Google Protobuf: vulnerabilidades y CVE
Google Protobuf tiene 7 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE7
Últimos 12 meses2
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-89418 | Alta (8.7) | 0.28% | — | 17 sept 2026 | google-protobuf contains an unbounded recursion when parsing unknown protobuf group fields. An attacker can send a small crafted payload of deeply nested START_GROUP wire bytes to any Node.js service that calls the… |
| CVE-2026-0994 | Alta (8.2) | 0.72% | — | 23 ene 2026 | A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages. Due to missing… |
| CVE-2024-7254 | Alta (8.7) | 2.8% | — | 19 sept 2024 | Any project that parses untrusted Protocol Buffers data containing an arbitrary number of nested groups / series of SGROUP tags can corrupted by exceeding the stack limit i.e. StackOverflow. Parsing nested groups as… |
| CVE-2024-2410 | Crítica (9.8) | 0.33% | — | 3 may 2024 | The JsonToBinaryStream() function is part of the protocol buffers C++ implementation and is used to parse JSON from a stream. If the input is broken up into separate chunks in a certain way, the parser will attempt to… |
| CVE-2024-24786 | Alta (7.5) | 1.3% | — | 5 mar 2024 | The protojson.Unmarshal function can enter an infinite loop when unmarshaling certain forms of invalid JSON. This condition can occur when unmarshaling into a message which contains a google.protobuf.Any value, or when… |
| CVE-2021-22570 | Media (5.5) | 2.7% | — | 26 ene 2022 | Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, leading to an unchecked call into the proto file's name during generation of the resulting error message. Since the… |
| CVE-2015-5237 | Alta (8.8) | 5.0% | — | 25 sept 2017 | protobuf allows remote authenticated attackers to cause a heap-based buffer overflow. |