CVE-2022-3171
published 2022-12-12CVE-2022-3171: A parsing issue similar to CVE-2022-3171, but with textformat in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a…
PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.05%
60.2th percentile
A parsing issue similar to CVE-2022-3171, but with textformat in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields causes objects to be converted back-n-forth between mutable and immutable forms, resulting in potentially long garbage collection pauses. We recommend updating to the versions mentioned above.
Affected
42 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| atlassian | jira_software | — | — |
| debian | protobuf | < protobuf 3.21.9-3 (bookworm) | protobuf 3.21.9-3 (bookworm) |
| fedoraproject | fedora | — | — |
| google-protobuf | < 3.16.3 | 3.16.3 | |
| google-protobuf | >= 0 < 3.16.3 | 3.16.3 | |
| google-protobuf | >= 3.17.0 < 3.19.6 | 3.19.6 | |
| google-protobuf | >= 3.17.0.rc.1 < 3.19.6 | 3.19.6 | |
| google-protobuf | >= 3.20.0 < 3.20.3 | 3.20.3 | |
| google-protobuf | >= 3.20.0.rc.1 < 3.20.3 | 3.20.3 | |
| google-protobuf | >= 3.21.0 < 3.21.7 | 3.21.7 | |
| google-protobuf | >= 3.21.0.rc.1 < 3.21.7 | 3.21.7 | |
| protobuf | >= 0 < 3.21.9-3 | 3.21.9-3 | |
| protobuf | >= 0 < 3.21.9-3 | 3.21.9-3 | |
| protobuf | >= 0 < 3.21.9-3 | 3.21.9-3 | |
| protobuf-java | < 3.16.3 | 3.16.3 | |
| protobuf-java | >= 3.16.0 < 3.16.3 | 3.16.3 | |
| protobuf-java | >= 3.17.0 < 3.19.6 | 3.19.6 | |
| protobuf-java | >= 3.19.0 < 3.19.6 | 3.19.6 | |
| protobuf-java | >= 3.20.0 < 3.20.3 | 3.20.3 | |
| protobuf-java | >= 3.21.0 < 3.21.7 | 3.21.7 | |
| protobuf-javalite | < 3.16.3 | 3.16.3 | |
| protobuf-javalite | >= 3.16.0 < 3.16.3 | 3.16.3 | |
| protobuf-javalite | >= 3.17.0 < 3.19.6 | 3.19.6 | |
| protobuf-javalite | >= 3.20.0 < 3.20.3 | 3.20.3 | |
| protobuf-javalite | >= 3.21.0 < 3.21.7 | 3.21.7 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
ghsa7.5HIGH
osv7.5HIGH
vendor_msrc7.5HIGH
vendor_oracle7.5MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Protobuf Java vulnerable to Uncontrolled Resource Consumption
osv·2022-12-12·CVSS 7.5
CVE-2022-3510 [HIGH] Protobuf Java vulnerable to Uncontrolled Resource Consumption
Protobuf Java vulnerable to Uncontrolled Resource Consumption
A parsing issue similar to CVE-2022-3171, but with Message-Type Extensions in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields causes objects to be converted back-n-forth between mutable and immutable forms, resulting in potentially long garbage collection pauses. We recommend updating to the versions mentioned above.
OSV
CVE-2022-3510: A parsing issue similar to CVE-2022-3171, but with Message-Type Extensions in protobuf-java core and lite versions prior to 3
osv·2022-12-12·CVSS 7.5
CVE-2022-3510 [HIGH] CVE-2022-3510: A parsing issue similar to CVE-2022-3171, but with Message-Type Extensions in protobuf-java core and lite versions prior to 3
A parsing issue similar to CVE-2022-3171, but with Message-Type Extensions in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields causes objects to be converted back-n-forth between mutable and immutable forms, resulting in potentially long garbage collection pauses. We recommend updating to the versions mentioned above.
