← Back

CVE-2022-3509

nvd nist
Published: Dec 12, 2022Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

A parsing issue similar to CVE-2022-3171, but with textformat in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields causes objects to be converted back-n-forth between mutable and immutable forms, resulting in potentially long garbage collection pauses. We recommend updating to the versions mentioned above.

Affected (8)

2 products
Protobuf Java
Protobuf Javalite
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Google
From 3.16.0 to 3.16.3
From 3.19.0 to 3.19.6
From 3.20.0 to 3.20.3
From 3.21.0 to 3.21.7
Google
From 3.16.0 to 3.16.3
From 3.17.0 to 3.19.6
From 3.20.0 to 3.20.3
From 3.21.0 to 3.21.7

References (2)

Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.