Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-22569

21
FAUCET Score

CVE-2021-22569 is a medium-severity vulnerability affecting Google and Oracle products utilizing protobuf-java, where a malicious payload can cause a denial of service by forcing the parser to process interleaved UnknownFieldSet fields out of order, leading to frequent pauses. The attack requires local access and user interaction, but can result in high availability impact. There is no public exploit code available, nor is it known to be actively exploited, and it has received minimal community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
< 3.19.2CPE matchmatch criteria
cpe:2.3:a:google:google-protobuf:*:*:*:*:*:ruby:*:*
< 3.16.1CPE matchmatch criteria
cpe:2.3:a:google:protobuf-java:*:*:*:*:*:*:*:*
>= 3.18.0, < 3.18.2CPE matchmatch criteria
cpe:2.3:a:google:protobuf-java:*:*:*:*:*:*:*:*
>= 3.19.0, < 3.19.2CPE matchmatch criteria
cpe:2.3:a:google:protobuf-java:*:*:*:*:*:*:*:*
< 3.18.2CPE matchmatch criteria
cpe:2.3:a:google:protobuf-kotlin:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.65%
Probability of exploitation in next 30 days
EPSS Percentile
74.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0165 is in the 85th percentile among its peer group of 5,760 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (35)

boschpatch availablevia llm_extracted
Fixed in: protobuf-java (3.16.1, 3.18.2, 3.19.2), protobuf-kotlin (3.18.2, 3.19.2), google-protobuf [JRuby gem] (3.19.2)
View patch
mavenpatch availablevia ghsa
Product: com.google.protobuf:protobuf-javaFixed in: 3.19.2
mavenpatch availablevia ghsa
Product: com.google.protobuf:protobuf-kotlinFixed in: 3.18.2
mavenpatch availablevia ghsa
Product: com.google.protobuf:protobuf-kotlinFixed in: 3.19.2
mavenpatch availablevia ghsa
Product: com.google.protobuf:protobuf-javaFixed in: 3.16.1
mavenpatch availablevia ghsa
Product: com.google.protobuf:protobuf-javaFixed in: 3.18.2
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 ARMFixed in: 2.16.2-2
microsoftpatch availablevia msrc
Product: azl3 pytorch 2.2.2-5 on Azure Linux 3.0Fixed in: 2.2.2-5
microsoftpatch availablevia msrc
Product: azl3 python-tensorboard 2.11.0-3 on Azure Linux 3.0Fixed in: 2.16.2-2
microsoftpatch availablevia msrc
Product: azl3 python-tensorboard 2.16.2-2 on Azure Linux 3.0Fixed in: 2.16.2-2
microsoftpatch availablevia msrc
Product: 19696-17084Fixed in: 2.16.2-2
microsoftpatch availablevia msrc
Product: azl3 pytorch 2.2.2-7 on Azure Linux 3.0Fixed in: 2.2.2-5
microsoftpatch availablevia msrc
Product: 17021-17084Fixed in: 2.16.2-2
microsoftpatch availablevia msrc
Product: 17466-17084Fixed in: 2.2.2-5
microsoftpatch availablevia msrc
Product: 19407-17084Fixed in: 2.2.2-5
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 x64Fixed in: 2.16.2-2
mongodbpatch availablevia llm_extracted
Fixed in: 3.19.2
View patch
oraclepatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: RHINT Service Registry 2.3.0 GAFixed in: protobuf-java
View patch
redhatpatch availablevia redhat_api
Product: Text-Only RHOARFixed in: protobuf-java
View patch
redhatpatch availablevia redhat_api
Product: RHPAM 7.13.0 asyncFixed in: protobuf-java
View patch
redhatpatch availablevia redhat_api
Product: Red Hat build of Quarkus 2.7.5Fixed in: protobuf-java
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Fuse 7.11Fixed in: protobuf-java
View patch
redhatpatch availablevia redhat_api
Product: RHINT Camel-Q 2.2.1
View patch
redhatpatch availablevia redhat_api
Product: RHINT Debezium 1.9.7Fixed in: protobuf-java
View patch
rubygemspatch availablevia ghsa
Product: google-protobufFixed in: 3.19.2
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift4/ose-metering-hadoop
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift4/ose-metering-presto
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift4/ose-metering-hive
redhatno patchvia redhat_api
Product: Red Hat Integration Service RegistryFixed in: protobuf-java
redhatno patchvia redhat_api
Product: Red Hat Integration Camel K 1Fixed in: protobuf-java
redhatno patchvia redhat_api
Product: Red Hat build of Debezium 1Fixed in: protobuf-java
redhatend of lifevia redhat_api
Product: Logging Subsystem for Red Hat OpenShiftFixed in: openshift-logging/elasticsearch6-rhel8
redhatend of lifevia redhat_api
Product: Red Hat Satellite 6Fixed in: candlepin
redhatend of lifevia redhat_api
Product: Red Hat Integration Camel Quarkus 1Fixed in: protobuf-java

Vendor Advisories (6)

microsoft2024-Sep/CVE-2021-22569

CVE-2021-22569

Sep 10, 2024
microsoft2022-Jan/CVE-2021-22569Moderate

Denial of Service of protobuf-java parsing procedure

Jan 11, 2022
mavenGHSA-wrvw-hg22-4m67high

A potential Denial of Service issue in protobuf-java

Jan 7, 2022
redhatCVE-2021-22569Moderate

protobuf-java: potential DoS in the parsing procedure for binary data

Jan 6, 2022
boschllm-bosch-9323ce73214e8e99HIGH

Denial of Service in protobuf-java (CVE-2021-22569)

mongodbllm-mongodb-c682a54daa478807HIGH

Denial of Service in protobuf-java (CVE-2021-22569)

References

bugs.chromium.org / p/oss-fuzz/issues/detail
ExploitIssue TrackingMailing ListVendor Advisory
cloud.google.com / support/bulletins
Vendor Advisory
lists.debian.org / debian-lts-announce/2023/04/msg00019.html
oracle.com / security-alerts/cpuapr2022.html
PatchThird Party Advisory
openwall.com / lists/oss-security/2022/01/12/4
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2022/01/12/7
Mailing ListThird Party Advisory