An open index of dependabot pull requests across open source projects.

com.google.protobuf:protobuf-java

Ecosystem:
maven
Package URL:
pkg:maven/com.google.protobuf:protobuf-java
Total PRs:
1,026 Dependabot PRs
Latest PR:
about 10 hours ago
Unique Repositories:
373 repositories
Unique Repos (30 days):
192 repositories
Security Advisories
Protobuf Java vulnerable to Uncontrolled Resource Consumption
GHSA-g5ww-5jh7-63cx CVE-2022-3509 HIGH published almost 3 years ago • updated 3 months ago
A parsing issue similar to CVE-2022-3171, but with textformat in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 ca...
NULL Pointer Dereference in Protocol Buffers
GHSA-77rm-9x9h-xj3g CVE-2021-22570 HIGH published over 3 years ago • updated about 1 month ago
Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, leading to an unchecked call into the proto fi...
A potential Denial of Service issue in protobuf-java
GHSA-wrvw-hg22-4m67 CVE-2021-22569 HIGH published over 3 years ago • updated about 1 month ago
## Summary A potential Denial of Service issue in protobuf-java was discovered in the parsing procedure for binary data. Reporter: [OSS-Fuzz](htt...
protobuf-java has potential Denial of Service issue
GHSA-735f-pc8j-v9w8 CVE-2024-7254 HIGH published 12 months ago • updated about 1 month ago
### Summary When parsing unknown fields in the Protobuf Java Lite and Full library, a maliciously crafted message can cause a StackOverflow error a...
Protobuf Java vulnerable to Uncontrolled Resource Consumption
GHSA-4gg5-vx3j-xwc7 CVE-2022-3510 HIGH published almost 3 years ago • updated about 1 month ago
A parsing issue similar to CVE-2022-3171, but with Message-Type Extensions in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 ...
Recent PRs (filtered by: Minor PRs )
Bump the maven group with 4 updates

google/gson #2895

4.31.1 → 4.32.0 Minor PR
Open 12 days ago 5 comments
google
Package Details
Name: com.google.protobuf:protobuf-java
Ecosystem: maven
PURL Type: maven
Package URL: pkg:maven/com.google.protobuf:protobuf-java
JSON API: View JSON
Security Advisories

6

Active advisories
HIGH 5
MODERATE 1
View All maven Advisories
Package Information
Description:

Core Protocol Buffers library. Protocol Buffers are a way of encoding structured data in an efficient yet extensible format.

Repository: https://github.com/protocolbuffers/protobuf
Homepage: https://developers.google.com/protocol-buffers/
Latest Release: 4.31.1
4 months ago
Dependent Repos: 38,630
Dependent Packages: 5,130
Ranking: Top 0.025% by dependent repos Top 0.0144% by dependent pkgs
PR Status
Open 408 (39.8%)
Merged 203 (19.8%)
Closed 230 (22.4%)
PR Types
Major 237 (23.1%)
Patch 186 (18.1%)
Minor 418 (40.7%)