An open index of dependabot pull requests across open source projects.

com.google.protobuf:protobuf-java

Ecosystem:
maven
Package URL:
pkg:maven/com.google.protobuf:protobuf-java
Total PRs:
1,209 Dependabot PRs
Latest PR:
1 day ago
Unique Repositories:
402 repositories
Unique Repos (30 days):
24 repositories
Security Advisories
Protobuf Java vulnerable to Uncontrolled Resource Consumption
GHSA-g5ww-5jh7-63cx CVE-2022-3509 HIGH published almost 3 years ago • updated about 19 hours ago
A parsing issue similar to CVE-2022-3171, but with textformat in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 ca...
A potential Denial of Service issue in protobuf-java
GHSA-wrvw-hg22-4m67 CVE-2021-22569 HIGH published almost 4 years ago • updated 3 days ago
## Summary A potential Denial of Service issue in protobuf-java was discovered in the parsing procedure for binary data. Reporter: [OSS-Fuzz](htt...
protobuf-java has a potential Denial of Service issue
GHSA-h4h5-3hr4-j3g2 CVE-2022-3171 MODERATE published about 3 years ago • updated 4 days ago
## Summary A potential Denial of Service issue in `protobuf-java` core and lite was discovered in the parsing procedure for binary and text format ...
Protobuf Java vulnerable to Uncontrolled Resource Consumption
GHSA-4gg5-vx3j-xwc7 CVE-2022-3510 HIGH published almost 3 years ago • updated 4 days ago
A parsing issue similar to CVE-2022-3171, but with Message-Type Extensions in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 ...
protobuf-java has potential Denial of Service issue
GHSA-735f-pc8j-v9w8 CVE-2024-7254 HIGH published about 1 year ago • updated about 20 hours ago
### Summary When parsing unknown fields in the Protobuf Java Lite and Full library, a maliciously crafted message can cause a StackOverflow error a...
Recent PRs (filtered by: Patch PRs )
Package Details
Name: com.google.protobuf:protobuf-java
Ecosystem: maven
PURL Type: maven
Package URL: pkg:maven/com.google.protobuf:protobuf-java
JSON API: View JSON
Security Advisories

5

Active advisories
HIGH 4
MODERATE 1
View All maven Advisories
Package Information
Description:

Core Protocol Buffers library. Protocol Buffers are a way of encoding structured data in an efficient yet extensible format.

Repository: https://github.com/protocolbuffers/protobuf
Homepage: https://developers.google.com/protocol-buffers/
Latest Release: 4.31.1
6 months ago
Dependent Repos: 38,630
Dependent Packages: 5,130
Ranking: Top 0.025% by dependent repos Top 0.0144% by dependent pkgs
PR Status
Open 483 (40.0%)
Merged 233 (19.3%)
Closed 307 (25.4%)
PR Types
Major 300 (24.8%)
Patch 238 (19.7%)
Minor 485 (40.1%)