CVE-2023-24535: Protobuf
High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.
Parsing invalid messages can panic. Parsing a text-format message which contains a potential number consisting of a minus sign, one or more characters of whitespace, and no further input will cause a panic.
Affected products
- Protobuf Protobuf: version 1.29.0 only
Published 2023-06-08. Last modified 2026-06-17.