CVE-2024-24786: Google.golang.org/protobuf Google.golang.org/protobuf/encoding/protojson
High severity, CVSS 7.5. EPSS: 1.3% chance of exploitation in the next 30 days.
The protojson.Unmarshal function can enter an infinite loop when unmarshaling certain forms of invalid JSON. This condition can occur when unmarshaling into a message which contains a google.protobuf.Any value, or when the UnmarshalOptions.DiscardUnknown option is set.
Affected products
- Google.golang.org/protobuf Google.golang.org/protobuf/encoding/protojson: before 1.33.0 (fixed in 1.33.0)
- Google.golang.org/protobuf Google.golang.org/protobuf/internal/encoding/json: before 1.33.0 (fixed in 1.33.0)
Published 2024-03-05. Last modified 2026-09-23.