Description
google-protobuf contains an unbounded recursion when parsing unknown protobuf group fields. An attacker can send a small crafted payload of deeply nested START_GROUP wire bytes to any Node.js service that calls the generated deserializeBinary() API, causing a RangeError: Maximum call stack size exceeded and crashing the process. No authentication or prior knowledge of the schema is required.
Published: 2026-09-17
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an unbounded recursion that occurs in the google-protobuf JavaScript library when parsing unknown group fields in Protocol Buffers. Deserialization of a small, manually crafted payload composed of deeply nested START_GROUP bytes will trigger a RangeError due to the maximum call stack size being exceeded. This leads to a crash of the Node.js process, effectively denying service. The flaw is a classic instance of uncontrolled recursion (CWE‑674) and requires no authentication or knowledge of the schema.

Affected Systems

Any Node.js application that uses the google-protobuf npm package and calls the generated deserializeBinary() API is vulnerable. This includes services built with Node.js that process incoming protobuf messages via this library.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity; the EPSS score is not reported, and the vulnerability is not listed in the CISA KEV catalog. An attacker can send the crafted payload to any exposed endpoint that accepts protobuf data. Because the flaw does not require prior authentication or schema knowledge, the attack surface is broad. Exploitability is high if the service is reachable, as a single malformed message can crash the process, leading to a denial-of-service condition. The lack of authentication or privilege checks further increases the risk.

Generated by OpenCVE AI on September 17, 2026 at 23:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade google-protobuf to the latest patched version that fixes the recursion issue.
  • Validate the size or depth of incoming protobuf messages before deserialization to prevent stack overflow.
  • Configure a process manager or health check to automatically restart the Node.js service upon crash and monitor for RangeError exceptions.

Generated by OpenCVE AI on September 17, 2026 at 23:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google protobuf-javascript
Vendors & Products Google
Google protobuf-javascript

Fri, 18 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-606
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Important


Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description google-protobuf contains an unbounded recursion when parsing unknown protobuf group fields. An attacker can send a small crafted payload of deeply nested START_GROUP wire bytes to any Node.js service that calls the generated deserializeBinary() API, causing a RangeError: Maximum call stack size exceeded and crashing the process. No authentication or prior knowledge of the schema is required.
Title Uncontrolled Recursion leading to Denial of Service in protobuf-javascript (google-protobuf)
Weaknesses CWE-674
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Google Protobuf-javascript
cve-icon MITRE

Status: PUBLISHED

Assigner: Google

Published:

Updated: 2026-09-17T19:38:55.924Z

Reserved: 2026-09-11T18:09:56.712Z

Link: CVE-2026-89418

cve-icon Vulnrichment

Updated: 2026-09-17T19:38:43.184Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-17T14:17:52.157

Modified: 2026-09-18T13:45:29.270

Link: CVE-2026-89418

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-17T13:27:30Z

Links: CVE-2026-89418 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:02:19Z

Weaknesses
  • CWE-606

    Unchecked Input for Loop Condition

  • CWE-674

    Uncontrolled Recursion