CVE detail
CVE-2026-41242
protobufjs compiles protobuf definitions into JavaScript (JS) functions. In versions prior to 8.0.1 and 7.5.5, attackers can inject arbitrary code in the "type" fields of protobuf definitions, which will then execute during object decoding using that definition. Versions 8.0.1 and 7.5.5 patch the issue.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 25.6 · diversity 13.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
12 source links · newest first
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41242.jsonsecurity.access.redhat.com
No excerpt available.
Vendor Advisorysecurity.access.redhat.comApr 18, 2026, 5:16 PM - https://bugzilla.redhat.com/show_bug.cgi?id=2459442bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comApr 18, 2026, 5:16 PM - https://access.redhat.com/security/cve/CVE-2026-41242access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 18, 2026, 5:16 PM - https://access.redhat.com/errata/RHSA-2026:37275access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 18, 2026, 5:16 PM - https://access.redhat.com/errata/RHSA-2026:26234access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 18, 2026, 5:16 PM - https://access.redhat.com/errata/RHSA-2026:24977access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 18, 2026, 5:16 PM - https://access.redhat.com/errata/RHSA-2026:21338access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 18, 2026, 5:16 PM No excerpt available.
Exploitgithub.comApr 18, 2026, 5:16 PMNo excerpt available.
Exploitgithub.comApr 18, 2026, 5:16 PMNo excerpt available.
Exploitgithub.comApr 18, 2026, 5:16 PMNo excerpt available.
Exploitgithub.comApr 18, 2026, 5:16 PMNo excerpt available.
Exploitgithub.comApr 18, 2026, 5:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-44293CVSS 7.7 · High
protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs generated JavaScript for toObject conversion could include an unsafe…
- CVE-2026-44291CVSS 8.1 · High
protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs used plain objects with inherited prototypes for internal type lookup…
- CVE-2026-65880CVSS 10.0 · Critical
Joomla Extension - balbooa.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3 - An insecure form processing logic allowed code execution for forms that include t…
- CVE-2026-56747CVSS 8.7 · High
Improper control of generation of code in the JSON Pointer-to-accessor compiler in Cribl Stream before 4.18.2 allows a remote authenticated attacker with edit privileges to execut…
- CVE-2026-14289CVSS 9.0 · Critical
The FacturaONE para WooCommerce con VeriFactu WordPress plugin before 5.37 does not authenticate one of its request handlers, whose only protection is derived from a cryptographic…
- CVE-2026-63720CVSS 7.5 · High
datamodel-code-generator prior to version 0.70.0 contains a code injection vulnerability that allows attackers who control input schemas to achieve remote code execution by supply…