CVE-2024-7254
published 2024-09-19CVE-2024-7254: Any project that parses untrusted Protocol Buffers data containing an arbitrary number of nested groups / series of SGROUP tags can corrupted by exceeding the…
PriorityP344high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
2.77%
84.7th percentile
Any project that parses untrusted Protocol Buffers data containing an arbitrary number of nested groups / series of SGROUP tags can corrupted by exceeding the stack limit i.e. StackOverflow. Parsing nested groups as unknown fields with DiscardUnknownFieldsParser or Java Protobuf Lite parser, or against Protobuf map fields, creates unbounded recursions that can be abused by an attacker.
Affected
39 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | protobuf | < protobuf 3.21.12-12 (forky) | protobuf 3.21.12-12 (forky) |
| google-protobuf | < 3.25.5 | 3.25.5 | |
| google-protobuf | < 4.27.5 | 4.27.5 | |
| google-protobuf | < 4.28.2 | 4.28.2 | |
| google-protobuf | >= 0 < 3.25.5 | 3.25.5 | |
| google-protobuf | >= 4.0.0.rc.1 < 4.27.5 | 4.27.5 | |
| google-protobuf | >= 4.28.0.rc.1 < 4.28.2 | 4.28.2 | |
| protobuf | < 3.25.5 | 3.25.5 | |
| protobuf | >= 0 < 3.21.12-12 | 3.21.12-12 | |
| protobuf | >= 0 < 3.12.4-1ubuntu7.22.04.4 | 3.12.4-1ubuntu7.22.04.4 | |
| protobuf | >= 0 < 3.21.12-8.2ubuntu0.2 | 3.21.12-8.2ubuntu0.2 | |
| protobuf | >= 0 < 2.6.1-1.3ubuntu0.1~esm4 | 2.6.1-1.3ubuntu0.1~esm4 | |
| protobuf | >= 0 < 3.0.0-9.1ubuntu1.1+esm3 | 3.0.0-9.1ubuntu1.1+esm3 | |
| protobuf | >= 0 < 3.6.1.3-2ubuntu5.2+esm2 | 3.6.1.3-2ubuntu5.2+esm2 | |
| protobuf | >= 4.0.0 < 4.27.5 | 4.27.5 | |
| protobuf | >= 4.28.0 < 4.28.2 | 4.28.2 | |
| protobuf-java | < 4.27.5 | 4.27.5 | |
| protobuf-java | < 4.28.2 | 4.28.2 | |
| protobuf-java | < 3.25.5 | 3.25.5 | |
| protobuf-java | >= 4.0.0 < 4.27.5 | 4.27.5 | |
| protobuf-java | >= 4.28.0 < 4.28.2 | 4.28.2 | |
| protobuf-javalite | < 4.27.5 | 4.27.5 | |
| protobuf-javalite | < 4.28.2 | 4.28.2 | |
| protobuf-javalite | < 3.25.5 | 3.25.5 | |
| protobuf-javalite | >= 4.0.0 < 4.27.5 | 4.27.5 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
ghsa8.7HIGH
osv8.7HIGH
vendor_debian8.7HIGH
vendor_redhat8.7HIGH
vendor_oracle7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Communications Applications Risk Matrix: Installation (Google Protobuf-Java) — CVE-2024-7254
vendor_oracle·2025-10-15·CVSS 7.5
CVE-2024-7254 [HIGH] Oracle Oracle Communications Applications Risk Matrix: Installation (Google Protobuf-Java) — CVE-2024-7254
Oracle Oracle Communications Applications Risk Matrix: Installation (Google Protobuf-Java) vulnerability
CVE: CVE-2024-7254
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2025 (OCT 2025)
Ubuntu
Protocol Buffers vulnerabilities
vendor_ubuntu·2025-09-02·CVSS 7.5
CVE-2024-7254 [HIGH] Protocol Buffers vulnerabilities
Title: Protocol Buffers vulnerabilities
Summary: Protocol Buffers could be made to crash if it received specially crafted
input.
USN-7435-1 and USN-7629-1 fixed vulnerabilities in Protocol Buffers
for several releases of Ubuntu. This update provides the corresponding
fixes for Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS.
