CVEs affecting projects tracked on Release Alert, from NVD & OSV.
protobufjs is vulnerable to ReDoS when parsing crafted invalid .proto files.