{"id":"GHSA-p2gh-cfq4-4wjc","summary":"Protobuf: Denial of Service issue through malicious messages containing negative varints or deep recursion","details":"### Impact\nA Denial of Service (DoS) vulnerability exists in the Protobuf PHP library during the parsing of untrusted input. Maliciously structured messages—specifically those containing negative `varint`s or deep recursion—can be used to crash the application, impacting service availability.\n\n### Patches\nPatches have been released to 5.34.0-RC1 and 4.33.6.","aliases":["CVE-2026-6409"],"modified":"2026-04-16T23:26:24.868199Z","published":"2026-03-25T21:02:08Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-03-25T21:02:08Z","nvd_published_at":null,"cwe_ids":["CWE-400"]},"references":[{"type":"WEB","url":"https://github.com/protocolbuffers/protobuf/security/advisories/GHSA-p2gh-cfq4-4wjc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-6409"},{"type":"WEB","url":"https://github.com/protocolbuffers/protobuf/issues/24159"},{"type":"WEB","url":"https://github.com/protocolbuffers/protobuf/issues/25067"},{"type":"WEB","url":"https://github.com/protocolbuffers/protobuf/commit/60e93d2d104f2af9cd345b1c6f3891d91430244a"},{"type":"WEB","url":"https://github.com/protocolbuffers/protobuf/commit/c8e9b27d95c6ab2d0668b5889e7dac2c477b7038"},{"type":"PACKAGE","url":"https://github.com/protocolbuffers/protobuf"}],"affected":[{"package":{"name":"google/protobuf","ecosystem":"Packagist","purl":"pkg:composer/google/protobuf"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.33.6"}]}],"versions":["v3.1.0-alpha-1","v3.10.0","v3.10.0RC1","v3.11.0","v3.11.0RC1","v3.11.0RC2","v3.11.1","v3.11.2","v3.11.3","v3.11.4","v3.12.0","v3.12.0RC1","v3.12.0RC2","v3.12.1","v3.12.2","v3.12.4","v3.13.0","v3.13.0.1","v3.13.0RC3","v3.14.0","v3.14.0RC1","v3.14.0RC2","v3.14.0RC3","v3.15.0","v3.15.0RC1","v3.15.0RC2","v3.15.1","v3.15.2","v3.15.3","v3.15.4","v3.15.5","v3.15.6","v3.15.7","v3.15.8","v3.16.0","v3.16.0RC1","v3.16.0RC2","v3.17.0","v3.17.0RC1","v3.17.0RC2","v3.17.1","v3.17.2","v3.17.3","v3.18.0","v3.18.0RC1","v3.18.0RC2","v3.18.1","v3.18.2","v3.18.3","v3.19.0","v3.19.0RC1","v3.19.0RC2","v3.19.1","v3.19.2","v3.19.3","v3.19.4","v3.19.5","v3.19.6","v3.2.0-alpha-1","v3.20.0RC1","v3.20.0RC2","v3.20.1","v3.20.1RC1","v3.20.2","v3.20.3","v3.21.0","v3.21.0RC1","v3.21.0RC2","v3.21.1","v3.21.10","v3.21.11","v3.21.12","v3.21.2","v3.21.3","v3.21.4","v3.21.5","v3.21.6","v3.21.7","v3.21.8","v3.21.9","v3.22.0","v3.22.0RC3","v3.22.1","v3.22.2","v3.22.3","v3.22.4","v3.22.5","v3.23.0","v3.23.0RC1","v3.23.0RC2","v3.23.0RC3","v3.23.1","v3.23.2","v3.23.3","v3.23.4","v3.24.0","v3.24.0RC1","v3.24.0RC2","v3.24.0RC3","v3.24.1","v3.24.2","v3.24.3","v3.24.4","v3.25.0","v3.25.0RC1","v3.25.0RC2","v3.25.1","v3.25.2","v3.25.3","v3.25.4","v3.25.5","v3.25.6","v3.25.7","v3.25.8","v3.25.9","v3.3.0","v3.3.0rc1","v3.3.1","v3.3.2","v3.4.0","v3.4.0rc1","v3.4.0rc2","v3.4.0rc3","v3.4.1","v3.5.0","v3.5.0.1","v3.5.1","v3.5.1.1","v3.5.2","v3.6.0","v3.6.0.1","v3.6.0rc1","v3.6.0rc2","v3.6.1","v3.6.1.1","v3.6.1.2","v3.6.1.3","v3.7.0","v3.7.0-rc.3","v3.7.0rc1","v3.7.0rc2","v3.7.1","v3.8.0","v3.8.0RC1","v3.9.0","v3.9.0RC1","v3.9.1","v3.9.2","v4.0.0RC1","v4.0.0RC2","v4.26.0","v4.26.0RC1","v4.26.0RC2","v4.26.0RC3","v4.26.1","v4.27.0","v4.27.0RC1","v4.27.0RC2","v4.27.0RC3","v4.27.1","v4.27.2","v4.27.3","v4.27.4","v4.27.5","v4.28.0","v4.28.0RC1","v4.28.0RC2","v4.28.0RC3","v4.28.1","v4.28.2","v4.28.3","v4.29.0","v4.29.0RC1","v4.29.0RC2","v4.29.0RC3","v4.29.1","v4.29.2","v4.29.3","v4.29.4","v4.29.5","v4.29.6","v4.30.0","v4.30.0RC1","v4.30.0RC2","v4.30.1","v4.30.2","v4.31.0","v4.31.0RC1","v4.31.0RC2","v4.31.1","v4.32.0","v4.32.0RC1","v4.32.0RC2","v4.32.1","v4.33.0","v4.33.0RC1","v4.33.0RC2","v4.33.1","v4.33.2","v4.33.3","v4.33.4","v4.33.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-p2gh-cfq4-4wjc/GHSA-p2gh-cfq4-4wjc.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}