PT-2026-30396 · Packagist · Google.Protobuf

Published

2026-03-25

·

Updated

2026-03-25

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Impact

A Denial of Service (DoS) vulnerability exists in the Protobuf PHP library during the parsing of untrusted input. Maliciously structured messages—specifically those containing negative varints or deep recursion—can be used to crash the application, impacting service availability.

Patches

Patches have been released to 5.34.0-RC1 and 4.33.6.

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-P2GH-CFQ4-4WJC

Affected Products

Google.Protobuf