CVE-2024-24786: Google.golang.org/protobuf Google.golang.org/protobuf/encoding/protojson

High severity, CVSS 7.5. EPSS: 1.3% chance of exploitation in the next 30 days.

The protojson.Unmarshal function can enter an infinite loop when unmarshaling certain forms of invalid JSON. This condition can occur when unmarshaling into a message which contains a google.protobuf.Any value, or when the UnmarshalOptions.DiscardUnknown option is set.

Affected products

Published 2024-03-05. Last modified 2026-09-23.