CVE-2022-3509
published 2022-12-12CVE-2022-3509: A parsing issue similar to CVE-2022-3171, but with textformat in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a…
PriorityP337high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.57%
43.2th percentile
A parsing issue similar to CVE-2022-3171, but with textformat in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields causes objects to be converted back-n-forth between mutable and immutable forms, resulting in potentially long garbage collection pauses. We recommend updating to the versions mentioned above.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| atlassian | jira_software | — | — |
| debian | protobuf | < protobuf 3.21.9-3 (bookworm) | protobuf 3.21.9-3 (bookworm) |
| protobuf | >= 0 < 3.21.9-3 | 3.21.9-3 | |
| protobuf | >= 0 < 3.21.9-3 | 3.21.9-3 | |
| protobuf | >= 0 < 3.21.9-3 | 3.21.9-3 | |
| protobuf-java | >= 3.16.0 < 3.16.3 | 3.16.3 | |
| protobuf-java | >= 3.19.0 < 3.19.6 | 3.19.6 | |
| protobuf-java | >= 3.20.0 < 3.20.3 | 3.20.3 | |
| protobuf-java | >= 3.21.0 < 3.21.7 | 3.21.7 | |
| protobuf-javalite | >= 3.16.0 < 3.16.3 | 3.16.3 | |
| protobuf-javalite | >= 3.17.0 < 3.19.6 | 3.19.6 | |
| protobuf-javalite | >= 3.20.0 < 3.20.3 | 3.20.3 | |
| protobuf-javalite | >= 3.21.0 < 3.21.7 | 3.21.7 | |
| msrc | azl3_python-tensorboard_2.11.0-3_on_azure_linux_3.0 | — | — |
| msrc | azl3_python-tensorboard_2.16.2-2_on_azure_linux_3.0 | — | — |
| msrc | azl3_pytorch_2.2.2-7_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
ghsa7.5HIGH
osv7.5HIGH
vendor_msrc7.5HIGH
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2022-3509: A parsing issue similar to CVE-2022-3171, but with textformat in protobuf-java core and lite versions prior to 3
osv·2022-12-12·CVSS 7.5
CVE-2022-3509 [HIGH] CVE-2022-3509: A parsing issue similar to CVE-2022-3171, but with textformat in protobuf-java core and lite versions prior to 3
A parsing issue similar to CVE-2022-3171, but with textformat in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields causes objects to be converted back-n-forth between mutable and immutable forms, resulting in potentially long garbage collection pauses. We recommend updating to the versions mentioned above.
GHSA
Protobuf Java vulnerable to Uncontrolled Resource Consumption
ghsa·2022-12-12·CVSS 7.5
CVE-2022-3509 [HIGH] CWE-400 Protobuf Java vulnerable to Uncontrolled Resource Consumption
Protobuf Java vulnerable to Uncontrolled Resource Consumption
A parsing issue similar to CVE-2022-3171, but with textformat in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields causes objects to be converted back-n-forth between mutable and immutable forms, resulting in potentially long garbage collection pauses. We recommend updating to the versions mentioned above.
OSV
Protobuf Java vulnerable to Uncontrolled Resource Consumption
osv·2022-12-12·CVSS 7.5
CVE-2022-3509 [HIGH] Protobuf Java vulnerable to Uncontrolled Resource Consumption
Protobuf Java vulnerable to Uncontrolled Resource Consumption
A parsing issue similar to CVE-2022-3171, but with textformat in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields causes objects to be converted back-n-forth between mutable and immutable forms, resulting in potentially long garbage collection pauses. We recommend updating to the versions mentioned above.
Atlassian
CVE-2022-3509: DoS (Denial of Service) com.google.protobuf:protobuf-java Dependency in Jira Software Data Center and Server
vendor_atlassian·2024-03-19·CVSS 7.5
CVE-2022-3509 [HIGH] CVE-2022-3509: DoS (Denial of Service) com.google.protobuf:protobuf-java Dependency in Jira Software Data Center and Server
CVE-2022-3509: DoS (Denial of Service) com.google.protobuf:protobuf-java Dependency in Jira Software Data Center and Server
DoS (Denial of Service) com.google.protobuf:protobuf-java Dependency in Jira Software Data Center and Server
CVE: CVE-2022-3509
Affected products: Jira Software
Red Hat
protobuf-java: Textformat parsing issue leads to DoS
vendor_redhat·2022-12-15·CVSS 4.3
CVE-2022-3509 [MEDIUM] CWE-915 protobuf-java: Textformat parsing issue leads to DoS
protobuf-java: Textformat parsing issue leads to DoS
A parsing issue similar to CVE-2022-3171, but with textformat in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields causes objects to be converted back-n-forth between mutable and immutable forms, resulting in potentially long garbage collection pauses. We recommend updating to the versions mentioned above.
A flaw was found in Textformat in protobuf-java core that can lead to a denial of service. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields can cause objects to convert between mutable and immutable forms, resu
Microsoft
Parsing issue in protobuf textformat
vendor_msrc·2022-11-08·CVSS 7.5
CVE-2022-3509 [HIGH] Parsing issue in protobuf textformat
Parsing issue in protobuf textformat
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
Google: Google
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en
Debian
CVE-2022-3509: protobuf - A parsing issue similar to CVE-2022-3171, but with textformat in protobuf-java c...
vendor_debian·2022·CVSS 4.3
CVE-2022-3509 [MEDIUM] CVE-2022-3509: protobuf - A parsing issue similar to CVE-2022-3171, but with textformat in protobuf-java c...
A parsing issue similar to CVE-2022-3171, but with textformat in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields causes objects to be converted back-n-forth between mutable and immutable forms, resulting in potentially long garbage collection pauses. We recommend updating to the versions mentioned above.
Scope: local
bookworm: resolved (fixed in 3.21.9-3)
bullseye: open
forky: resolved (fixed in 3.21.9-3)
sid: resolved (fixed in 3.21.9-3)
trixie: resolved (fixed in 3.21.9-3)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-12-12
Published