Insecure functionality In google.golang.org/protobuf/encoding/protojson
Description
Golang protojson.Unmarshal function infinite loop when unmarshaling certain forms of invalid JSON The protojson.Unmarshal function can enter an infinite loop when unmarshaling certain forms of invalid JSON. This condition can occur when unmarshaling into a message which contains a google.protobuf.Any value, or when the UnmarshalOptions.DiscardUnknown option is set.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
go | 1.33.0 | ||
go | 1.33.0 | ||
debian 13 | 1.33.0-1 | ||
rpm rhel9 | 2:1.33.7-1.el9_4 | ||
debian 14 | 1.33.0-1 | ||
go | 1.33.0 | ||
debian 12 | - | ||
rpm rhel9 | 4:4.9.4-3.el9_4 | ||
rpm rhel8 | - | - | |
rpm rhel7 | 0:0.7-1.el7_9 |
1-10 of 18
10
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2. 3. 4. 5. 6. 7.