protobuf
cpe:2.3:a:google:protobuf:*:*:*:*:*:*:*, +2 more
- < 5.34.0-RC1
- < 4.33.6
A denial-of-service vulnerability has been identified in the Protobuf PHP library, specifically in versions prior to 5.34.0-RC1 and 4.33.6. This vulnerability arises during the parsing of untrusted input, where maliciously crafted messages containing negative varints or deep recursion can crash the application, disrupting service availability.
Exploitation of this vulnerability leads to a denial-of-service condition, causing the application to crash and unavailable.
Users can upgrade to Protobuf versions 5.34.0-RC1 or 4.33.6 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.