CVE-2021-22569
An issue in protobuf-java allowed the interleaving of com.google.protobuf.UnknownFieldSet fields in such a way that would be processed out of order. A small malicious payload can occupy the parser for several minutes by creating large numbers of short-lived objects that cause frequent, repeated pauses. We recommend upgrading libraries beyond the vulnerable versions.
Published:Jan 6, 2022
Last Modified:Apr 21, 2025
EPS:Jan 7, 2022
EPSS Score:0.00353
CVSS Score:7.5
Affected Products
Vendor
Product
Action
Vendor
Google
Product
Google-protobuf
Google
Google-protobuf
Vendor
Google
Product
Protobuf-java
Google
Protobuf-java
Vendor
Google
Product
Protobuf-kotlin
Google
Protobuf-kotlin
Vendor
Oracle
Product
Communications Cloud Native Core Console
Oracle
Communications Cloud Native Core Console
Vendor
Oracle
Product
Communications Cloud Native Core Network Repository Function
Oracle
Communications Cloud Native Core Network Repository Function
Vendor
Oracle
Product
Communications Cloud Native Core Policy
Oracle
Communications Cloud Native Core Policy
Vendor
Oracle
Product
Spatial And Graph Mapviewer
Oracle
Spatial And Graph Mapviewer
Vendor
Redhat
Product
Camel Quarkus
Redhat
Camel Quarkus
Vendor
Redhat
Product
Integration
Redhat
Integration
Vendor
Redhat
Product
Jboss Enterprise Bpms Platform
Redhat
Jboss Enterprise Bpms Platform
Vendor
Redhat
Product
Jboss Fuse
Redhat
Jboss Fuse
Vendor
Redhat
Product
Openshift Application Runtimes
Redhat
Openshift Application Runtimes
Vendor
Redhat
Product
Quarkus
Redhat
Quarkus
Vendor
Redhat
Product
Service Registry
Redhat
Service Registry
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
