-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| com.google.protobuf:protobuf-java | maven | >= 3.21.0-rc-1, < 3.21.7 | 3.21.7 |
| com.google.protobuf:protobuf-kotlin | maven | >= 3.21.0-rc-1, < 3.21.7 | 3.21.7 |
| google-protobuf | rubygems | >= 3.21.0.rc.1, < 3.21.7 | 3.21.7 |
| com.google.protobuf:protobuf-javalite | maven | >= 3.21.0-rc-1, < 3.21.7 | 3.21.7 |
| com.google.protobuf:protobuf-kotlin-lite | maven | >= 3.21.0-rc-1, < 3.21.7 | 3.21.7 |
| com.google.protobuf:protobuf-java | maven | >= 3.20.0-rc-1, < 3.20.3 | 3.20.3 |
| com.google.protobuf:protobuf-java | maven | >= 3.17.0-rc-1, < 3.19.6 | 3.19.6 |
| com.google.protobuf:protobuf-java | maven | < 3.16.3 | 3.16.3 |
| com.google.protobuf:protobuf-kotlin | maven | >= 3.20.0-rc-1, < 3.20.3 | 3.20.3 |
| com.google.protobuf:protobuf-kotlin | maven | >= 3.17.0-rc-1, < 3.19.6 | 3.19.6 |
| com.google.protobuf:protobuf-kotlin | maven | < 3.16.3 | 3.16.3 |
| google-protobuf | rubygems | >= 3.20.0.rc.1, < 3.20.3 | 3.20.3 |
| google-protobuf | rubygems | >= 3.17.0.rc.1, < 3.19.6 | 3.19.6 |
| google-protobuf | rubygems | < 3.16.3 | 3.16.3 |
| com.google.protobuf:protobuf-javalite | maven | >= 3.20.0-rc-1, < 3.20.3 | 3.20.3 |
| com.google.protobuf:protobuf-javalite | maven | >= 3.17.0-rc-1, < 3.19.6 | 3.19.6 |
| com.google.protobuf:protobuf-javalite | maven | < 3.16.3 | 3.16.3 |
| com.google.protobuf:protobuf-kotlin-lite | maven | >= 3.20.0-rc-1, < 3.20.3 | 3.20.3 |
| com.google.protobuf:protobuf-kotlin-lite | maven | >= 3.17.0-rc-1, < 3.19.6 | 3.19.6 |
| com.google.protobuf:protobuf-kotlin-lite | maven | < 3.16.3 | 3.16.3 |
The vulnerability stems from inefficient parsing logic that created excessive object conversions between mutable/immutable forms. Release notes specifically mention:
KEV Misses 88% of Exploited CVEs- Get the report