Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-7254

25
FAUCET Score

CVE-2024-7254 is a high-severity vulnerability affecting Google and NetApp products that utilize Protocol Buffers. It allows an unauthenticated attacker to trigger a denial-of-service condition (stack overflow) by providing specially crafted, deeply nested Protocol Buffers data. The vulnerability has a CVSS score of 7.5, indicating a high impact on availability with low attack complexity. While there are no known public exploits or Metasploit modules, the vulnerability has garnered significant community discussion and media coverage, suggesting awareness among researchers.

Impacted Technologies

VendorProductVersion(s)CPE
< 3.25.5CPE matchmatch criteria
cpe:2.3:a:google:protobuf:*:*:*:*:*:ruby:*:*
>= 4.0.0, < 4.27.5CPE matchmatch criteria
cpe:2.3:a:google:protobuf:*:*:*:*:*:ruby:*:*
>= 4.28.0, < 4.28.2CPE matchmatch criteria
cpe:2.3:a:google:protobuf:*:*:*:*:*:ruby:*:*
< 3.25.5CPE matchmatch criteria
cpe:2.3:a:google:protobuf-java:*:*:*:*:*:*:*:*
>= 4.0.0, < 4.27.5CPE matchmatch criteria
cpe:2.3:a:google:protobuf-java:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

8.7HIGH

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
NONE
VS Integrity
NONE
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
2.77%
Probability of exploitation in next 30 days
EPSS Percentile
84.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0277 is in the 73rd percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (49)

