Google Protobuf-kotlin: vulnerabilities and CVEs
Google Protobuf-kotlin has 3 published vulnerabilities, 0 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.
CVEs3
Last 12 months0
Critical0
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-7254 | High (8.7) | 2.8% | — | Sep 19, 2024 | Any project that parses untrusted Protocol Buffers data containing an arbitrary number of nested groups / series of SGROUP tags can corrupted by exceeding the stack limit i.e. StackOverflow. Parsing nested groups as… |
| CVE-2022-3171 | High (7.5) | 1.1% | — | Oct 12, 2022 | A parsing issue with binary data in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded… |
| CVE-2021-22569 | Medium (5.5) | 1.7% | — | Jan 10, 2022 | An issue in protobuf-java allowed the interleaving of com.google.protobuf.UnknownFieldSet fields in such a way that would be processed out of order. A small malicious payload can occupy the parser for several minutes by… |
📰 Related news
- Alert Google patches three Chrome flaws, including a critical WebGL bug that escapes the sandbox
- Alert Google fixes 95 vulnerabilities in Chrome, 23 of them critical, in its latest Stable channel update
- Alert Google fixes two critical vulnerabilities in Cloud Application Integration with no customer action required