Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-6409

Опубликовано: 16 апр. 2026
Источник: debian
EPSS Низкий

Описание

A Denial of Service (DoS) vulnerability exists in the Protobuf PHP library during the parsing of untrusted input. Maliciously structured messages—specifically those containing negative varints or deep recursion—can be used to crash the application, impacting service availability.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
protobuffixed3.21.12-16package
protobuffixed3.21.12-11+deb13u1trixiepackage
protobuffixed3.21.12-3+deb12u1bookwormpackage
protobufpostponedbullseyepackage

Примечания

  • https://github.com/protocolbuffers/protobuf/security/advisories/GHSA-p2gh-cfq4-4wjc

  • https://github.com/protocolbuffers/protobuf/issues/24159

  • Fixed by: https://github.com/protocolbuffers/protobuf/commit/60e93d2d104f2af9cd345b1c6f3891d91430244a (v4.33.6)

  • https://github.com/protocolbuffers/protobuf/issues/25067

  • Fixed by: https://github.com/protocolbuffers/protobuf/commit/c8e9b27d95c6ab2d0668b5889e7dac2c477b7038 (v4.33.6)

EPSS

Процентиль: 29%
0.0036
Низкий

Связанные уязвимости

ubuntu
4 месяца назад

A Denial of Service (DoS) vulnerability exists in the Protobuf PHP library during the parsing of untrusted input. Maliciously structured messages—specifically those containing negative varints or deep recursion—can be used to crash the application, impacting service availability.

nvd
4 месяца назад

A Denial of Service (DoS) vulnerability exists in the Protobuf PHP library during the parsing of untrusted input. Maliciously structured messages—specifically those containing negative varints or deep recursion—can be used to crash the application, impacting service availability.

msrc
3 месяца назад

Denial of Service (DoS) vulnerability exists in the Protobuf PHP library during the parsing of untrusted input

github
4 месяца назад

Protobuf: Denial of Service issue through malicious messages containing negative varints or deep recursion

CVSS3: 7.5
fstec
7 месяцев назад

Уязвимость библиотеки сериализации данных protobuf, связанная с недостаточной проверкой вводимых данных, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 29%
0.0036
Низкий