Skip to content

fix: bump protobufjs to ^7.5.5 to address GHSA-xq3m-2v4x-88gg#3048

Merged
murgatroid99 merged 1 commit intogrpc:masterfrom
tawni-dev:fix/protobufjs-7.5.5-security-bump
May 7, 2026
Merged

fix: bump protobufjs to ^7.5.5 to address GHSA-xq3m-2v4x-88gg#3048
murgatroid99 merged 1 commit intogrpc:masterfrom
tawni-dev:fix/protobufjs-7.5.5-security-bump

Conversation

@tawni-dev
Copy link
Copy Markdown
Contributor

Summary

Bumps protobufjs from ^7.5.3 to ^7.5.5 to address the arbitrary code execution vulnerability in protobufjs < 7.5.5.
Security advisory: GHSA-xq3m-2v4x-88gg

Details

Attackers can inject arbitrary code into the type fields of protobuf definitions, which executes during object decoding. Fixed in protobufjs 7.5.5.

Testing

8/8 unit tests pass

@linux-foundation-easycla
Copy link
Copy Markdown

linux-foundation-easycla Bot commented Apr 18, 2026

CLA Signed
The committers listed above are authorized under a signed CLA.

  • ✅ login: tawni-dev / name: Tawni Glover (736a45c)

@coldfannn
Copy link
Copy Markdown

@murgatroid99 @nicolasnoble PTAL.

@murgatroid99 murgatroid99 merged commit 1589dda into grpc:master May 7, 2026
4 of 5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants