Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-j452-xhg8-qg39 | Mafintosh's protocol-buffers-schema is vulnerable to prototype pollution |
Fri, 17 Apr 2026 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-1135 |
Fri, 17 Apr 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-915 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 16 Apr 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-1135 |
Wed, 15 Apr 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-1174 |
Wed, 15 Apr 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mafintosh
Mafintosh protocol-buffers-schema Parser |
|
| Vendors & Products |
Mafintosh
Mafintosh protocol-buffers-schema Parser |
Wed, 15 Apr 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-1174 |
Wed, 15 Apr 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 15 Apr 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | JavaScript is vulnerable to prototype pollution in Mafintosh's protocol-buffers-schema Version 3.6.0, where an attacker may alter the application logic, bypass security checks, cause a DoS or achieve remote code execution. | |
| Title | Mafintosh's protocol-buffers-schema is vulnerable to prototype pollution | |
| References |
|
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2026-04-15T18:55:45.526Z
Reserved: 2026-04-07T17:20:03.756Z
Link: CVE-2026-5758
Updated: 2026-04-15T18:55:39.046Z
Status : Awaiting Analysis
Published: 2026-04-15T18:17:24.920
Modified: 2026-04-17T15:17:00.957
Link: CVE-2026-5758
OpenCVE Enrichment
Updated: 2026-04-17T09:30:14Z
Github GHSA