Description
A parsing issue with binary data in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields causes objects to be converted back-n-forth between mutable and immutable forms, resulting in potentially long garbage collection pauses. We recommend updating to the versions mentioned above.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-7102 | A parsing issue with binary data in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields causes objects to be converted back-n-forth between mutable and immutable forms, resulting in potentially long garbage collection pauses. We recommend updating to the versions mentioned above. |
Github GHSA |
GHSA-h4h5-3hr4-j3g2 | protobuf-java has a potential Denial of Service issue |
References
History
Mon, 21 Apr 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Subscriptions
Fedoraproject
Subscribe
Fedora
Subscribe
Google
Subscribe
Google-protobuf
Subscribe
Protobuf-java
Subscribe
Protobuf-javalite
Subscribe
Protobuf-kotlin
Subscribe
Protobuf-kotlin-lite
Subscribe
Redhat
Subscribe
Amq Streams
Subscribe
Integration
Subscribe
Jboss Enterprise Bpms Platform
Subscribe
Quarkus
Subscribe
Status: PUBLISHED
Assigner: Google
Published:
Updated: 2025-04-21T13:47:57.569Z
Reserved: 2022-09-09T00:00:00.000Z
Link: CVE-2022-3171
Updated: 2024-08-03T01:00:10.773Z
Status : Modified
Published: 2022-10-12T23:15:09.807
Modified: 2024-11-21T07:18:58.277
Link: CVE-2022-3171
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA