« Back to list

CVE-2022-3171

Status: ModifiedHigh (7.5)—

A parsing issue with binary data in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields causes objects to be converted back-n-forth between mutable and immutable forms, resulting in potentially long garbage collection pauses. We recommend updating to the versions mentioned above.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (6)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2022-3171",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2022-3171",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-04-21T13:36:41.564407Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cve-coordination@google.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.3,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve-coordination@google.com",
      "affectedData": [
        {
          "vendor": "Google LLC",
          "product": "Protocolbuffers",
          "versions": [
            {
              "status": "affected",
              "version": "3.21.7",
              "lessThan": "3.21.7",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "3.20.3",
              "lessThan": "3.20.3",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "3.19.6",
              "lessThan": "3.19.6",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "3.16.3",
              "lessThan": "3.16.3",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "core and lite"
          ]
        }
      ]
    }
  ],
  "published": "2022-10-12T23:15:09.807",
  "references": [
    {
      "url": "https://github.com/protocolbuffers/protobuf/security/advisories/GHSA-h4h5-3hr4-j3g2",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cve-coordination@google.com"
    },
    {
      "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CBAUKJQL6O4TIWYBENORSY5P43TVB4M3/",
      "source": "cve-coordination@google.com"
    },
    {
      "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MPCGUT3T5L6C3IDWUPSUO22QDCGQKTOP/",
      "source": "cve-coordination@google.com"
    },
    {
      "url": "https://security.gentoo.org/glsa/202301-09",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cve-coordination@google.com"
    },
    {
      "url": "https://github.com/protocolbuffers/protobuf/security/advisories/GHSA-h4h5-3hr4-j3g2",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CBAUKJQL6O4TIWYBENORSY5P43TVB4M3/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MPCGUT3T5L6C3IDWUPSUO22QDCGQKTOP/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://security.gentoo.org/glsa/202301-09",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cve-coordination@google.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A parsing issue with binary data in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields causes objects to be converted back-n-forth between mutable and immutable forms, resulting in potentially long garbage collection pauses. We recommend updating to the versions mentioned above."
    },
    {
      "lang": "es",
      "value": "Un problema de análisis de datos binarios en protobuf-java core y lite versiones anteriores a 3.21.7, 3.20.3, 3.19.6 y 3.16.3, puede conllevar a un ataque de denegación de servicio. Las entradas que contienen múltiples instancias de mensajes insertados no repetidos con campos repetidos o desconocidos causan que los objetos sean convertidos de ida y vuelta entre las formas mutables e inmutables, resultando en pausas de recolección de basura potencialmente largas. Es recomendado actualizar a versiones mencionadas anteriormente"
    }
  ],
  "lastModified": "2026-06-17T04:58:59.997",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:google:google-protobuf:*:*:*:*:*:ruby:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1097AC30-B07F-4759-B62E-86B7856DB9BF",
              "versionEndExcluding": "3.16.3"
            },
            {
              "criteria": "cpe:2.3:a:google:google-protobuf:*:*:*:*:*:ruby:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F9A3FACD-AB55-41D7-86E2-A49E55C901E9",
              "versionEndExcluding": "3.19.6",
              "versionStartIncluding": "3.17.0"
            },
            {
              "criteria": "cpe:2.3:a:google:google-protobuf:*:*:*:*:*:ruby:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C92E0E73-782B-4ABB-A1C9-FB762744E1E8",
              "versionEndExcluding": "3.20.3",
              "versionStartIncluding": "3.20.0"
            },
            {
              "criteria": "cpe:2.3:a:google:google-protobuf:*:*:*:*:*:ruby:*:*",
              "vulnerable": true,
