{"schema_version":"1.9.0","id":"GHSA-wrvw-hg22-4m67","published":"2022-01-07T22:31:44Z","modified":"2026-09-10T03:49:12.224093549Z","aliases":["CVE-2021-22569"],"summary":"A potential Denial of Service issue in protobuf-java","details":"## Summary\n\nA potential Denial of Service issue in protobuf-java was discovered in the parsing procedure for binary data.\n\nReporter: [OSS-Fuzz](https://github.com/google/oss-fuzz)\n\nAffected versions: All versions of Java Protobufs (including Kotlin and JRuby) prior to the versions listed below. Protobuf \"javalite\" users (typically Android) are not affected.\n\n## Severity\n\n[CVE-2021-22569](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22569) **High** - CVSS Score: 7.5,  An implementation weakness in how unknown fields are parsed in Java. A small (~800 KB) malicious payload can occupy the parser for several minutes by creating large numbers of short-lived objects that cause frequent, repeated GC pauses.\n\n## Proof of Concept\n\nFor reproduction details, please refer to the oss-fuzz issue that identifies the specific inputs that exercise this parsing weakness.\n\n## Remediation and Mitigation\n\nPlease update to the latest available versions of the following packages:\n\n- protobuf-java (3.16.1, 3.18.2, 3.19.2) \n- protobuf-kotlin (3.18.2, 3.19.2)\n- google-protobuf [JRuby  gem only] (3.19.2) \n","affected":[{"package":{"name":"com.google.protobuf:protobuf-java","ecosystem":"Maven","purl":"pkg:maven/com.google.protobuf/protobuf-java"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.16.1"}]}],"versions":["2.0.1","2.0.3","2.1.0","2.2.0","2.3.0","2.4.0a","2.4.1","2.5.0","2.6.0","2.6.1","3.0.0","3.0.0-alpha-2","3.0.0-alpha-3","3.0.0-alpha-3.1","3.0.0-beta-1","3.0.0-beta-2","3.0.0-beta-3","3.0.0-beta-4","3.0.2","3.1.0","3.10.0","3.10.0-rc-1","3.11.0","3.11.0-rc-1","3.11.0-rc-2","3.11.1","3.11.3","3.11.4","3.12.0","3.12.0-rc-1","3.12.0-rc-2","3.12.1","3.12.2","3.12.4","3.13.0","3.13.0-rc-3","3.14.0","3.14.0-rc-1","3.14.0-rc-2","3.14.0-rc-3","3.15.0","3.15.0-rc-1","3.15.0-rc-2","3.15.1","3.15.2","3.15.3","3.15.4","3.15.5","3.15.6","3.15.7","3.15.8","3.16.0","3.16.0-rc-1","3.16.0-rc-2","3.2.0","3.2.0-rc.1","3.2.0rc2","3.3.0","3.3.1","3.4.0","3.5.0","3.5.1","3.6.0","3.6.1","3.7.0","3.7.0-rc1","3.7.1","3.8.0","3.8.0-rc-1","3.9.0","3.9.0-rc-1","3.9.1","3.9.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-wrvw-hg22-4m67/GHSA-wrvw-hg22-4m67.json"}},{"package":{"name":"google-protobuf","ecosystem":"RubyGems","purl":"pkg:gem/google-protobuf"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.19.2"}]}],"versions":["3.0.0","3.0.0.alpha.1.0","3.0.0.alpha.1.1","3.0.0.alpha.2.0","3.0.0.alpha.3","3.0.0.alpha.3.1.pre","3.0.0.alpha.4.0","3.0.0.alpha.5.0.3","3.0.0.alpha.5.0.4","3.0.0.alpha.5.0.5","3.0.0.alpha.5.0.5.1","3.0.2","3.1.0","3.1.0.0.pre","3.10.0.rc.1","3.10.1","3.11.0","3.11.0.rc.1","3.11.0.rc.2","3.11.1","3.11.2","3.11.3","3.11.4","3.12.0","3.12.0.rc.1","3.12.0.rc.2","3.12.1","3.12.2","3.12.4","3.13.0","3.13.0.rc.3","3.14.0","3.14.0.rc.1","3.14.0.rc.2","3.14.0.rc.3","3.15.0","3.15.0.rc.1","3.15.0.rc.2","3.15.1","3.15.2","3.15.3","3.15.4","3.15.5","3.15.6","3.15.7","3.15.8","3.16.0","3.16.0.rc.1","3.16.0.rc.2","3.17.0","3.17.0.rc.1","3.17.0.rc.2","3.17.1","3.17.2","3.17.3","3.18.0","3.18.0.rc.1","3.18.0.rc.2","3.18.1","3.18.2","3.18.3","3.19.0","3.19.0.rc.1","3.19.0.rc.2","3.19.1","3.2.0","3.2.0.1","3.2.0.2","3.2.1.pre","3.3.0","3.4.0.1","3.4.0.2","3.4.1.1","3.5.0","3.5.0.pre","3.5.1","3.5.1.1","3.5.1.2","3.6.0","3.6.1","3.7.0","3.7.0.rc.2","3.7.0.rc.3","3.7.1","3.8.0","3.8.0.rc.1","3.9.0","3.9.0.rc.1","3.9.1","3.9.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-wrvw-hg22-4m67/GHSA-wrvw-hg22-4m67.json"}},{"package":{"name":"com.google.protobuf:protobuf-java","ecosystem":"Maven","purl":"pkg:maven/com.google.protobuf/protobuf-java"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.18.0"},{"fixed":"3.18.2"}]}],"versions":["3.18.0","3.18.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-wrvw-hg22-4m67/GHSA-wrvw-hg22-4m67.json"}},{"package":{"name":"com.google.protobuf:protobuf-java","ecosystem":"Maven","purl":"pkg:maven/com.google.protobuf/protobuf-java"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.19.0"},{"fixed":"3.19.2"}]}],"versions":["3.19.0","3.19.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-wrvw-hg22-4m67/GHSA-wrvw-hg22-4m67.json"}},{"package":{"name":"com.google.protobuf:protobuf-kotlin","ecosystem":"Maven","purl":"pkg:maven/com.google.protobuf/protobuf-kotlin"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.18.0"},{"fixed":"3.18.2"}]}],"versions":["3.18.0","3.18.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-wrvw-hg22-4m67/GHSA-wrvw-hg22-4m67.json"}},{"package":{"name":"com.google.protobuf:protobuf-kotlin","ecosystem":"Maven","purl":"pkg:maven/com.google.protobuf/protobuf-kotlin"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.19.0"},{"fixed":"3.19.2"}]}],"versions":["3.19.0","3.19.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-wrvw-hg22-4m67/GHSA-wrvw-hg22-4m67.json"}}],"references":[{"type":"WEB","url":"https://github.com/protocolbuffers/protobuf/security/advisories/GHSA-wrvw-hg22-4m67"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-22569"},{"type":"WEB","url":"https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=39330"},{"type":"WEB","url":"https://cloud.google.com/support/bulletins#gcp-2022-001"},{"type":"PACKAGE","url":"https://github.com/protocolbuffers/protobuf"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpuapr2022.html"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2022/01/12/4"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2022/01/12/7"}],"database_specific":{"cwe_ids":["CWE-696"],"github_reviewed":true,"github_reviewed_at":"2022-01-07T22:23:14Z","nvd_published_at":"2022-01-10T14:10:00Z","severity":"HIGH"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}