Description
A parsing issue similar to CVE-2022-3171, but with Message-Type Extensions in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields causes objects to be converted back-n-forth between mutable and immutable forms, resulting in potentially long garbage collection pauses. We recommend updating to the versions mentioned above.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-7503 | A parsing issue similar to CVE-2022-3171, but with Message-Type Extensions in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields causes objects to be converted back-n-forth between mutable and immutable forms, resulting in potentially long garbage collection pauses. We recommend updating to the versions mentioned above. |
Github GHSA |
GHSA-4gg5-vx3j-xwc7 | Protobuf Java vulnerable to Uncontrolled Resource Consumption |
References
History
Tue, 22 Apr 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 22 Apr 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-400 |
Status: PUBLISHED
Assigner: Google
Published:
Updated: 2025-04-22T15:09:17.050Z
Reserved: 2022-10-14T13:53:33.104Z
Link: CVE-2022-3510
Updated: 2024-08-03T01:14:01.623Z
Status : Modified
Published: 2022-12-12T13:15:14.670
Modified: 2025-04-22T15:15:59.860
Link: CVE-2022-3510
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA