PT-2021-7857 · Google+6 · Protobuf-Java+6

Published

2021-09-26

·

Updated

2026-05-18

·

CVE-2021-22569

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions protobuf-java (affected versions not specified)
Description The issue is related to the incorrect order of actions in the Protobuf data serialization protocol analysis component. This allows a remote attacker to cause a denial of service. A small malicious payload can occupy the parser for several minutes by creating large numbers of short-lived objects that cause frequent, repeated pauses.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2023-1230
AZL-41431
BDU:2023-03823
CLEANSTART-2026-JU62349
CLEANSTART-2026-SQ91016
CLEANSTART-2026-SV95049
CLEANSTART-2026-WK99982
CVE-2021-22569
DLA-3393-1
GHSA-WRVW-HG22-4M67
OESA-2022-1694
OPENSUSE-SU-2022_3922-1
SUSE-SU-2022:3922-1
SUSE-SU-2022_3922-1
SUSE-SU-2023:2783-1
SUSE-SU-2023:2783-2
USN-5945-1

Affected Products

Alt Linux
Astra Linux
Jira Service Management Server
Linuxmint
Suse
Ubuntu
Protobuf-Java