CVE-2026-44290: protobuf.js: Process-wide denial of service through unsafe option paths
(updated )
protobufjs allowed certain schema option paths to traverse through inherited object properties while applying options. A crafted protobuf schema or JSON descriptor could cause option handling to write to properties on global JavaScript constructors, corrupting process-wide built-in functionality.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-44290 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →