs compiles protobuf definitions into JavaScript (JS) functions. From 8.2.0 to 8.4.2, protobufjs preserved unknown wi... | Not Provided | 2026-06-22 | 2026-06-22 |
| CVE-2026-54269 json | protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 8.6.0 and 7.6.3, protobufjs accepted certai... | Not Provided | 2026-06-22 | 2026-06-22 |
| CVE-2026-52756 json | Ghidra before 12.2 contains an unauthenticated path traversal vulnerability in the IsfServer that accepts TCP connections and... | Not Provided | 2026-06-10 | 2026-06-10 |
| CVE-2026-48712 json | protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.6.1 and 8.4.1, protobufjs could recurse w... | Not Provided | 2026-06-22 | 2026-06-22 |
| CVE-2026-48599 json | Authorization Bypass Through User-Controlled Key vulnerability in elixir-grpc grpc allows authenticated attackers to access o... | Not Provided | 2026-06-15 | 2026-06-16 |
| CVE-2026-48137 json | There is an untrusted pointer dereference vulnerability in the NI grpc-device sideband streaming API that may allow an attack... | Not Provided | 2026-06-19 | 2026-06-22 |
| CVE-2026-45740 json | protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.8 and 8.2.0, protobufjs could recurse w... | Not Provided | 2026-05-13 | 2026-05-13 |
| CVE-2026-45542 json | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.4, and 6.0, a h... | Not Provided | 2026-06-10 | 2026-06-10 |
| CVE-2026-44295 json | protobufjs-cli is the command line add-on for protobuf.js. Prior to 1.2.1 and 2.0.2, pbjs static code generation could emit u... | Not Provided | 2026-05-13 | 2026-05-13 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Protobuf | 4.0.0 | ||||
| Application | Protobuf | 4.0.0 | ||||
| Application | Protobuf | 3.9.2 | ||||
| Application | Protobuf | 3.9.1 | ||||
| Application | Protobuf | 3.9.0 | ||||
| Application | Protobuf | 3.9.0 | ||||
| Application | Protobuf | 3.8.0 | ||||
| Application | Protobuf | 3.8.0 | ||||
| Application | Protobuf | 3.7.1 | ||||
| Application | Protobuf | 3.7.0 | ||||
| Application | Protobuf | 3.7.0 | ||||
| Application | Protobuf | 3.7.0 | ||||
| Application | Protobuf | 3.7.0 | ||||
| Application | Protobuf | 3.6.1.3 | ||||
| Application | Protobuf | 3.6.1.2 | ||||
| Application | Protobuf | 3.6.1.1 | ||||
| Application | Protobuf | 3.6.1 | ||||
| Application | Protobuf | 3.6.0.1 | ||||
| Application | Protobuf | 3.6.0 | ||||
| Application | Protobuf | 3.6.0 |