Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-p2gh-cfq4-4wjc | Protobuf: Denial of Service issue through malicious messages containing negative varints or deep recursion |
Thu, 16 Apr 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Protocol Buffers
Protocol Buffers protobuf-php |
|
| Vendors & Products |
Protocol Buffers
Protocol Buffers protobuf-php |
Thu, 16 Apr 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 16 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Denial of Service (DoS) vulnerability exists in the Protobuf PHP library during the parsing of untrusted input. Maliciously structured messages—specifically those containing negative varints or deep recursion—can be used to crash the application, impacting service availability. | |
| Title | Denial of Service (DoS) vulnerability exists in the Protobuf PHP library during the parsing of untrusted input | |
| Weaknesses | CWE-20 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Google
Published:
Updated: 2026-04-16T15:24:43.164Z
Reserved: 2026-04-15T21:56:37.963Z
Link: CVE-2026-6409
Updated: 2026-04-16T15:24:31.568Z
Status : Awaiting Analysis
Published: 2026-04-16T15:17:41.910
Modified: 2026-04-17T15:17:00.957
Link: CVE-2026-6409
No data.
OpenCVE Enrichment
Updated: 2026-04-17T03:30:08Z
Github GHSA