CVE-2026-54269: protobufjs: Schema-derived names can shadow runtime-significant properties
Summary
protobufjs accepted certain schema-derived names that could collide with properties used by protobufjs runtime helpers. The known affected names are fields named hasOwnProperty, field or oneof names such as $type when loaded through protobufjs JSON/reflection descriptors, and service methods whose generated helper name is rpcCall.
When affected message or service types were used, protobufjs could read schema-controlled data where it expected an own-property helper, reflected type metadata, or the base RPC helper. This could cause deterministic exceptions or recursive calls in affected decode post-checks, verification, object conversion, reflected JSON serialization, or protobufjs RPC helper invocation.
Impact
An attacker who can provide or influence protobuf schemas or protobufjs JSON descriptors may be able to make affected message or service types unusable, resulting in denial of service for the affected processing path.
Applications using only trusted schemas are affected only if those schemas contain one of the problematic names and the application reaches the affected API path.
The issue is not known to allow code execution by itself.
Preconditions
The application must use an affected protobufjs version. The application must load or use a schema or protobufjs JSON descriptor containing one of the problematic names: a field named hasOwnProperty, a field or oneof named $type through protobufjs JSON/reflection descriptor input, or a service method whose generated helper name is rpcCall. The application must reach the affected API path for that name: required-field decode post-checks, verify, or toObject for hasOwnProperty; reflected message JSON serialization for $type; or protobufjs RPC service invocation for rpcCall.
Workarounds
Do not load protobuf schemas or protobufjs JSON descriptors from untrusted sources with affected versions. If untrusted schemas or descriptors must be accepted, validate schema-derived field, oneof, and service method names before loading and reject the problematic names described above.
Applications using trusted schemas can avoid the issue by renaming affected fields or service methods, or by avoiding the affected API path.
Other sources
protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 8.6.0 and 7.6.3, protobufjs accepted certain schema-derived names that could collide with properties used by protobufjs runtime helpers. The known affected names are fields named hasOwnProperty, field or oneof names such as $type when loaded through protobufjs JSON/reflection descriptors, and service methods whose generated helper name is rpcCall. When affected message or service types were used, protobufjs could read schema-controlled data where it expected an own-property helper, reflected type metadata, or the base RPC helper. This could cause deterministic exceptions or recursive calls in affected decode post-checks, verification, object conversion, reflected JSON serialization, or protobufjs RPC helper invocation. This vulnerability is fixed in 8.6.0 and 7.6.3.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/protobufjsto a version that resolves this vulnerability.Fixed in 8.6.0 - Upgrade
Upgrade
npm/protobufjs-clito a version that resolves this vulnerability.Fixed in 1.3.3 - Upgrade
Upgrade
npm/protobufjs-clito a version that resolves this vulnerability.Fixed in 2.5.1 - Upgrade
Upgrade
npm/protobufjsto a version that resolves this vulnerability.Fixed in 7.6.3 - Upgrade
Upgrade
protobufjsto a version that resolves this vulnerability.Fixed in 8.6.0 - Upgrade
Upgrade
protobufjsto a version that resolves this vulnerability.Fixed in 7.6.3 - Configuration
When loading protobuf definitions or protobufjs JSON/reflection descriptors, validate and reject schema-derived names that are: (1) a field named `hasOwnProperty`, (2) a field or oneof named `$type` (from protobufjs JSON/reflection descriptor input), and (3) service methods whose generated helper name is `rpcCall`. This mitigates schema-controlled name collisions that can trigger deterministic exceptions/recursive calls in affected decode/verify/toObject/reflected JSON serialization/rpcCall paths.
protobufjs schema/descriptor loading Schema-derived field/oneof/service method names = reject problematic names - Compensating control
Do not load or accept protobuf schemas or protobufjs JSON descriptors from untrusted sources when using affected protobufjs versions. If untrusted schemas/descriptors must be accepted, validate schema-derived field, oneof, and service method names before loading and reject the problematic names (`hasOwnProperty`, `$type` via JSON/reflection descriptor, and generated `rpcCall`).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-54269?
The severity of CVE-2026-54269 is rated as medium with a score of 5.3.
Which software is affected by CVE-2026-54269?
CVE-2026-54269 affects the npm packages protobufjs and protobufjs-cli.
How do I fix CVE-2026-54269?
To fix CVE-2026-54269, ensure that you avoid using certain schema-derived names such as 'hasOwnProperty' and '$type' in your protobufjs descriptors.
What is the risk associated with CVE-2026-54269?
The risk associated with CVE-2026-54269 is rated as 27, indicating a level of concern that should be addressed.
Can CVE-2026-54269 lead to potential security issues?
Yes, CVE-2026-54269 can lead to security issues as certain names may collide with protobufjs runtime functionalities.