highVulnerability

GHSA-qjfj-3mm5-vrjg

## Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-p2gh-cfq4-4wjc. This link is maintained to preserve external references. ## Original Description A Denial of Service (DoS) vulnerability exists in the Protobuf PHP library during the parsing of untrusted input. Maliciously structured messages—specifically those containing negative varints or deep recursion—can be used to crash the application, impacting service availability.

Properties

ghsa_id
GHSA-qjfj-3mm5-vrjg
summary
Withdrawn Advisory: Protobuf: Denial of Service issue through malicious messages containing negative varints or deep recursion
severity
high
cve_id
GHSA-qjfj-3mm5-vrjg
is_ghsa_only
true
ghsa_published
2026-04-16T15:31:33Z
source_url
https://github.com/advisories/GHSA-qjfj-3mm5-vrjg
ghsa_updated
2026-04-16T22:59:20Z

Related Entities (4)

AFFECTS (1)

[Software]composer/google/protobuf

HAS_WEAKNESS (1)

[Weakness]Improper Input Validation

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]composer/google/protobuf

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-qjfj-3mm5-vrjg — Ninja Signal Threat Intelligence | Ninja Signal