Description
Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.4.5 and 7.0.0-alpha04, Wire protobuf readers do not consistently validate attacker-controlled lengths against the current logical message boundary before advancing cursors, pointers, limits, slices, or allocations. In Kotlin, ProtoAdapter.decode(ByteArray) and ProtoAdapter.decode(ByteString) use ByteArrayProtoReader32.internalNextLengthDelimited(), where a positive oversized length can wrap pos + length to a negative limit and escape the existing negative-length check. Related ProtoReader, ReadBuffer.readVarint(), ReadBuffer.verifyAdditional(count:), packed-repeated, nested-message, and ProtoDecoder.decodeSizeDelimited(_:from:) paths can cross logical boundaries, perform pointer arithmetic, reserve capacity, or convert an unrepresentable size before proving the requested bytes exist. An attacker who supplies malformed protobuf bytes can cause unchecked exceptions, traps, out-of-bounds behavior, or excessive allocation, resulting in denial of service without known confidentiality, integrity, or code-execution impact. This issue is fixed in versions 6.4.5 and 7.0.0-alpha04.
Published: 2026-09-16
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

Wire’s protobuf readers do not enforce length boundaries consistently before advancing cursors or allocating memory. A positive length that overflows a 32‑bit counter can wrap the cursor position to a negative limit, allowing the parser to read beyond its intended boundary. An attacker who sends specially crafted protobuf data can trigger unchecked exceptions, out‑of‑bounds reads, or uncontrolled allocations, causing the process to crash or consume excessive resources. The vulnerability leads to denial of service; there is no evidence of confidentiality, integrity, or code‑execution impact.

Affected Systems

The Square Wire library used for Android, Kotlin, Swift, and Java gRPC and protocol buffers is affected. Versions prior to 6.4.5 in the 6.x series and prior to 7.0.0‑alpha04 in the 7.x series lack the necessary length validation. Any application that incorporates one of these vulnerable library releases is at risk.

Risk and Exploitability

With a CVSS score of 7.5, the vulnerability is classified as high severity. The EPSS score indicates a very low probability of exploitation, and it is not listed in the CISA KEV catalog. An attacker could exploit it remotely by sending crafted messages to a service that uses the vulnerable library, or locally by providing malicious input to a process that parses protobuf data. The impact is limited to service interruption, with no known data compromise or code execution. Because the exploit requires control over protobuf input, mitigation primarily involves updating the library or enforcing strict input validation.

Generated by OpenCVE AI on September 17, 2026 at 22:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Square Wire library to version 6.4.5 or later, or to 7.0.0‑alpha04 or later when available.
  • Verify that your application does not call any internal reader APIs that bypass the public API safety checks; replace such calls with the public decoding interfaces provided by Wire.
  • If an immediate upgrade is infeasible, implement application‑level validation that rejects protobuf messages whose declared lengths exceed reasonable limits before passing them to the Wire decoder.

Generated by OpenCVE AI on September 17, 2026 at 22:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-9rm7-3qhh-h2mc Wire: Unauthenticated decoder crash via 32-bit length integer overflow in ByteArrayProtoReader32 (incomplete fix of CVE-2026-45799)
History

Fri, 18 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
First Time appeared Square
Square wire
Vendors & Products Square
Square wire

Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.4.5 and 7.0.0-alpha04, Wire protobuf readers do not consistently validate attacker-controlled lengths against the current logical message boundary before advancing cursors, pointers, limits, slices, or allocations. In Kotlin, ProtoAdapter.decode(ByteArray) and ProtoAdapter.decode(ByteString) use ByteArrayProtoReader32.internalNextLengthDelimited(), where a positive oversized length can wrap pos + length to a negative limit and escape the existing negative-length check. Related ProtoReader, ReadBuffer.readVarint(), ReadBuffer.verifyAdditional(count:), packed-repeated, nested-message, and ProtoDecoder.decodeSizeDelimited(_:from:) paths can cross logical boundaries, perform pointer arithmetic, reserve capacity, or convert an unrepresentable size before proving the requested bytes exist. An attacker who supplies malformed protobuf bytes can cause unchecked exceptions, traps, out-of-bounds behavior, or excessive allocation, resulting in denial of service without known confidentiality, integrity, or code-execution impact. This issue is fixed in versions 6.4.5 and 7.0.0-alpha04.
Title Wire: Unauthenticated decoder crash via 32-bit length integer overflow in ByteArrayProtoReader32 (incomplete fix of CVE-2026-45799)
Weaknesses CWE-190
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T19:41:42.146Z

Reserved: 2026-07-15T16:54:55.816Z

Link: CVE-2026-63126

cve-icon Vulnrichment

Updated: 2026-09-16T19:41:37.069Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T19:17:24.013

Modified: 2026-09-30T17:43:24.057

Link: CVE-2026-63126

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T04:00:03Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound