Home/Product/google protobuf
Product

google protobuf

13 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-0994
<= 33.4
A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth
7.5HIGH
CVE-2025-4565
< 4.25.8
Any project that uses Protobuf Pure-Python backend to parse untrusted Protocol Buffers data containing an arbitrary number of rec
5.3MEDIUM
CVE-2024-7254
< 3.25.5
Any project that parses untrusted Protocol Buffers data containing an arbitrary number of nested groups / series of SGROUP tags
7.5HIGH
CVE-2024-2410
>= 4.22.0 and < 4.25.0
The JsonToBinaryStream() function is part of the protocol buffers C++ implementation and is used to parse JSON from a stream. If
7.6HIGH
CVE-2023-24535
all versions
Parsing invalid messages can panic. Parsing a text-format message which contains a potential number consisting of a minus sign, on
7.5HIGH
CVE-2022-3510
>= 3.16.0 and < 3.16.3
A parsing issue similar to CVE-2022-3171, but with Message-Type Extensions in protobuf-java core and lite versions prior to 3.21.7
7.5HIGH
CVE-2022-3509
>= 3.16.0 and < 3.16.3
A parsing issue similar to CVE-2022-3171, but with textformat in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.1
7.5HIGH
CVE-2022-3171
< 3.16.3
A parsing issue with binary data in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a
4.3MEDIUM
CVE-2022-1941
< 3.18.3
A parsing vulnerability for the MessageSet type in the ProtocolBuffers versions prior to and including 3.16.1, 3.17.3, 3.18.2, 3.1
7.5HIGH
CVE-2021-22570
< 3.15.0
Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, leading to an unchecked call
6.5MEDIUM
CVE-2021-22569
< 3.16.1
An issue in protobuf-java allowed the interleaving of com.google.protobuf.UnknownFieldSet fields in such a way that would be proce
7.5HIGH
CVE-2021-3121
< 1.3.2
An issue was discovered in GoGo Protobuf before 1.3.2. plugin/unmarshal/unmarshal.go lacks certain index validation, aka the "skip
8.6HIGH
CVE-2015-5237
<= 3.1.0
protobuf allows remote authenticated attackers to cause a heap-based buffer overflow.
8.8HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin