CVE-2026-6409

A Denial of Service (DoS) vulnerability exists in the Protobuf PHP library during the parsing of untrusted input. Maliciously structured messages—specifically those containing negative varints or deep recursion—can be used to crash the application, impacting service availability.
CVSS

No CVSS.

Configurations

No configuration.

History

16 Apr 2026, 15:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-16 15:17

Updated : 2026-04-17 15:17


NVD link : CVE-2026-6409

Mitre link : CVE-2026-6409

CVE.ORG link : CVE-2026-6409


JSON object : View

Products Affected

No product.

CWE
CWE-20

Improper Input Validation