Original advisory details:
It was discovered that Protocol Buffers incorrectly handled memory when
receiving malicious input using the Python bindings. An attacker could
possibly use this issue to cause a denial of service. (CVE-2025-4565)
It was discovered that Protocol Buffers incorrectly handled memory when
receiving malicious input using the Java bindings. An attacker could
possibly use this issue to cause a denial of service. This issue only
affected
Oracle
Oracle Oracle Communications Risk Matrix: Automated Test Suite (Google Protobuf-Java) — CVE-2024-7254
vendor_oracle·2025-07-15·CVSS 7.5
CVE-2024-7254 [HIGH] Oracle Oracle Communications Risk Matrix: Automated Test Suite (Google Protobuf-Java) — CVE-2024-7254
Oracle Oracle Communications Risk Matrix: Automated Test Suite (Google Protobuf-Java) vulnerability
CVE: CVE-2024-7254
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2025 (JUL 2025)
Ubuntu
Protocol Buffers vulnerabilities
vendor_ubuntu·2025-07-09·CVSS 7.5
CVE-2024-7254 [HIGH] Protocol Buffers vulnerabilities
Title: Protocol Buffers vulnerabilities
Summary: Protocol Buffers could be made to crash if it received specially crafted
input.
It was discovered that Protocol Buffers incorrectly handled memory when
receiving malicious input using the Python bindings. An attacker could
possibly use this issue to cause a denial of service. (CVE-2025-4565)
It was discovered that Protocol Buffers incorrectly handled memory when
receiving malicious input using the Java bindings. An attacker could
possibly use this issue to cause a denial of service. This issue only
affected Ubuntu 25.04. (CVE-2024-7254)
Instructions: In general, a standard system update will make all the necessary changes.
Oracle
Oracle Oracle Communications Applications Risk Matrix: Security (Google Protobuf-Java) — CVE-2024-7254
vendor_oracle·2025-04-15·CVSS 7.5
CVE-2024-7254 [HIGH] Oracle Oracle Communications Applications Risk Matrix: Security (Google Protobuf-Java) — CVE-2024-7254
Oracle Oracle Communications Applications Risk Matrix: Security (Google Protobuf-Java) vulnerability
CVE: CVE-2024-7254
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2025 (APR 2025)
Ubuntu
Protocol Buffers vulnerability
vendor_ubuntu·2025-04-14
CVE-2024-7254 Protocol Buffers vulnerability
Title: Protocol Buffers vulnerability
Summary: Protocol Buffers could be made to crash if it received specially crafted
input.
It was discovered that Protocol Buffers incorrectly handled memory when
receiving malicious input using the Java bindings. An attacker could
possibly use this issue to cause a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Oracle
Oracle Oracle Communications Applications Risk Matrix: Solution Designer (Google Protobuf-Java) — CVE-2024-7254
vendor_oracle·2025-01-15·CVSS 7.5
CVE-2024-7254 [HIGH] Oracle Oracle Communications Applications Risk Matrix: Solution Designer (Google Protobuf-Java) — CVE-2024-7254
Oracle Oracle Communications Applications Risk Matrix: Solution Designer (Google Protobuf-Java) vulnerability
CVE: CVE-2024-7254
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2025 (JAN 2025)
Oracle
Oracle Oracle Communications Risk Matrix: Signaling (Google Protobuf-Java) — CVE-2024-7254
vendor_oracle·2024-10-15·CVSS 7.5
CVE-2024-7254 [HIGH] Oracle Oracle Communications Risk Matrix: Signaling (Google Protobuf-Java) — CVE-2024-7254
Oracle Oracle Communications Risk Matrix: Signaling (Google Protobuf-Java) vulnerability
CVE: CVE-2024-7254
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2024 (OCT 2024)
Red Hat
protobuf: StackOverflow vulnerability in Protocol Buffers
vendor_redhat·2024-09-19·CVSS 8.7
CVE-2024-7254 [HIGH] CWE-770 protobuf: StackOverflow vulnerability in Protocol Buffers
protobuf: StackOverflow vulnerability in Protocol Buffers
Any project that parses untrusted Protocol Buffers data containing an arbitrary number of nested groups / series of SGROUP tags can corrupted by exceeding the stack limit i.e. StackOverflow. Parsing nested groups as unknown fields with DiscardUnknownFieldsParser or Java Protobuf Lite parser, or against Protobuf map fields, creates unbounded recursions that can be abused by an attacker.
