← Späť na vyhľadávanie CVE

CVE-2026-6409

Protobuf PHP

Popis

A Denial of Service (DoS) vulnerability exists in the Protobuf PHP library during the parsing of untrusted input. Maliciously structured messages—specifically those containing negative varints or deep recursion—can be used to crash the application, impacting service availability.

CVSS 7.1EPSS 0.36%Riziko 0.73
Zobraziť zdroj
Zverejnené
2026-04-16 15:17:41
Dotknuté verzie
unknown
Typ
Package
Vektor
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X