highVulnerability

GHSA-p2gh-cfq4-4wjc

### Impact A Denial of Service (DoS) vulnerability exists in the Protobuf PHP library during the parsing of untrusted input. Maliciously structured messages—specifically those containing negative `varint`s or deep recursion—can be used to crash the application, impacting service availability. ### Patches Patches have been released to 5.34.0-RC1 and 4.33.6.

Properties

ghsa_id
GHSA-p2gh-cfq4-4wjc
severity
high
summary
Protobuf: Denial of Service issue through malicious messages containing negative varints or deep recursion
cve_id
GHSA-p2gh-cfq4-4wjc
is_ghsa_only
true
ghsa_published
2026-03-25T21:02:08Z
source_url
https://github.com/advisories/GHSA-p2gh-cfq4-4wjc
ghsa_updated
2026-03-25T21:02:08Z

Related Entities (3)

AFFECTS (1)

[Software]composer/google/protobuf

HAS_WEAKNESS (1)

[Weakness]Uncontrolled Resource Consumption

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-p2gh-cfq4-4wjc — Ninja Signal Threat Intelligence | Ninja Signal