A flaw was found in Protocol Buffers (protobuf). This issue can allows an attacker to cause a StackOverflow via parsing untrusted Protocol Buffers data containing arbitrarily nested SGROUP tags, leading to unbounded recursion.
Statement: This issue represents a significant severity risk because unbounded recursion in Protocol Buffers parsing can be
Debian
CVE-2024-7254: protobuf - Any project that parses untrusted Protocol Buffers data containing an arbitrary ...
vendor_debian·2024·CVSS 8.7
CVE-2024-7254 [HIGH] CVE-2024-7254: protobuf - Any project that parses untrusted Protocol Buffers data containing an arbitrary ...
Any project that parses untrusted Protocol Buffers data containing an arbitrary number of nested groups / series of SGROUP tags can corrupted by exceeding the stack limit i.e. StackOverflow. Parsing nested groups as unknown fields with DiscardUnknownFieldsParser or Java Protobuf Lite parser, or against Protobuf map fields, creates unbounded recursions that can be abused by an attacker.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 3.21.12-12)
sid: resolved (fixed in 3.21.12-12)
trixie: open
OSV
protobuf vulnerabilities
osv·2025-09-02·CVSS 8.7
CVE-2025-4565 [HIGH] protobuf vulnerabilities
protobuf vulnerabilities
USN-7435-1 and USN-7629-1 fixed vulnerabilities in Protocol Buffers
for several releases of Ubuntu. This update provides the corresponding
fixes for Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS.
Original advisory details:
It was discovered that Protocol Buffers incorrectly handled memory when
receiving malicious input using the Python bindings. An attacker could
possibly use this issue to cause a denial of service. (CVE-2025-4565)
It was discovered that Protocol Buffers incorrectly handled memory when
receiving malicious input using the Java bindings. An attacker could
possibly use this issue to cause a denial of service. This issue only
affected Ubuntu 25.04. (CVE-2024-7254)
OSV
protobuf vulnerabilities
osv·2025-07-09·CVSS 8.7
CVE-2025-4565 [HIGH] protobuf vulnerabilities
protobuf vulnerabilities
It was discovered that Protocol Buffers incorrectly handled memory when
receiving malicious input using the Python bindings. An attacker could
possibly use this issue to cause a denial of service. (CVE-2025-4565)
It was discovered that Protocol Buffers incorrectly handled memory when
receiving malicious input using the Java bindings. An attacker could
possibly use this issue to cause a denial of service. This issue only
affected Ubuntu 25.04. (CVE-2024-7254)
GHSA
protobuf-java has potential Denial of Service issue
ghsa·2024-09-19·CVSS 8.7
CVE-2024-7254 [HIGH] CWE-20 protobuf-java has potential Denial of Service issue
protobuf-java has potential Denial of Service issue
### Summary
When parsing unknown fields in the Protobuf Java Lite and Full library, a maliciously crafted message can cause a StackOverflow error and lead to a program crash.
Reporter: Alexis Challande, Trail of Bits Ecosystem Security Team
Affected versions: This issue affects all versions of both the Java full and lite Protobuf runtimes, as well as Protobuf for Kotlin and JRuby, which themselves use the Java Protobuf runtime.
### Severity
[CVE-2024-7254](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-7254) **High** CVSS4.0 Score 8.7 (NOTE: there may be a delay in publication)
This is a potential Denial of Service. Parsing nested groups as unknown fields with DiscardUnknownFieldsParser or Java Protobuf Lite parser, or agains
OSV
protobuf-java has potential Denial of Service issue
osv·2024-09-19·CVSS 8.7
CVE-2024-7254 [HIGH] protobuf-java has potential Denial of Service issue
protobuf-java has potential Denial of Service issue
### Summary
When parsing unknown fields in the Protobuf Java Lite and Full library, a maliciously crafted message can cause a StackOverflow error and lead to a program crash.
