-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability manifests in group parsing logic where both ByteArrayProtoReader32 and ProtoReader classes handled nested groups through skipGroup calls without recursion depth tracking. The patch adds recursionDepth counter checks around these calls, confirming these were the vulnerable paths. Both implementations shared identical vulnerable patterns for STATE_START_GROUP handling prior to the enforced recursion limit.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| com.squareup.wire:wire-runtime | maven | < 5.2.0 | 5.2.0 |
Ongoing coverage of React2Shell