CVE-2022-3171 Details
Description
A parsing issue with binary data in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields causes objects to be converted back-n-forth between mutable and immutable forms, resulting in potentially long garbage collection pauses. We recommend updating to the versions mentioned above.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 21, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
| CWE-20 | Improper Input Validation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| google google-protobuf | < 3.16.3 >= 3.17.0, < 3.19.6 >= 3.20.0, < 3.20.3 >= 3.21.0, < 3.21.7 |
CPE
Remediation
| |
| google protobuf-java | < 3.16.3 >= 3.17.0, < 3.19.6 >= 3.20.0, < 3.20.3 >= 3.21.0, < 3.21.7 |
CPE
Remediation
| |
| google protobuf-javalite | < 3.16.3 >= 3.17.0, < 3.19.6 >= 3.20.0, < 3.20.3 >= 3.21.0, < 3.21.7 |
CPE
Remediation
| |
| google protobuf-kotlin | < 3.16.3 >= 3.17.0, < 3.19.6 >= 3.20.0, < 3.20.3 >= 3.21.0, < 3.21.7 |
CPE
Remediation
| |
| google protobuf-kotlin-lite | < 3.16.3 >= 3.17.0, < 3.19.6 >= 3.20.0, < 3.20.3 >= 3.21.0, < 3.21.7 |
CPE
Remediation
| |
| fedoraproject fedora | 37 |
CPE
Remediation
| |
Change History
10 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Nov 7, 2023 | CVE Modified | [email protected] |
| Apr 27, 2023 | CVE Modified | [email protected] |
| Feb 21, 2023 | Modified Analysis | [email protected] |
| Jan 11, 2023 | CVE Modified | [email protected] |
| Dec 18, 2022 | CVE Modified | [email protected] |
| Oct 13, 2022 | Initial Analysis | [email protected] |