OSV
CVE-2022-3509: A parsing issue similar to CVE-2022-3171, but with textformat in protobuf-java core and lite versions prior to 3
osv·2022-12-12·CVSS 7.5
CVE-2022-3509 [HIGH] CVE-2022-3509: A parsing issue similar to CVE-2022-3171, but with textformat in protobuf-java core and lite versions prior to 3
A parsing issue similar to CVE-2022-3171, but with textformat in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields causes objects to be converted back-n-forth between mutable and immutable forms, resulting in potentially long garbage collection pauses. We recommend updating to the versions mentioned above.
GHSA
Protobuf Java vulnerable to Uncontrolled Resource Consumption
ghsa·2022-12-12·CVSS 7.5
CVE-2022-3509 [HIGH] CWE-400 Protobuf Java vulnerable to Uncontrolled Resource Consumption
Protobuf Java vulnerable to Uncontrolled Resource Consumption
A parsing issue similar to CVE-2022-3171, but with textformat in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields causes objects to be converted back-n-forth between mutable and immutable forms, resulting in potentially long garbage collection pauses. We recommend updating to the versions mentioned above.
OSV
Protobuf Java vulnerable to Uncontrolled Resource Consumption
osv·2022-12-12·CVSS 7.5
CVE-2022-3509 [HIGH] Protobuf Java vulnerable to Uncontrolled Resource Consumption
Protobuf Java vulnerable to Uncontrolled Resource Consumption
A parsing issue similar to CVE-2022-3171, but with textformat in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields causes objects to be converted back-n-forth between mutable and immutable forms, resulting in potentially long garbage collection pauses. We recommend updating to the versions mentioned above.
GHSA
Protobuf Java vulnerable to Uncontrolled Resource Consumption
ghsa·2022-12-12·CVSS 7.5
CVE-2022-3510 [HIGH] CWE-400 Protobuf Java vulnerable to Uncontrolled Resource Consumption
Protobuf Java vulnerable to Uncontrolled Resource Consumption
A parsing issue similar to CVE-2022-3171, but with Message-Type Extensions in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields causes objects to be converted back-n-forth between mutable and immutable forms, resulting in potentially long garbage collection pauses. We recommend updating to the versions mentioned above.
OSV
CVE-2022-3171: A parsing issue with binary data in protobuf-java core and lite versions prior to 3
osv·2022-10-12·CVSS 7.5
CVE-2022-3171 [HIGH] CVE-2022-3171: A parsing issue with binary data in protobuf-java core and lite versions prior to 3
A parsing issue with binary data in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields causes objects to be converted back-n-forth between mutable and immutable forms, resulting in potentially long garbage collection pauses. We recommend updating to the versions mentioned above.
GHSA
protobuf-java has a potential Denial of Service issue
ghsa·2022-10-04·CVSS 7.5
CVE-2022-3171 [HIGH] CWE-20 protobuf-java has a potential Denial of Service issue
protobuf-java has a potential Denial of Service issue
## Summary
A potential Denial of Service issue in `protobuf-java` core and lite was discovered in the parsing procedure for binary and text format data. Input streams containing multiple instances of non-repeated [embedded messages](http://developers.google.com/protocol-buffers/docs/encoding#embedded) with repeated or unknown fields causes objects to be converted back-n-forth between mutable and immutable forms, resulting in potentially long garbage collection pauses.
Reporter: [OSS Fuzz](https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=48771)
Affected versions: This issue affects both the Java full and lite Protobuf runtimes, as well as Protobuf for Kotlin and JRuby, which themselves use the Java Protobuf runtime.
## Severity
OSV
protobuf-java has a potential Denial of Service issue
osv·2022-10-04·CVSS 7.5
CVE-2022-3171 [HIGH] protobuf-java has a potential Denial of Service issue
protobuf-java has a potential Denial of Service issue
## Summary
A potential Denial of Service issue in `protobuf-java` core and lite was discovered in the parsing procedure for binary and text format data. Input streams containing multiple instances of non-repeated [embedded messages](http://developers.google.com/protocol-buffers/docs/encoding#embedded) with repeated or unknown fields causes objects to be converted back-n-forth between mutable and immutable forms, resulting in potentially long garbage collection pauses.