autodeskpatch availablevia llm_extracted
View patch
freepbxpatch availablevia llm_extracted
View patch
github_advisorypatch availablevia nvd_reference
View patch
honeywellpatch availablevia llm_extracted
View patch
mavenpatch availablevia ghsa
Product: com.google.protobuf:protobuf-kotlin-liteFixed in: 4.27.5
mavenpatch availablevia ghsa
Product: com.google.protobuf:protobuf-kotlin-liteFixed in: 4.28.2
mavenpatch availablevia ghsa
Product: com.google.protobuf:protobuf-kotlinFixed in: 4.27.5
mavenpatch availablevia ghsa
Product: com.google.protobuf:protobuf-kotlinFixed in: 4.28.2
mavenpatch availablevia ghsa
Product: com.google.protobuf:protobuf-javaliteFixed in: 4.27.5
mavenpatch availablevia ghsa
Product: com.google.protobuf:protobuf-javaliteFixed in: 4.28.2
mavenpatch availablevia ghsa
Product: com.google.protobuf:protobuf-javaFixed in: 4.27.5
mavenpatch availablevia ghsa
Product: com.google.protobuf:protobuf-javaFixed in: 3.25.5
mavenpatch availablevia ghsa
Product: com.google.protobuf:protobuf-javaFixed in: 4.28.2
mavenpatch availablevia ghsa
Product: com.google.protobuf:protobuf-javaliteFixed in: 3.25.5
mavenpatch availablevia ghsa
Product: com.google.protobuf:protobuf-kotlinFixed in: 3.25.5
mavenpatch availablevia ghsa
Product: com.google.protobuf:protobuf-kotlin-liteFixed in: 3.25.5
redhatpatch availablevia redhat_api
Product: Red Hat Trusted Profile Analyzer 1.2Fixed in: rhtpa/rhtpa-trustification-service-rhel9:sha256:8c6e51e26ca9a1d4d4fc9e90650103e60360cf0571533c56fbd08dac3007efbe
View patch
redhatpatch availablevia redhat_api
Product: Red Hat build of Apache Camel 4.4.3 for Spring Boot
View patch
redhatpatch availablevia redhat_api
Product: Red Hat build of Apache Camel 4.8 for Spring Boot
View patch
redhatpatch availablevia redhat_api
Product: Red Hat build of Apache Camel 4 for Quarkus 3Fixed in: com.google.protobuf/protobuf-java
View patch
redhatpatch availablevia redhat_api
Product: Red Hat build of Quarkus 3.2Fixed in: com.google.protobuf/protobuf
View patch
redhatpatch availablevia redhat_api
Product: Red Hat build of Quarkus 3.8Fixed in: com.google.protobuf/protobuf
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss EAP XP 5.0 Update 2.0Fixed in: protobuf-java
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7Fixed in: eap7-protostream-0:4.3.7-1.Final_redhat_00001.1.el7eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7Fixed in: eap7-wildfly-0:7.4.23-5.GA_redhat_00004.1.el7eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 8Fixed in: eap7-protostream-0:4.3.7-1.Final_redhat_00001.1.el8eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 8Fixed in: eap7-wildfly-0:7.4.23-5.GA_redhat_00004.1.el8eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 9Fixed in: eap7-protostream-0:4.3.7-1.Final_redhat_00001.1.el9eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 9Fixed in: eap7-wildfly-0:7.4.23-5.GA_redhat_00004.1.el9eap
View patch
redhatpatch availablevia redhat_api
Product: Streams for Apache Kafka 2.8.0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Trusted Profile Analyzer 1.2Fixed in: rhtpa/rhtpa-guac-rhel9:sha256:9cc0e1374aa5e6ff8caf86d9bbd6f9c2dfa14d812ad99ae653a2fbb8ec124f30
View patch
rubygemspatch availablevia ghsa
Product: google-protobufFixed in: 4.27.5
rubygemspatch availablevia ghsa
Product: google-protobufFixed in: 4.28.2
rubygemspatch availablevia ghsa
Product: google-protobufFixed in: 3.25.5
redhatno patchvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform Expansion PackFixed in: protobuf-java
redhatno patchvia redhat_api
Product: Red Hat build of Apicurio Registry 2Fixed in: com.google.protobuf/protobuf-java
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-modelmesh-rhel8
redhatno patchvia redhat_api
Product: Red Hat OpenStack Platform 16.2Fixed in: protobuf
redhatno patchvia redhat_api
Product: Red Hat Process Automation 7Fixed in: com.google.protobuf/protobuf-java
redhatno patchvia redhat_api
Product: streams for Apache KafkaFixed in: com.google.protobuf/protobuf-java
redhatend of lifevia redhat_api
Product: Red Hat build of Debezium 2Fixed in: com.google.protobuf/protobuf-java
redhatend of lifevia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-trustyai-service-rhel8
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux AI (RHEL AI)Fixed in: rhelai1/bootc-nvidia-rhel9
redhatend of lifevia redhat_api
Product: Red Hat Data Grid 8Fixed in: com.google.protobuf/protobuf-java
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux AI (RHEL AI)Fixed in: rhelai1/instructlab-nvidia-rhel9
redhatend of lifevia redhat_api
Product: Red Hat Fuse 7Fixed in: com.google.protobuf/protobuf-java
redhatend of lifevia redhat_api
Product: Red Hat Integration Camel K 1Fixed in: com.google.protobuf/protobuf-java
redhatend of lifevia redhat_api
Product: Red Hat AMQ Broker 7Fixed in: com.google.protobuf/protobuf-java

Vendor Advisories (6)

honeywellllm-honeywell-c82b5cfda9df97a3CRITICAL

HP ThinPro 8.1 SP8 Security Updates

Oct 27, 2025
autodeskllm-autodesk-c365b674a2ff5a3aCRITICAL

HP ThinPro 8.1 SP8 Security Updates

Oct 27, 2025
freepbxllm-freepbx-e54908c7967265f6CRITICAL

HP ThinPro 8.1 SP8 Security Updates

Oct 27, 2025
mavenGHSA-735f-pc8j-v9w8high

protobuf-java has potential Denial of Service issue

Sep 19, 2024
redhatCVE-2024-7254Important

protobuf: StackOverflow vulnerability in Protocol Buffers

Sep 19, 2024
microsoft2024-Sep/CVE-2024-7254

Stack overflow in Protocol Buffers Java Lite

Sep 10, 2024

References

security.netapp.com / advisory/ntap-20241213-0010
Third Party Advisory
security.netapp.com / advisory/ntap-20250418-0006
Third Party Advisory
github.com / protocolbuffers/protobuf/commit/cc8b3483a5584b3301e3d43d17eb59704857ffaa
Patch