Skip to main content

Vendor/product archive

google / protobuf CVEs

Beta · best-effort

5 CVEs tagged to google / protobuf0 Critical, 4 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2026-0994

Published Jan 23, 2026

A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google…

CVSS 8.2 · High
evidence mentions
19
Buzz score
43.0
Vendor/product tagsBeta · best-effort

CVE-2024-7254

Published Sep 19, 2024

Any project that parses untrusted Protocol Buffers data containing an arbitrary number of nested groups / series of SGROUP tags can corrupted by exceeding the stack limit i.e. Sta…

CVSS 8.7 · High
evidence mentions
2
Buzz score
16.0

CVE-2024-2410

Published May 3, 2024

The JsonToBinaryStream() function is part of the protocol buffers C++ implementation and is used to parse JSON from a stream. If the input is broken up into separate chunks in a c…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2015-5237

Published Sep 25, 2017

protobuf allows remote authenticated attackers to cause a heap-based buffer overflow.

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1