CVEs (5)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Google Netapp8Active Iq Unified Manager BluexpOntap Tools+5 moreJun 17, 2026 Sep 19, 2024 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 Any project that parses untrusted Protocol Buffers data containing an arbitrary number of nested groups / series of SGROUP tags can corrupted by exceeding the stack limit i.e. StackOverflow. Parsing nested groups as unkn...Show more |
1Google 2Protobuf Java Protobuf JavaliteJun 17, 2026 Dec 12, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A parsing issue similar to CVE-2022-3171, but with Message-Type Extensions in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing mult...Show more |
1Google 2Protobuf Java Protobuf JavaliteJun 17, 2026 Dec 12, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A parsing issue similar to CVE-2022-3171, but with textformat in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instance...Show more |
2Fedoraproject Google6Fedora Google ProtobufProtobuf Java+3 moreJun 17, 2026 Oct 12, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A parsing issue with binary data in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded me...Show more |
2Google Oracle7Communications Cloud Native Core Console Communications Cloud Native Core Network Repository FunctionCommunications Cloud Native Core Policy+4 moreJun 17, 2026 Jan 10, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue in protobuf-java allowed the interleaving of com.google.protobuf.UnknownFieldSet fields in such a way that would be processed out of order. A small malicious payload can occupy the parser for several minutes by...Show more |