Impact
Wire’s protobuf readers do not enforce length boundaries consistently before advancing cursors or allocating memory. A positive length that overflows a 32‑bit counter can wrap the cursor position to a negative limit, allowing the parser to read beyond its intended boundary. An attacker who sends specially crafted protobuf data can trigger unchecked exceptions, out‑of‑bounds reads, or uncontrolled allocations, causing the process to crash or consume excessive resources. The vulnerability leads to denial of service; there is no evidence of confidentiality, integrity, or code‑execution impact.
Affected Systems
The Square Wire library used for Android, Kotlin, Swift, and Java gRPC and protocol buffers is affected. Versions prior to 6.4.5 in the 6.x series and prior to 7.0.0‑alpha04 in the 7.x series lack the necessary length validation. Any application that incorporates one of these vulnerable library releases is at risk.
Risk and Exploitability
With a CVSS score of 7.5, the vulnerability is classified as high severity. The EPSS score indicates a very low probability of exploitation, and it is not listed in the CISA KEV catalog. An attacker could exploit it remotely by sending crafted messages to a service that uses the vulnerable library, or locally by providing malicious input to a process that parses protobuf data. The impact is limited to service interruption, with no known data compromise or code execution. Because the exploit requires control over protobuf input, mitigation primarily involves updating the library or enforcing strict input validation.
OpenCVE Enrichment
Github GHSA