# Six Critical Vulnerabilities in protobuf.js Expose Thousands of Node.js Applications to Code Execution and Denial of Service


## The Threat


Cybersecurity researchers at Cyera have discovered six vulnerabilities in protobuf.js, the widely-used JavaScript and TypeScript implementation of Google's Protocol Buffers serialization format. Collectively codenamed "Proto6," these flaws could allow attackers to trigger remote code execution (RCE), cause process crashes, corrupt runtime memory, and disrupt critical services—all from a single malicious protobuf schema or crafted message payload.


The core issue stems from protobuf.js treating schema and metadata inputs as inherently trusted by default. This validation gap becomes dangerous in modern software architectures where schemas, configuration files, and data structures regularly cross service boundaries—flowing between microservices, cloud SDKs, CI/CD systems, vector databases, and AI inference pipelines. The researchers note that the conditions required to exploit these flaws are "increasingly common" in the contemporary data and machine learning ecosystems that routinely exchange untrusted schemas and configuration data.


The attack surface is particularly broad. Affected systems include any Node.js application that deserializes Protobuf data, any service that generates code from Protobuf schemas, Google Cloud client libraries, messaging automation frameworks like Baileys (used to build WhatsApp bots), and enterprise CI/CD pipelines. Security researcher Vladimir Tokarev explained that the most severe vulnerability (CVE-2026-44291) works by poisoning the JavaScript prototype chain through specially crafted input, then leveraging protobuf.js's reliance on property lookups to inject attacker-controlled strings directly into dynamically compiled functions—ultimately achieving arbitrary code execution within the Node.js process.


## Severity and Impact


| Vulnerability | CVE ID | CVSS Score | Severity | Attack Vector | Authentication | Complexity |

|---|---|---|---|---|---|---|

| Unbounded recursion DoS | CVE-2026-44289 | 7.5 | High | Network | None | Low |

| Process-wide DoS from unsafe option paths | CVE-2026-44290 | 7.5 | High | Network | None | Low |

| Code generation gadget via prototype pollution | CVE-2026-44291 | 8.1 | High | Network | None | Low |

| Prototype injection in message constructors | CVE-2026-44292 | 5.3 | Medium | Network | None | Low |

| DoS from crafted field names | CVE-2026-44294 | 5.3 | Medium | Network | None | Low |

| Code injection in pbjs static output | CVE-2026-44295 | 8.7 | Critical | Network | None | Low |


## Affected Products


protobuf.js:

  • Version 7.5.5 and earlier
  • Versions 8.0.0 through 8.0.1

  • protobufjs-cli:

  • Version 1.2.0 and earlier
  • Versions 2.0.0 through 2.0.1

  • Downstream Dependencies:

  • Google Cloud client libraries (all Node.js versions using affected protobuf.js)
  • Baileys (WhatsApp Web API automation library)
  • Any CI/CD pipeline, data orchestration system, vector database, or inference pipeline relying on these packages

  • ## Mitigations


    Immediate Actions:


    1. Update protobuf.js to version 7.5.6 or 8.0.2 immediately. Patch deployment should be treated as critical across all development teams.


    2. Update protobufjs-cli to version 1.2.1 or 2.0.2 in any build systems or code generation tooling.


    3. Audit schema sources in your environment. Implement strict controls over where Protobuf schemas are sourced from. If schemas come from external parties, third-party integrations, or untrusted repositories, implement validation and code review processes.


    4. Restrict schema loading in development and production. For any service that loads or generates code from Protobuf schemas, ensure those sources are authenticated and validated. Treat schema files with the same security rigor as code.


    5. CI/CD pipeline hardening is critical, particularly for CVE-2026-44295 (which could leak build secrets). Implement:

    - Least-privilege credentials for build systems

    - Schema validation before code generation steps

    - Monitoring for unexpected build artifacts or environment variable exfiltration


    6. Network segmentation for services using protobuf.js, particularly those processing untrusted message payloads (messaging bots, data pipelines). Isolate these services to limit lateral movement if code execution is achieved.


    7. Input validation at application boundaries. Even with the patch applied, implement defensive validation of any externally-sourced Protobuf messages or schemas.


    For Specific Contexts:


  • WhatsApp bot operators using Baileys: Update immediately and consider message filtering rules to detect malformed messages that could trigger DoS conditions (CVE-2026-44292).
  • AI/ML pipeline owners: Audit all vector stores, embedding systems, and inference orchestration tools that accept schema-based inputs.
  • Cloud platform users: Force update Google Cloud client libraries to pull the latest protobuf.js dependency versions through your package manager.

  • ## References


  • Cyera Security Advisory: Original Proto6 vulnerability disclosure
  • protobuf.js GitHub Repository: https://github.com/protobufjs/protobuf.js/releases
  • protobufjs-cli GitHub Repository: Code generation tooling updates
  • Google Cloud Node.js Client Libraries: Migration guidance for affected users
  • CVE-2026-44289 through CVE-2026-44295: National Vulnerability Database (NVD)

  • ---


    ## HackWire Analysis


    The Proto6 vulnerabilities represent a fundamental shift in how we should think about schema and metadata security in modern software architectures. For the past decade, the industry has largely treated configuration files, schema definitions, and metadata as "safe" inputs—trusted by default, validated as an afterthought. This advisory challenges that assumption in an age where these artifacts flow continuously across distributed systems, cloud platforms, and third-party integrations.


    What makes Proto6 particularly concerning is not just the individual CVEs, but the systemic conditions that make exploitation likely. In AI and data engineering ecosystems—which are now central to enterprise infrastructure—Protobuf schemas move constantly: through CI/CD pipelines during model training, across microservice boundaries in vector databases, through orchestration systems like Kubernetes, and between external APIs and internal services. A threat actor with the ability to poison a single schema repository (through supply chain compromise, CI/CD infiltration, or API manipulation) could potentially compromise dozens of downstream services simultaneously.


    CVE-2026-44295 (the most severe) is particularly insidious because it allows code injection during the build phase itself. An attacker who can introduce a crafted schema name into a build system doesn't just compromise the resulting application—they can exfiltrate build secrets, inject backdoors into production artifacts, or corrupt the build output entirely. This attack vector transforms protobuf.js from a runtime risk into a supply chain weapon.


    The researchers' observation that "protobuf.js is heavily used inside databases, vector stores, inference pipelines, orchestration systems, CI/CD tooling, and cloud SDKs" is the critical insight here. This isn't a vulnerability affecting a niche JavaScript library—this is a foundational dependency in the infrastructure that modern enterprises depend on. The patch timeline matters enormously; organizations using transitive dependencies through Google Cloud SDKs or orchestration platforms may not even realize they're exposed until they actively update.


    The defensive lesson is clear: treat schemas and metadata with the same rigor you'd apply to code. Implement schema validation pipelines, sign critical configuration artifacts, monitor for unexpected changes to schema repositories, and never assume that a YAML file, Protobuf definition, or configuration document is less dangerous than executable code. In supply chain security, the distinction between "data" and "code" has become dangerously blurred.


    — HackWire Editorial


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)