CVE-2026-6409
published 2026-04-16CVE-2026-6409: A Denial of Service (DoS) vulnerability exists in the Protobuf PHP library during the parsing of untrusted input. Maliciously structured messages—specifically…
PriorityP431high7.1CVSS 4.0
AVNACLATNPRNUIPVCNVINVAHSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.36%
28.1th percentile
A Denial of Service (DoS) vulnerability exists in the Protobuf PHP library during the parsing of untrusted input. Maliciously structured messages—specifically those containing negative varints or deep recursion—can be used to crash the application, impacting service availability.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| protobuf | >= 0 < 4.33.6 | 4.33.6 | |
| protocol_buffers | protobuf-php | < 5.34.0-RC1 | 5.34.0-RC1 |
| protocol_buffers | protobuf-php | < 4.33.6 | 4.33.6 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Protocol Buffers Protobuf-php up to 4.33.5/5.33.x Structured Message denial of service (GHSA-p2gh-cfq4-4wjc / EUVD-2026-23268)
vuldb·2026-04-16·CVSS 7.1
CVE-2026-6409 [HIGH] Protocol Buffers Protobuf-php up to 4.33.5/5.33.x Structured Message denial of service (GHSA-p2gh-cfq4-4wjc / EUVD-2026-23268)
A vulnerability was found in Protocol Buffers Protobuf-php up to 4.33.5/5.33.x and classified as problematic. Affected is an unknown function of the component Structured Message Handler. Executing a manipulation can lead to denial of service.
This vulnerability appears as CVE-2026-6409. The attack may be performed from remote. There is no available exploit.
It is suggested to upgrade the affected component.
GHSA
Protobuf: Denial of Service issue through malicious messages containing negative varints or deep recursion
ghsa·2026-03-25
CVE-2026-6409 [HIGH] CWE-400 Protobuf: Denial of Service issue through malicious messages containing negative varints or deep recursion
Protobuf: Denial of Service issue through malicious messages containing negative varints or deep recursion
### Impact
A Denial of Service (DoS) vulnerability exists in the Protobuf PHP library during the parsing of untrusted input. Maliciously structured messages—specifically those containing negative `varint`s or deep recursion—can be used to crash the application, impacting service availability.
### Patches
Patches have been released to 5.34.0-RC1 and 4.33.6.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-13311 goose: shell-quote: Denial of Service due to inefficient input parsing [fedora-all]
bugzilla·2026-06-25·CVSS 7.5
CVE-2026-13311 [HIGH] CVE-2026-13311 goose: shell-quote: Denial of Service due to inefficient input parsing [fedora-all]
CVE-2026-13311 goose: shell-quote: Denial of Service due to inefficient input parsing [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
Goose is not affected by this CVE, as it targets only the UI/docs portion, and we are not shipping any of the GUI pieces yet.
```
rolivier@rdtx ~/W/goose ((v1.36.0))> rg shell-quote
ui/pnpm-lock.yaml
162: shell-quote:
280: '@types/shell-quote':
3026: '@types/[email protected]':
6409: [email protected]:
10115: '@types/[email protected]': {}
14255: [email protected]: {}
ui/desktop/package.json
96: "shell-quote": "^1.8.3",
137: "@types/shell-quote": "^1.7.5",
Bugzilla
CVE-2026-13311 goose: shell-quote: Denial of Service due to inefficient input parsing [epel-all]
bugzilla·2026-06-25·CVSS 7.5
CVE-2026-13311 [HIGH] CVE-2026-13311 goose: shell-quote: Denial of Service due to inefficient input parsing [epel-all]
CVE-2026-13311 goose: shell-quote: Denial of Service due to inefficient input parsing [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
Goose is not affected by this CVE, as it targets only the UI/docs portion, and we are not shipping any of the GUI pieces yet.
```
rolivier@rdtx ~/W/goose ((v1.36.0))> rg shell-quote
ui/pnpm-lock.yaml
162: shell-quote:
280: '@types/shell-quote':
3026: '@types/[email protected]':
6409: [email protected]:
10115: '@types/[email protected]': {}
14255: [email protected]: {}
ui/desktop/package.json
96: "shell-quote": "^1.8.3",
137: "@types/shell-quote": "^1.7.5",
2026-04-16
Published