cbcvebase.
CVE-2026-6409
published 2026-04-16

CVE-2026-6409: A Denial of Service (DoS) vulnerability exists in the Protobuf PHP library during the parsing of untrusted input. Maliciously structured messages—specifically…

PriorityP431high7.1CVSS 4.0
AVNACLATNPRNUIPVCNVINVAHSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.36%
28.1th percentile
A Denial of Service (DoS) vulnerability exists in the Protobuf PHP library during the parsing of untrusted input. Maliciously structured messages—specifically those containing negative varints or deep recursion—can be used to crash the application, impacting service availability.

Affected

3 ranges
VendorProductVersion rangeFixed in
googleprotobuf>= 0 < 4.33.64.33.6
protocol_buffersprotobuf-php< 5.34.0-RC15.34.0-RC1
protocol_buffersprotobuf-php< 4.33.64.33.6
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.