CVE-2022-3171 - CVE House
Back to Database
Status published Medium CVE-2022-3171

Memory handling vulnerability in ProtocolBuffers Java core and lite

Vulnerability Description

A parsing issue with binary data in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields causes objects to be converted back-n-forth between mutable and immutable forms, resulting in potentially long garbage collection pauses. We recommend updating to the versions mentioned above.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-3171

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Protocolbuffers
Vulnerable Versions:
3.21.7, 3.20.3, 3.19.6, 3.16.3

Timeline

Official Publish: October 12th, 2022
Last Modified: April 21st, 2025
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Weaknesses (CWE)