CVE-2024-58103: Square Wire
Medium severity, CVSS 5.8. EPSS: 0.5% chance of exploitation in the next 30 days.
Square Wire before 5.2.0 does not enforce a recursion limit on nested groups in ByteArrayProtoReader32.kt and ProtoReader.kt.
Affected products
- Square Wire: before 5.2.0 (fixed in 5.2.0)
Published 2025-03-16. Last modified 2026-06-17.