Impact
The vulnerability is an unbounded recursion that occurs in the google-protobuf JavaScript library when parsing unknown group fields in Protocol Buffers. Deserialization of a small, manually crafted payload composed of deeply nested START_GROUP bytes will trigger a RangeError due to the maximum call stack size being exceeded. This leads to a crash of the Node.js process, effectively denying service. The flaw is a classic instance of uncontrolled recursion (CWE‑674) and requires no authentication or knowledge of the schema.
Affected Systems
Any Node.js application that uses the google-protobuf npm package and calls the generated deserializeBinary() API is vulnerable. This includes services built with Node.js that process incoming protobuf messages via this library.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity; the EPSS score is not reported, and the vulnerability is not listed in the CISA KEV catalog. An attacker can send the crafted payload to any exposed endpoint that accepts protobuf data. Because the flaw does not require prior authentication or schema knowledge, the attack surface is broad. Exploitability is high if the service is reachable, as a single malformed message can crash the process, leading to a denial-of-service condition. The lack of authentication or privilege checks further increases the risk.
OpenCVE Enrichment