Reporter: [OSS Fuzz](https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=48771)
Affected versions: This issue affects both the Java full and lite Protobuf runtimes, as well as Protobuf for Kotlin and JRuby, which themselves use the Java Protobuf runtime.
## Severity
Atlassian
CVE-2022-3171: DoS (Denial of Service) com.google.protobuf:protobuf-java Dependency in Jira Software Data Center and Server
vendor_atlassian·2024-03-19·CVSS 7.5
CVE-2022-3171 [MEDIUM] CVE-2022-3171: DoS (Denial of Service) com.google.protobuf:protobuf-java Dependency in Jira Software Data Center and Server
CVE-2022-3171: DoS (Denial of Service) com.google.protobuf:protobuf-java Dependency in Jira Software Data Center and Server
DoS (Denial of Service) com.google.protobuf:protobuf-java Dependency in Jira Software Data Center and Server
CVE: CVE-2022-3171
Affected products: Jira Software
Oracle
Oracle Oracle GoldenGate Risk Matrix: Veridata (Google Protobuf-Java) — CVE-2022-3171
vendor_oracle·2023-10-15·CVSS 6.5
CVE-2022-3171 [MEDIUM] Oracle Oracle GoldenGate Risk Matrix: Veridata (Google Protobuf-Java) — CVE-2022-3171
Oracle Oracle GoldenGate Risk Matrix: Veridata (Google Protobuf-Java) vulnerability
CVE: CVE-2022-3171
CVSS: 6.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Adjacent
Network
Advisory: cpuoct2023 (OCT 2023)
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Accessibility (Google Protobuf-Java) — CVE-2022-3171
vendor_oracle·2023-07-15·CVSS 7.5
CVE-2022-3171 [MEDIUM] Oracle Oracle Financial Services Applications Risk Matrix: Accessibility (Google Protobuf-Java) — CVE-2022-3171
Oracle Oracle Financial Services Applications Risk Matrix: Accessibility (Google Protobuf-Java) vulnerability
CVE: CVE-2022-3171
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2023 (JUL 2023)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Core (Google Protobuf-Java) — CVE-2022-3171
vendor_oracle·2023-04-15·CVSS 7.5
CVE-2022-3171 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: Core (Google Protobuf-Java) — CVE-2022-3171
Oracle Oracle Communications Applications Risk Matrix: Core (Google Protobuf-Java) vulnerability
CVE: CVE-2022-3171
CVSS: 7.5
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2023 (APR 2023)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Policy (Google Protobuf-Java) — CVE-2022-3171
vendor_oracle·2023-01-15·CVSS 7.5
CVE-2022-3171 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: Policy (Google Protobuf-Java) — CVE-2022-3171
Oracle Oracle Communications Applications Risk Matrix: Policy (Google Protobuf-Java) vulnerability
CVE: CVE-2022-3171
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2023 (JAN 2023)
Red Hat
protobuf-java: Textformat parsing issue leads to DoS
vendor_redhat·2022-12-15·CVSS 4.3
CVE-2022-3509 [MEDIUM] CWE-915 protobuf-java: Textformat parsing issue leads to DoS
protobuf-java: Textformat parsing issue leads to DoS
A parsing issue similar to CVE-2022-3171, but with textformat in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields causes objects to be converted back-n-forth between mutable and immutable forms, resulting in potentially long garbage collection pauses. We recommend updating to the versions mentioned above.
