{"id":"CVE-2022-1941","aliases":["GHSA-8gq9-2x98-w8hf","PYSEC-2026-899"],"title":"protobuf-cpp and protobuf-python have potential Denial of Service issue","summary":"protobuf-cpp and protobuf-python have potential Denial of Service issue","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","vendor":"protobuf","product":"protobuf","ecosystem":"pip","affected":["protobuf < 3.18.3","protobuf >= 3.19.0, < 3.19.5","protobuf >= 3.20.0, < 3.20.2","protobuf >= 4.0.0, < 4.21.6"],"patched":["protobuf 3.18.3","protobuf 3.19.5","protobuf 3.20.2","protobuf 4.21.6"],"published":"2022-09-23","updated":"2026-07-08","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-8gq9-2x98-w8hf","references":[{"url":"https://github.com/protocolbuffers/protobuf/security/advisories/GHSA-8gq9-2x98-w8hf"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2022-1941"},{"url":"https://cloud.google.com/support/bulletins#GCP-2022-019"},{"url":"https://github.com/protocolbuffers/protobuf"},{"url":"https://lists.debian.org/debian-lts-announce/2023/04/msg00019.html"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CBAUKJQL6O4TIWYBENORSY5P43TVB4M3"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MPCGUT3T5L6C3IDWUPSUO22QDCGQKTOP"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CBAUKJQL6O4TIWYBENORSY5P43TVB4M3"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MPCGUT3T5L6C3IDWUPSUO22QDCGQKTOP"},{"url":"https://security.netapp.com/advisory/ntap-20240705-0001"},{"url":"http://www.openwall.com/lists/oss-security/2022/09/27/1"}],"tags":["osv","pip"],"epss":0.01502,"epssPercentile":0.73166,"ingestedAt":"2026-07-08T18:25:47.490Z","slug":"CVE-2022-1941","body":"## Overview\n\n### Summary\n\nA message parsing and memory management vulnerability in ProtocolBuffer’s C++ and Python implementations can trigger an out of memory (OOM) failure when processing a specially crafted message, which could lead to a denial of service (DoS) on services using the libraries.\n\nReporter: [ClusterFuzz](https://google.github.io/clusterfuzz/)\n\nAffected versions: All versions of C++ Protobufs (including Python) prior to the versions listed below.\n\n### Severity & Impact\nAs scored by google  \n**Medium 5.7** - [CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H](https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)  \nAsscored byt NIST  \n**High 7.5** - [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H](https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)\n\nA small (~500 KB) malicious payload can be constructed which causes the running service to allocate more than 3GB of RAM.\n\n### Proof of Concept\n\nFor reproduction details, please refer to the unit test that identifies the specific inputs that exercise this parsing weakness.\n\n### Mitigation / Patching\n\nPlease update to the latest available versions of the following packages:\n- protobuf-cpp (3.18.3, 3.19.5, 3.20.2, 3.21.6)\n- protobuf-python (3.18.3, 3.19.5, 3.20.2, 4.21.6)\n\n## Affected packages\n\n- `protobuf < 3.18.3`\n- `protobuf >= 3.19.0, < 3.19.5`\n- `protobuf >= 3.20.0, < 3.20.2`\n- `protobuf >= 4.0.0, < 4.21.6`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `protobuf 3.18.3`\n- `protobuf 3.19.5`\n- `protobuf 3.20.2`\n- `protobuf 4.21.6`","depth":"twilight","depthScore":42,"depthScoreParts":{"impact":41.3,"likelihood":0.3,"exploitation":0,"ransomware":0},"changes":[]}