{"id":"CVE-2026-89418","published":"2026-09-17T14:17:52.157","lastModified":"2026-09-18T13:45:29.270","description":"google-protobuf contains an unbounded recursion when parsing unknown protobuf group fields. An attacker can send a small crafted payload of deeply nested START_GROUP wire bytes to any Node.js service that calls the generated deserializeBinary() API, causing a RangeError: Maximum call stack size exceeded and crashing the process. No authentication or prior knowledge of the schema is required.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":["CWE-674"],"vendors":[],"products":[],"references":[{"url":"https://github.com/protocolbuffers/protobuf-javascript/security/advisories/GHSA-5h29-r2cp-hfmr","tags":[]},{"url":"https://github.com/protocolbuffers/protobuf-javascript/security/advisories/GHSA-5h29-r2cp-hfmr","tags":[]}],"exploitRefs":[{"url":"https://github.com/protocolbuffers/protobuf-javascript/security/advisories/GHSA-5h29-r2cp-hfmr","tags":[]},{"url":"https://github.com/protocolbuffers/protobuf-javascript/security/advisories/GHSA-5h29-r2cp-hfmr","tags":[]}],"hasPoc":true,"ai":null}