A flaw was found in Textformat in protobuf-java core that can lead to a denial of service. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields can cause objects to convert between mutable and immutable forms, resu
Red Hat
protobuf-java: Message-Type Extensions parsing issue leads to DoS
vendor_redhat·2022-12-15·CVSS 4.3
CVE-2022-3510 [MEDIUM] CWE-915 protobuf-java: Message-Type Extensions parsing issue leads to DoS
protobuf-java: Message-Type Extensions parsing issue leads to DoS
A parsing issue similar to CVE-2022-3171, but with Message-Type Extensions in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields causes objects to be converted back-n-forth between mutable and immutable forms, resulting in potentially long garbage collection pauses. We recommend updating to the versions mentioned above.
A flaw was found in Message-Type Extensions in protobuf-java core that can lead to a denial of service. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields can cause objects to convert be
Red Hat
protobuf-java: timeout in parser leads to DoS
vendor_redhat·2022-10-12·CVSS 4.3
CVE-2022-3171 [MEDIUM] CWE-20 protobuf-java: timeout in parser leads to DoS
protobuf-java: timeout in parser leads to DoS
A parsing issue with binary data in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields causes objects to be converted back-n-forth between mutable and immutable forms, resulting in potentially long garbage collection pauses. We recommend updating to the versions mentioned above.
Microsoft
Memory handling vulnerability in ProtocolBuffers Java core and lite
vendor_msrc·2022-10-11·CVSS 7.5
CVE-2022-3171 [MEDIUM] CWE-20 Memory handling vulnerability in ProtocolBuffers Java core and lite
Memory handling vulnerability in ProtocolBuffers Java core and lite
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
Google: Google
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference:
Debian
CVE-2022-3171: protobuf - A parsing issue with binary data in protobuf-java core and lite versions prior t...
vendor_debian·2022·CVSS 4.3
CVE-2022-3171 [MEDIUM] CVE-2022-3171: protobuf - A parsing issue with binary data in protobuf-java core and lite versions prior t...
A parsing issue with binary data in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields causes objects to be converted back-n-forth between mutable and immutable forms, resulting in potentially long garbage collection pauses. We recommend updating to the versions mentioned above.
Scope: local
bookworm: resolved (fixed in 3.21.9-3)
bullseye: open
forky: resolved (fixed in 3.21.9-3)
sid: resolved (fixed in 3.21.9-3)
trixie: resolved (fixed in 3.21.9-3)
Debian
CVE-2022-3510: protobuf - A parsing issue similar to CVE-2022-3171, but with Message-Type Extensions in pr...
vendor_debian·2022·CVSS 4.3
CVE-2022-3510 [MEDIUM] CVE-2022-3510: protobuf - A parsing issue similar to CVE-2022-3171, but with Message-Type Extensions in pr...
A parsing issue similar to CVE-2022-3171, but with Message-Type Extensions in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields causes objects to be converted back-n-forth between mutable and immutable forms, resulting in potentially long garbage collection pauses. We recommend updating to the versions mentioned above.
Scope: local
bookworm: resolved (fixed in 3.21.9-3)
bullseye: open
forky: resolved (fixed in 3.21.9-3)
sid: resolved (fixed in 3.21.9-3)
trixie: resolved (fixed in 3.21.9-3)
Debian
CVE-2022-3509: protobuf - A parsing issue similar to CVE-2022-3171, but with textformat in protobuf-java c...
vendor_debian·2022·CVSS 4.3
CVE-2022-3509 [MEDIUM] CVE-2022-3509: protobuf - A parsing issue similar to CVE-2022-3171, but with textformat in protobuf-java c...
A parsing issue similar to CVE-2022-3171, but with textformat in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields causes objects to be converted back-n-forth between mutable and immutable forms, resulting in potentially long garbage collection pauses. We recommend updating to the versions mentioned above.
Scope: local
bookworm: resolved (fixed in 3.21.9-3)
bullseye: open
forky: resolved (fixed in 3.21.9-3)
sid: resolved (fixed in 3.21.9-3)
trixie: resolved (fixed in 3.21.9-3)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-12-12
Published