HIGH
GHSA-p2gh-cfq4-4wjc
Protobuf: Denial of Service issue through malicious messages containing negative varints or deep recursion
Quick fix
GHSA-p2gh-cfq4-4wjc — google/protobuf: upgrade to the fixed version with the command below.
composer require google/protobuf:^4.33.6Details
### Impact A Denial of Service (DoS) vulnerability exists in the Protobuf PHP library during the parsing of untrusted input. Maliciously structured messages—specifically those containing negative `varint`s or deep recursion—can be used to crash the application, impacting service availability.
### Patches Patches have been released to 5.34.0-RC1 and 4.33.6.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/google/protobuf
Introduced in:
0Fixed in: 4.33.6Fix
composer require google/protobuf:^4.33.6References
- https://github.com/protocolbuffers/protobuf/security/advisories/GHSA-p2gh-cfq4-4wjc[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-6409[ADVISORY]
- https://github.com/protocolbuffers/protobuf/issues/24159[WEB]
- https://github.com/protocolbuffers/protobuf/issues/25067[WEB]
- https://github.com/protocolbuffers/protobuf/commit/60e93d2d104f2af9cd345b1c6f3891d91430244a[WEB]
- https://github.com/protocolbuffers/protobuf/commit/c8e9b27d95c6ab2d0668b5889e7dac2c477b7038[WEB]
- https://github.com/protocolbuffers/protobuf[PACKAGE]