Description
An issue in protobuf-java allowed the interleaving of com.google.protobuf.UnknownFieldSet fields in such a way that would be processed out of order. A small malicious payload can occupy the parser for several minutes by creating large numbers of short-lived objects that cause frequent, repeated pauses. We recommend upgrading libraries beyond the vulnerable versions.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3393-1 | protobuf security update |
EUVD |
EUVD-2022-0729 | An issue in protobuf-java allowed the interleaving of com.google.protobuf.UnknownFieldSet fields in such a way that would be processed out of order. A small malicious payload can occupy the parser for several minutes by creating large numbers of short-lived objects that cause frequent, repeated pauses. We recommend upgrading libraries beyond the vulnerable versions. |
Github GHSA |
GHSA-wrvw-hg22-4m67 | A potential Denial of Service issue in protobuf-java |
Ubuntu USN |
USN-5945-1 | Protocol Buffers vulnerabilities |
References
History
Mon, 21 Apr 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Subscriptions
Google
Subscribe
Google-protobuf
Subscribe
Protobuf-java
Subscribe
Protobuf-kotlin
Subscribe
Oracle
Subscribe
Communications Cloud Native Core Console
Subscribe
Communications Cloud Native Core Network Repository Function
Subscribe
Communications Cloud Native Core Policy
Subscribe
Spatial And Graph Mapviewer
Subscribe
Redhat
Subscribe
Camel Quarkus
Subscribe
Integration
Subscribe
Jboss Enterprise Bpms Platform
Subscribe
Jboss Fuse
Subscribe
Openshift Application Runtimes
Subscribe
Quarkus
Subscribe
Service Registry
Subscribe
Status: PUBLISHED
Assigner: Google
Published:
Updated: 2025-04-21T13:57:08.444Z
Reserved: 2021-01-05T00:00:00.000Z
Link: CVE-2021-22569
Updated: 2024-08-03T18:44:14.144Z
Status : Modified
Published: 2022-01-10T14:10:16.747
Modified: 2024-11-21T05:50:20.647
Link: CVE-2021-22569
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Github GHSA
Ubuntu USN