Protobuf PHP Library Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in the Protobuf PHP library, specifically in versions prior to 5.34.0-RC1 and 4.33.6. This vulnerability arises during the parsing of untrusted input, where maliciously crafted messages containing negative varints or deep recursion can crash the application, disrupting service availability.

Impact

Exploitation of this vulnerability leads to a denial-of-service condition, causing the application to crash and unavailable.

Remediation

Users can upgrade to Protobuf versions 5.34.0-RC1 or 4.33.6 to address this vulnerability.

Added: Apr 16, 2026, 3:24 PM
Updated: Apr 16, 2026, 3:24 PM

Vulnerability Rating

Custom Algorithm
spread
6.6
impact
2.5
exploitability
4.7
remediation
7.7
relevance
6.0
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.