Update dependency protobuf to v5 [SECURITY] - #6
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
renovate
Bot
force-pushed
the
renovate/pypi-protobuf-vulnerability
branch
from
November 2, 2023 08:41
cceae95 to
dfe90c9
Compare
renovate
Bot
force-pushed
the
renovate/pypi-protobuf-vulnerability
branch
from
August 10, 2024 05:54
dfe90c9 to
d188a9c
Compare
renovate
Bot
force-pushed
the
renovate/pypi-protobuf-vulnerability
branch
2 times, most recently
from
November 4, 2024 02:48
beaef2d to
46694c1
Compare
renovate
Bot
force-pushed
the
renovate/pypi-protobuf-vulnerability
branch
from
January 15, 2025 03:58
46694c1 to
b191394
Compare
renovate
Bot
force-pushed
the
renovate/pypi-protobuf-vulnerability
branch
from
January 31, 2025 16:21
b191394 to
408d6dd
Compare
renovate
Bot
force-pushed
the
renovate/pypi-protobuf-vulnerability
branch
from
March 5, 2025 04:10
408d6dd to
565c6f7
Compare
renovate
Bot
force-pushed
the
renovate/pypi-protobuf-vulnerability
branch
2 times, most recently
from
March 18, 2025 20:13
0515c2f to
ddb1026
Compare
renovate
Bot
force-pushed
the
renovate/pypi-protobuf-vulnerability
branch
from
April 12, 2025 03:41
ddb1026 to
ab32400
Compare
renovate
Bot
force-pushed
the
renovate/pypi-protobuf-vulnerability
branch
from
May 9, 2025 00:22
ab32400 to
28ce318
Compare
renovate
Bot
force-pushed
the
renovate/pypi-protobuf-vulnerability
branch
from
June 21, 2025 12:02
28ce318 to
9590c3a
Compare
renovate
Bot
force-pushed
the
renovate/pypi-protobuf-vulnerability
branch
from
September 11, 2025 08:13
9590c3a to
09a942c
Compare
renovate
Bot
force-pushed
the
renovate/pypi-protobuf-vulnerability
branch
from
September 14, 2025 23:39
09a942c to
637badd
Compare
renovate
Bot
force-pushed
the
renovate/pypi-protobuf-vulnerability
branch
from
September 26, 2025 03:44
637badd to
dfaac06
Compare
renovate
Bot
force-pushed
the
renovate/pypi-protobuf-vulnerability
branch
from
January 31, 2026 07:00
dfaac06 to
c341bc0
Compare
Contributor
Author
|
renovate
Bot
force-pushed
the
renovate/pypi-protobuf-vulnerability
branch
from
February 6, 2026 03:31
c341bc0 to
63d0d28
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^3.15.8→^5.0.0==3.15.8→==5.29.6protobuf-cpp and protobuf-python have potential Denial of Service issue
CVE-2022-1941 / GHSA-8gq9-2x98-w8hf
More information
Details
Summary
A message parsing and memory management vulnerability in ProtocolBuffer’s C++ and Python implementations can trigger an out of memory (OOM) failure when processing a specially crafted message, which could lead to a denial of service (DoS) on services using the libraries.
Reporter: ClusterFuzz
Affected versions: All versions of C++ Protobufs (including Python) prior to the versions listed below.
Severity & Impact
As scored by google
Medium 5.7 - CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Asscored byt NIST
High 7.5 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
A small (~500 KB) malicious payload can be constructed which causes the running service to allocate more than 3GB of RAM.
Proof of Concept
For reproduction details, please refer to the unit test that identifies the specific inputs that exercise this parsing weakness.
Mitigation / Patching
Please update to the latest available versions of the following packages:
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
protobuf-python has a potential Denial of Service issue
CVE-2025-4565 / GHSA-8qvm-5x2c-j2w7
More information
Details
Summary
Any project that uses Protobuf pure-Python backend to parse untrusted Protocol Buffers data containing an arbitrary number of recursive groups, recursive messages or a series of
SGROUPtags can be corrupted by exceeding the Python recursion limit.Reporter: Alexis Challande, Trail of Bits Ecosystem Security Team
ecosystem@trailofbits.com
Affected versions: This issue only affects the pure-Python implementation of protobuf-python backend. This is the implementation when
PROTOCOL_BUFFERS_PYTHON_IMPLEMENTATION=pythonenvironment variable is set or the default when protobuf is used from Bazel or pure-Python PyPi wheels. CPython PyPi wheels do not use pure-Python by default.This is a Python variant of a previous issue affecting protobuf-java.
Severity
This is a potential Denial of Service. Parsing nested protobuf data creates unbounded recursions that can be abused by an attacker.
Proof of Concept
For reproduction details, please refer to the unit tests decoder_test.py and message_test
Remediation and Mitigation
A mitigation is available now. Please update to the latest available versions of the following packages:
Severity
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
protobuf affected by a JSON recursion depth bypass
CVE-2026-0994 / GHSA-7gcm-g887-7qv7
More information
Details
A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages.
Due to missing recursion depth accounting inside the internal Any-handling logic, an attacker can supply deeply nested Any structures that bypass the intended recursion limit, eventually exhausting Python’s recursion stack and causing a RecursionError.
Severity
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:LReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about these updates again.
This PR was generated by Mend Renovate. View the repository job log.