Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p2gh-cfq4-4wjc

Опубликовано: 25 мар. 2026
Источник: github
Github: Прошло ревью
CVSS4: 7.1

Описание

Protobuf: Denial of Service issue through malicious messages containing negative varints or deep recursion

Impact

A Denial of Service (DoS) vulnerability exists in the Protobuf PHP library during the parsing of untrusted input. Maliciously structured messages—specifically those containing negative varints or deep recursion—can be used to crash the application, impacting service availability.

Patches

Patches have been released to 5.34.0-RC1 and 4.33.6.

Пакеты

Наименование

google/protobuf

composer
Затронутые версииВерсия исправления

< 4.33.6

4.33.6

EPSS

Процентиль: 29%
0.0036
Низкий

7.1 High

CVSS4

Дефекты

CWE-400

Связанные уязвимости

ubuntu
4 месяца назад

A Denial of Service (DoS) vulnerability exists in the Protobuf PHP library during the parsing of untrusted input. Maliciously structured messages—specifically those containing negative varints or deep recursion—can be used to crash the application, impacting service availability.

nvd
4 месяца назад

A Denial of Service (DoS) vulnerability exists in the Protobuf PHP library during the parsing of untrusted input. Maliciously structured messages—specifically those containing negative varints or deep recursion—can be used to crash the application, impacting service availability.

msrc
3 месяца назад

Denial of Service (DoS) vulnerability exists in the Protobuf PHP library during the parsing of untrusted input

debian
4 месяца назад

A Denial of Service (DoS) vulnerability exists in the Protobuf PHP lib ...

CVSS3: 7.5
fstec
7 месяцев назад

Уязвимость библиотеки сериализации данных protobuf, связанная с недостаточной проверкой вводимых данных, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 29%
0.0036
Низкий

7.1 High

CVSS4

Дефекты

CWE-400