CVE-2026-44289 is an uncontrolled-recursion denial-of-service vulnerability in protobufjs. Versions through 7.5.5 and versions 8.0.0 through 8.0.1 decode nested Protocol Buffers data without enforcing a recursion-depth limit. The issue affects both skipping unknown group fields and generated decoders processing nested message fields. A sufficiently nested crafted protobuf binary payload can recursively consume the JavaScript call stack until stack exhaustion terminates or disrupts the decoding process.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone Python proof-of-concept for CVE-2026-44289, with the README also listing related CVEs affecting protobuf.js. The repository contains 6 files: a README, license, requirements, a CVE naming template, and one executable Python PoC file. The main and only code file, cve-2026-44289.py, implements a simplified recursive protobuf decoder class and a payload generator. Core capability: the PoC creates a deeply nested length-delimited protobuf-style payload using generate_deep_nested_payload(), then feeds it into VulnerableProtobufDecoder.decode(), which recursively decodes nested messages without a depth limit when run in vulnerable mode. This demonstrates uncontrolled recursion leading to RecursionError / simulated stack overflow, i.e., a denial-of-service condition. In safe mode, the same decoder is instantiated with a max_depth limit to show how the issue can be mitigated. Exploit structure: - VulnerableProtobufDecoder.decode(): recursively parses varint tags and length-delimited nested fields; the recursive self.decode(nested_data, depth + 1) call is the vulnerable behavior. - generate_deep_nested_payload(depth): constructs attacker-controlled nested binary input by repeatedly wrapping the previous payload in field 1, wire type 2. - _encode_varint(value): helper for protobuf-style varint encoding. - main(): CLI interface supporting payload generation and decode testing. Operationally, this is not a remote exploit and contains no shell, command execution, callback, or persistence logic. It is a local PoC / lab demonstrator for parser denial of service. No network services, IPs, or C2 endpoints are present. The only fingerprintable runtime artifact is the default payload file path payload.bin. The requirements file mentions protobuf and google-api-python-client, but the PoC itself relies only on Python standard library modules (argparse, sys, struct, typing). Overall, the repository’s purpose is educational demonstration of uncontrolled recursion in protobuf decoding rather than weaponized exploitation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A high-severity denial-of-service vulnerability in protobufjs caused by unbounded recursion when decoding nested protobuf messages or skipping unknown group fields. Crafted binary input can exhaust the JavaScript call stack. The reported CVSS v3 base score is 7.5. Fixed versions are 7.5.6 and 8.0.2, with a patch publication date of September 28, 2026.
High-severity unlimited recursion vulnerability in protobufjs during Protobuf message decoding that can exhaust memory and crash the process, causing denial of service.
A denial-of-service vulnerability in protobuf.js caused by unbounded protobuf recursion.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.