VDB
Sign up
HIGH

GHSA-p2gh-cfq4-4wjc

Protobuf: Denial of Service issue through malicious messages containing negative varints or deep recursion

Quick fix

GHSA-p2gh-cfq4-4wjc — google/protobuf: upgrade to the fixed version with the command below.

composer require google/protobuf:^4.33.6

Details

### Impact A Denial of Service (DoS) vulnerability exists in the Protobuf PHP library during the parsing of untrusted input. Maliciously structured messages—specifically those containing negative `varint`s or deep recursion—can be used to crash the application, impacting service availability.

### Patches Patches have been released to 5.34.0-RC1 and 4.33.6.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/google/protobuf
Introduced in: 0Fixed in: 4.33.6
Fixcomposer require google/protobuf:^4.33.6

References