CVE-2024-58103: Square Wire

Medium severity, CVSS 5.8. EPSS: 0.5% chance of exploitation in the next 30 days.

Square Wire before 5.2.0 does not enforce a recursion limit on nested groups in ByteArrayProtoReader32.kt and ProtoReader.kt.

Affected products

  • Square Wire: before 5.2.0 (fixed in 5.2.0)

Published 2025-03-16. Last modified 2026-06-17.