Reporter: Alexis Challande, Trail of Bits Ecosystem Security Team
Affected versions: This issue affects all versions of both the Java full and lite Protobuf runtimes, as well as Protobuf for Kotlin and JRuby, which themselves use the Java Protobuf runtime.
### Severity
[CVE-2024-7254](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-7254) **High** CVSS4.0 Score 8.7 (NOTE: there may be a delay in publication)
This is a potential Denial of Service. Parsing nested groups as unknown fields with DiscardUnknownFieldsParser or Java Protobuf Lite parser, or agains
OSV
CVE-2024-7254: Any project that parses untrusted Protocol Buffers data containing an arbitrary number of nested groups / series of SGROUP tags can corrupted by excee
osv·2024-09-19·CVSS 8.7
CVE-2024-7254 [HIGH] CVE-2024-7254: Any project that parses untrusted Protocol Buffers data containing an arbitrary number of nested groups / series of SGROUP tags can corrupted by excee
Any project that parses untrusted Protocol Buffers data containing an arbitrary number of nested groups / series of SGROUP tags can corrupted by exceeding the stack limit i.e. StackOverflow. Parsing nested groups as unknown fields with DiscardUnknownFieldsParser or Java Protobuf Lite parser, or against Protobuf map fields, creates unbounded recursions that can be abused by an attacker.
No detection rules found.
No public exploits indexed.
Trailofbits
Don’t recurse on untrusted input
blogs_trailofbits·2025-02-21·CVSS 7.5
[HIGH] Don’t recurse on untrusted input
A single malicious request can take down web applications that use recursive functions to process untrusted user input. We developed a simple CodeQL query to assist in finding stack overflows and used it to find denial-of-service (DoS) vulnerabilities in several high-profile Java projects. All of these projects are maintained by security-conscious organizations with robust development practices:
- ElasticSearch (in PatternBank, parseGeometryCollection)
- OpenSearch (in FilterPath, parseGeometryCollection, and validatePatternBank)
- Protocol Buffers CVE-2024-7254
- Guava Function rewrite
- XStream CVE-2024-47072
Our findings indicate that recursion, while a powerful programming tool, becomes a severe liability when used to process untrusted data in applications with availability requireme
Trailofbits
Don’t recurse on untrusted input
blogs_trailofbits·2025-02-21·CVSS 7.5
[HIGH] Don’t recurse on untrusted input
A single malicious request can take down web applications that use recursive functions to process untrusted user input. We developed a simple CodeQL query to assist in finding stack overflows and used it to find denial-of-service (DoS) vulnerabilities in several high-profile Java projects. All of these projects are maintained by security-conscious organizations with robust development practices:
ElasticSearch (in PatternBank , parseGeometryCollection )
OpenSearch (in FilterPath , parseGeometryCollection , and validatePatternBank )
Protocol Buffers CVE-2024-7254
Guava Function rewrite
XStream CVE-2024-47072
Our findings indicate that recursion, while a powerful programming tool, becomes a severe liability when used to process untrusted data in applications with availability requiremen
Bugzilla
CVE-2024-7254 protobuf: StackOverflow vulnerability in Protocol Buffers
bugzilla·2024-09-19·CVSS 8.7
CVE-2024-7254 [HIGH] CVE-2024-7254 protobuf: StackOverflow vulnerability in Protocol Buffers
CVE-2024-7254 protobuf: StackOverflow vulnerability in Protocol Buffers
Any project that parses untrusted Protocol Buffers data containing an arbitrary number of nested groups / series of SGROUP tags can corrupted by exceeding the stack limit i.e. StackOverflow. Parsing nested groups as unknown fields with DiscardUnknownFieldsParser or Java Protobuf Lite parser, or against Protobuf map fields, creates unbounded recursions that can be abused by an attacker.
Discussion:
This issue has been addressed in the following products:
Red Hat build of Apache Camel for Quarkus 2.13
Via RHSA-2024:7972 https://access.redhat.com/errata/RHSA-2024:7972
---
This issue has been addressed in the following products:
Streams for Apache Kafka 2.8.0
Via RHSA-2024:9571 https://access.redhat.com/errata/RHS
2024-09-19
Published