7.5
CVE-2026-45799
- EPSS 0.55%
- Veröffentlicht 17.07.2026 19:49:30
- Zuletzt bearbeitet 12.08.2026 19:04:04
- CVE-Watchlists
- Unerledigt
Wire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wire-decoding service
Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.3.0 and 7.0.0-alpha03, ByteArrayProtoReader32.skipGroup() and ProtoReader.skipGroup() in wire-runtime do not validate that a LENGTH_DELIMITED field length is non-negative before skip(), allowing a crafted protobuf varint encoding -128 as a signed Int to make skip(-128) move the internal position negative and make the next readByte() throw ArrayIndexOutOfBoundsException instead of the documented IOException or ProtocolException, which can crash services using ProtoAdapter.decode(byte[]) on untrusted payloads. This issue is fixed in versions 6.3.0 and 7.0.0-alpha03.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.55% | 0.43 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-129 Improper Validation of Array Index
The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.
https://github.com/square/wire/security/advisories/GHSA-7xpr-hc2w-34m9
https://github.com/square/wire/pull/3595
https://github.com/square/wire/pull/3597
https://github.com/square/wire/commit/47d5b0dba53935d5332cd41a80a353b3fc90e7b0
https://github.com/square/wire/commit/e4e56fab38a547d9625f05c97f1d8f0bcc3a5773
https://github.com/square/wire/releases/tag/6.3.0
https://github.com/square/wire/releases/tag/7.0.0-alpha03