PT-2022-6841 · Google+1 · Protobuf-Java+1

CVE-2022-3510

·

Published

2022-11-11

·

Updated

2026-07-21

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions protobuf-java versions prior to 3.21.7 protobuf-java versions prior to 3.20.3 protobuf-java versions prior to 3.19.6 protobuf-java versions prior to 3.16.3
Description The issue is related to insufficient input validation in the Java Protocol Buffers library, which can lead to a denial of service attack. Specifically, inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields cause objects to be converted back and forth between mutable and immutable forms, resulting in potentially long garbage collection pauses.
Recommendations Update to version 3.21.7 or later. Update to version 3.20.3 or later. Update to version 3.19.6 or later. Update to version 3.16.3 or later.

Exploit

Fix

DoS

Resource Exhaustion

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-04975
CLEANSTART-2026-DD05788
CLEANSTART-2026-JU62349
CLEANSTART-2026-KU61465
CLEANSTART-2026-LE11246
CLEANSTART-2026-RN56220
CLEANSTART-2026-RS65756
CLEANSTART-2026-SH44648
CLEANSTART-2026-SQ91016
CLEANSTART-2026-SV95049
CLEANSTART-2026-VH41554
CLEANSTART-2026-WK99982
CVE-2022-3510
GHSA-4GG5-VX3J-XWC7

Affected Products

Debian
Protobuf-Java