              "matchCriteriaId": "83C75530-D5AE-4AD9-A548-E4AD87300982",
              "versionEndExcluding": "3.21.7",
              "versionStartIncluding": "3.21.0"
            },
            {
              "criteria": "cpe:2.3:a:google:protobuf-java:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DC11741F-5A8A-4EBA-B4F8-046866813A97",
              "versionEndExcluding": "3.16.3"
            },
            {
              "criteria": "cpe:2.3:a:google:protobuf-java:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E669203D-A2DE-4148-A966-81843737603C",
              "versionEndExcluding": "3.19.6",
              "versionStartIncluding": "3.17.0"
            },
            {
              "criteria": "cpe:2.3:a:google:protobuf-java:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "56CA1E8D-A555-4F4F-80D8-F23D0DC50BB8",
              "versionEndExcluding": "3.20.3",
              "versionStartIncluding": "3.20.0"
            },
            {
              "criteria": "cpe:2.3:a:google:protobuf-java:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E82CFAC2-2F65-45FD-88D9-D42145FC4A4F",
              "versionEndExcluding": "3.21.7",
              "versionStartIncluding": "3.21.0"
            },
            {
              "criteria": "cpe:2.3:a:google:protobuf-javalite:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "50F55B55-9C50-4489-A1A7-9FD0893FB877",
              "versionEndExcluding": "3.16.3"
            },
            {
              "criteria": "cpe:2.3:a:google:protobuf-javalite:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2B4050D4-2224-467C-B46D-2CD734B3B0FB",
              "versionEndExcluding": "3.19.6",
              "versionStartIncluding": "3.17.0"
            },
            {
              "criteria": "cpe:2.3:a:google:protobuf-javalite:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "459A8615-D2ED-49F3-A81C-DC4560D96C93",
              "versionEndExcluding": "3.20.3",
              "versionStartIncluding": "3.20.0"
            },
            {
              "criteria": "cpe:2.3:a:google:protobuf-javalite:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "712693B9-41AB-41D1-97B2-560FDFEE0863",
              "versionEndExcluding": "3.21.7",
              "versionStartIncluding": "3.21.0"
            },
            {
              "criteria": "cpe:2.3:a:google:protobuf-kotlin:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "78B4C867-FA47-464D-85D1-DB46E5F035A6",
              "versionEndExcluding": "3.16.3"
            },
            {
              "criteria": "cpe:2.3:a:google:protobuf-kotlin:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DCCCC941-D98E-4B60-A1E2-282EBFF92B17",
              "versionEndExcluding": "3.19.6",
              "versionStartIncluding": "3.17.0"
            },
            {
              "criteria": "cpe:2.3:a:google:protobuf-kotlin:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "85E923BA-CB98-4B28-9BB5-A8D62E21D086",
              "versionEndExcluding": "3.20.3",
              "versionStartIncluding": "3.20.0"
            },
            {
              "criteria": "cpe:2.3:a:google:protobuf-kotlin:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "81C71355-5BBB-4197-A5A6-EFDF750C4C90",
              "versionEndExcluding": "3.21.7",
              "versionStartIncluding": "3.21.0"
            },
            {
              "criteria": "cpe:2.3:a:google:protobuf-kotlin-lite:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F758471D-1586-4A85-A567-85321F7B186F",
              "versionEndExcluding": "3.16.3"
            },
            {
              "criteria": "cpe:2.3:a:google:protobuf-kotlin-lite:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DAA9ACA3-A94B-473B-9393-51C32473954F",
              "versionEndExcluding": "3.19.6",
              "versionStartIncluding": "3.17.0"
            },
            {
              "criteria": "cpe:2.3:a:google:protobuf-kotlin-lite:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2EE1D9B6-30FC-4AB9-921B-A4A8F4E41387",
              "versionEndExcluding": "3.20.3",
              "versionStartIncluding": "3.20.0"
            },
            {
              "criteria": "cpe:2.3:a:google:protobuf-kotlin-lite:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9839B552-5DAF-4892-B34D-69201B0258A2",
              "versionEndExcluding": "3.21.7",
              "versionStartIncluding": "3.21.0"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E30D0E6F-4AE8-4284-8716-991DFA48CC5D"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve-coordination@google.com"
}