CVE 7.1 HIGH

Denial of Service (DoS) vulnerability exists in the Protobuf PHP library during the parsing of untrusted input_CVE-2026-6409

7.1 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Description

A Denial of Service (DoS) vulnerability exists in the Protobuf PHP library during the parsing of untrusted input. Maliciously structured messages—specifically those containing negative varints or deep recursion—can be used to crash the application, impacting service availability.

Basic Information

ID CVE-2026-6409
Source Google
Published Apr 16, 2026 at 14:30

Affected Product

Vendor Protocol Buffers
Product Protobuf-php (Pecl)
Affected Versions Protocol Buffers Protobuf-php (Pecl) 0
Protocol Buffers Protobuf-php (Pecl) 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.