Google · Google.Protobuf · CVE-2026-89418
**Name of the Vulnerable Software and Affected Versions**
google-protobuf (affected versions not specified)
**Description**
The software contains an unbounded recursion issue when parsing unknown protobuf group fields. An attacker can send a crafted payload consisting of deeply nested START GROUP wire bytes to a Node.js service that utilizes the `deserializeBinary()` function. This action triggers a RangeError: Maximum call stack size exceeded, which leads to a process crash. This issue can be exploited without authentication or prior knowledge of the schema.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.