Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:33570
HistoryJan 10, 2022 - 5:41 a.m.

Denial Of Service (DoS)

2022-01-1005:41:50
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
22
dos
protobuf
vulnerability
crash
unknownfieldset
attacker
payload
application

EPSS

0.001

Percentile

42.3%

protobuf is vulnerable to denial of service. The library does not properly handle unknown fields in the UnknownFieldSet function in UnknownFieldSet.java, allowing an attacker to crash the application through many short-lived objects by providing malicious payload.