CVE-2022-3510
published 2022-12-12CVE-2022-3510: A parsing issue similar to CVE-2022-3171, but with Message-Type Extensions in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3…
PriorityP337high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.48%
38.3th percentile
A parsing issue similar to CVE-2022-3171, but with Message-Type Extensions in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields causes objects to be converted back-n-forth between mutable and immutable forms, resulting in potentially long garbage collection pauses. We recommend updating to the versions mentioned above.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | protobuf | < protobuf 3.21.9-3 (bookworm) | protobuf 3.21.9-3 (bookworm) |
| protobuf | >= 0 < 3.21.9-3 | 3.21.9-3 | |
| protobuf | >= 0 < 3.21.9-3 | 3.21.9-3 | |
| protobuf | >= 0 < 3.21.9-3 | 3.21.9-3 | |
| protobuf-java | >= 3.16.0 < 3.16.3 | 3.16.3 | |
| protobuf-java | >= 3.19.0 < 3.19.6 | 3.19.6 | |
| protobuf-java | >= 3.20.0 < 3.20.3 | 3.20.3 | |
| protobuf-java | >= 3.21.0 < 3.21.7 | 3.21.7 | |
| protobuf-javalite | >= 3.16.0 < 3.16.3 | 3.16.3 | |
| protobuf-javalite | >= 3.17.0 < 3.19.6 | 3.19.6 | |
| protobuf-javalite | >= 3.20.0 < 3.20.3 | 3.20.3 | |
| protobuf-javalite | >= 3.21.0 < 3.21.7 | 3.21.7 | |
| msrc | azl3_python-tensorboard_2.16.2-6_on_azure_linux_3.0 | — | — |
| msrc | azl3_pytorch_2.2.2-7_on_azure_linux_3.0 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
ghsa7.5HIGH
osv7.5HIGH
vendor_msrc7.5HIGH
vendor_oracle7.5HIGH
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Protobuf Java vulnerable to Uncontrolled Resource Consumption
osv·2022-12-12·CVSS 7.5
CVE-2022-3510 [HIGH] Protobuf Java vulnerable to Uncontrolled Resource Consumption
Protobuf Java vulnerable to Uncontrolled Resource Consumption
A parsing issue similar to CVE-2022-3171, but with Message-Type Extensions in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields causes objects to be converted back-n-forth between mutable and immutable forms, resulting in potentially long garbage collection pauses. We recommend updating to the versions mentioned above.
OSV
CVE-2022-3510: A parsing issue similar to CVE-2022-3171, but with Message-Type Extensions in protobuf-java core and lite versions prior to 3
osv·2022-12-12·CVSS 7.5
CVE-2022-3510 [HIGH] CVE-2022-3510: A parsing issue similar to CVE-2022-3171, but with Message-Type Extensions in protobuf-java core and lite versions prior to 3
A parsing issue similar to CVE-2022-3171, but with Message-Type Extensions in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields causes objects to be converted back-n-forth between mutable and immutable forms, resulting in potentially long garbage collection pauses. We recommend updating to the versions mentioned above.
GHSA
Protobuf Java vulnerable to Uncontrolled Resource Consumption
ghsa·2022-12-12·CVSS 7.5
CVE-2022-3510 [HIGH] CWE-400 Protobuf Java vulnerable to Uncontrolled Resource Consumption
Protobuf Java vulnerable to Uncontrolled Resource Consumption
A parsing issue similar to CVE-2022-3171, but with Message-Type Extensions in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields causes objects to be converted back-n-forth between mutable and immutable forms, resulting in potentially long garbage collection pauses. We recommend updating to the versions mentioned above.
Oracle
Oracle Oracle Analytics Risk Matrix: Analytics Server, BI Search (Google Protobuf-Java) — CVE-2022-3510
vendor_oracle·2024-01-15·CVSS 7.5
CVE-2022-3510 [HIGH] Oracle Oracle Analytics Risk Matrix: Analytics Server, BI Search (Google Protobuf-Java) — CVE-2022-3510
Oracle Oracle Analytics Risk Matrix: Analytics Server, BI Search (Google Protobuf-Java) vulnerability
CVE: CVE-2022-3510
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2024 (JAN 2024)
Oracle
Oracle Oracle Communications Risk Matrix: Policy (Google Protobuf-Java) — CVE-2022-3510
vendor_oracle·2023-01-15·CVSS 7.5
CVE-2022-3510 [HIGH] Oracle Oracle Communications Risk Matrix: Policy (Google Protobuf-Java) — CVE-2022-3510
Oracle Oracle Communications Risk Matrix: Policy (Google Protobuf-Java) vulnerability
CVE: CVE-2022-3510
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2023 (JAN 2023)
Red Hat
protobuf-java: Message-Type Extensions parsing issue leads to DoS
vendor_redhat·2022-12-15·CVSS 4.3
CVE-2022-3510 [MEDIUM] CWE-915 protobuf-java: Message-Type Extensions parsing issue leads to DoS
protobuf-java: Message-Type Extensions parsing issue leads to DoS
A parsing issue similar to CVE-2022-3171, but with Message-Type Extensions in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields causes objects to be converted back-n-forth between mutable and immutable forms, resulting in potentially long garbage collection pauses. We recommend updating to the versions mentioned above.
A flaw was found in Message-Type Extensions in protobuf-java core that can lead to a denial of service. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields can cause objects to convert be
Microsoft
Parsing issue in protobuf message-type extension
vendor_msrc·2022-11-08·CVSS 7.5
CVE-2022-3510 [HIGH] Parsing issue in protobuf message-type extension
Parsing issue in protobuf message-type extension
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
Google: Google
Customer Action Required: Yes
Debian
CVE-2022-3510: protobuf - A parsing issue similar to CVE-2022-3171, but with Message-Type Extensions in pr...
vendor_debian·2022·CVSS 4.3
CVE-2022-3510 [MEDIUM] CVE-2022-3510: protobuf - A parsing issue similar to CVE-2022-3171, but with Message-Type Extensions in pr...
A parsing issue similar to CVE-2022-3171, but with Message-Type Extensions in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields causes objects to be converted back-n-forth between mutable and immutable forms, resulting in potentially long garbage collection pauses. We recommend updating to the versions mentioned above.
Scope: local
bookworm: resolved (fixed in 3.21.9-3)
bullseye: open
forky: resolved (fixed in 3.21.9-3)
sid: resolved (fixed in 3.21.9-3)
trixie: resolved (fixed in 3.21.9-3)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-12-12
Published