Skip to content
This repository was archived by the owner on Apr 18, 2026. It is now read-only.
This repository was archived by the owner on Apr 18, 2026. It is now read-only.

Security vulnerabilities in protobuf dependency #50

@dlazerka

Description

@dlazerka

The issues doesn't seem to impact this library, as it only concerns parsing user-provided content as a protobuf, while here it only parses google-provided content. But nevertheless, automated code scanning tools don't know about that and generate warnings that this library is vulnerable.

Proposed solution: update protobuf version to the latest.

  • CVE-2021-22569 5.5 Incorrect Behavior Order vulnerability pending CVSS allocation
  • CVE-2022-3171 7.5 Uncontrolled Resource Consumption vulnerability with medium severity found

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions