CVE-2022-3510 is a denial-of-service vulnerability affecting protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6, and 3.16.3. This parsing issue, similar to CVE-2022-3171, occurs when inputs with multiple instances of non-repeated embedded messages containing repeated or unknown fields cause excessive object conversions, leading to long garbage collection pauses. With a CVSS score of 7.5 (High), this vulnerability can be exploited remotely with low attack complexity, resulting in a high impact on availability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.16.0, < 3.16.3CPE matchmatch criteria | cpe:2.3:a:google:protobuf-java:*:*:*:*:*:*:*:* | ||
>= 3.19.0, < 3.19.6CPE matchmatch criteria | cpe:2.3:a:google:protobuf-java:*:*:*:*:*:*:*:* | ||
>= 3.20.0, < 3.20.3CPE matchmatch criteria | cpe:2.3:a:google:protobuf-java:*:*:*:*:*:*:*:* | ||
>= 3.21.0, < 3.21.7CPE matchmatch criteria | cpe:2.3:a:google:protobuf-java:*:*:*:*:*:*:*:* | ||
>= 3.16.0, < 3.16.3CPE matchmatch criteria | cpe:2.3:a:google:protobuf-javalite:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Splunk User Behavior Analytics (UBA) Third-Party Package Updates
Jan 9, 2024protobuf-java: Message-Type Extensions parsing issue leads to DoS
Dec 15, 2022Protobuf Java vulnerable to Uncontrolled Resource Consumption
Dec 12, 2022Parsing issue in protobuf message-type extension
Nov 8, 2022