CVE-2026-44294 is a denial-of-service vulnerability in protobufjs affecting versions through 7.5.5 and versions 8.0.0–8.0.1. The library generates JavaScript property accessors from schema-controlled field and oneof names without correctly escaping certain control characters. A crafted protobuf schema or JSON descriptor can introduce syntax errors into generated encode, decode, verify, fromObject, or toObject functions, preventing their compilation and making affected message types unusable. The vulnerability is fixed in versions 7.5.6 and 8.0.2.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone Python proof-of-concept for CVE-2026-44289, with the README also listing related CVEs affecting protobuf.js. The repository contains 6 files: a README, license, requirements, a CVE naming template, and one executable Python PoC file. The main and only code file, cve-2026-44289.py, implements a simplified recursive protobuf decoder class and a payload generator. Core capability: the PoC creates a deeply nested length-delimited protobuf-style payload using generate_deep_nested_payload(), then feeds it into VulnerableProtobufDecoder.decode(), which recursively decodes nested messages without a depth limit when run in vulnerable mode. This demonstrates uncontrolled recursion leading to RecursionError / simulated stack overflow, i.e., a denial-of-service condition. In safe mode, the same decoder is instantiated with a max_depth limit to show how the issue can be mitigated. Exploit structure: - VulnerableProtobufDecoder.decode(): recursively parses varint tags and length-delimited nested fields; the recursive self.decode(nested_data, depth + 1) call is the vulnerable behavior. - generate_deep_nested_payload(depth): constructs attacker-controlled nested binary input by repeatedly wrapping the previous payload in field 1, wire type 2. - _encode_varint(value): helper for protobuf-style varint encoding. - main(): CLI interface supporting payload generation and decode testing. Operationally, this is not a remote exploit and contains no shell, command execution, callback, or persistence logic. It is a local PoC / lab demonstrator for parser denial of service. No network services, IPs, or C2 endpoints are present. The only fingerprintable runtime artifact is the default payload file path payload.bin. The requirements file mentions protobuf and google-api-python-client, but the PoC itself relies only on Python standard library modules (argparse, sys, struct, typing). Overall, the repository’s purpose is educational demonstration of uncontrolled recursion in protobuf decoding rather than weaponized exploitation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An availability vulnerability in protobufjs caused by improperly escaped control characters in schema-controlled names. A crafted schema or JSON descriptor can cause generated encode, decode, verify, or conversion functions to fail during compilation. The reference rates the vulnerability Medium, with a CVSS v3 base score of 5.3, and identifies fixes in versions 7.5.6 and 8.0.2.
Vulnerability in protobufjs code generation from .proto schemas where a malicious schema or JSON descriptor with problematic characters can trigger denial of service.
A denial-of-service vulnerability in protobuf.js caused by crafted field names in generated code.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.