The Protobuf C Project maintains a specialized serialization library that, despite a narrow product scope, is embedded in systems requiring binary protocol efficiency and is more widely present than typical for a single-purpose compiler component. The observed vulnerability surface reflects the implementation complexity inherent to a C-based code-generation and message-handling system. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Protobuf C Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-48468MEDIUM protobuf-c before 1.4.1 has an unsigned integer overflow in parse_required_member. | Apr 13, 2023 | 5.5 | 21 | NO | NO |
CVE-2022-33070MEDIUM Protobuf-c v1.4.0 was discovered to contain an invalid arithmetic shift via the function parse_tag_and_wiretype in protobuf-c/protobuf-c.c. This vulnerability allows attackers to c | Jun 23, 2022 | 5.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Protobuf C Project.
Media articles that mention a CVE ID that affects a product developed by Protobuf C Project — matched by CVE ID, not by vendor name.