highVulnerability
GHSA-p2gh-cfq4-4wjc
### Impact A Denial of Service (DoS) vulnerability exists in the Protobuf PHP library during the parsing of untrusted input. Maliciously structured messages—specifically those containing negative `varint`s or deep recursion—can be used to crash the application, impacting service availability. ### Patches Patches have been released to 5.34.0-RC1 and 4.33.6.
Properties
- ghsa_id
- GHSA-p2gh-cfq4-4wjc
- severity
- high
- summary
- Protobuf: Denial of Service issue through malicious messages containing negative varints or deep recursion
- cve_id
- GHSA-p2gh-cfq4-4wjc
- is_ghsa_only
- true
- ghsa_published
- 2026-03-25T21:02:08Z
- source_url
- https://github.com/advisories/GHSA-p2gh-cfq4-4wjc
- ghsa_updated
- 2026-03-25T21:02:08Z
Related Entities (3)
AFFECTS (1)
→[Software]composer/google/protobuf
HAS_WEAKNESS (1)
→[Weakness]Uncontrolled Resource Consumption
REPORTED_BY (1)
→[Source]GitHub Advisory Database
Explore deeper with Ninja Signal's threat intelligence graph