7.5

CVE-2026-45799

Exploit

Wire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wire-decoding service

Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.3.0 and 7.0.0-alpha03, ByteArrayProtoReader32.skipGroup() and ProtoReader.skipGroup() in wire-runtime do not validate that a LENGTH_DELIMITED field length is non-negative before skip(), allowing a crafted protobuf varint encoding -128 as a signed Int to make skip(-128) move the internal position negative and make the next readByte() throw ArrayIndexOutOfBoundsException instead of the documented IOException or ProtocolException, which can crash services using ProtoAdapter.decode(byte[]) on untrusted payloads. This issue is fixed in versions 6.3.0 and 7.0.0-alpha03.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SquareupWire Version < 6.3.0
SquareupWire Version7.0.0 Updatealpha01
SquareupWire Version7.0.0 Updatealpha02
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.55% 0.43
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security-advisories@github.com 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-129 Improper Validation of Array Index

The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.

https://github.com/square/wire/security/advisories/GHSA-7xpr-hc2w-34m9
Vendor Advisory
Exploit
https://github.com/square/wire/pull/3595
Issue Tracking
https://github.com/square/wire/pull/3597
Issue Tracking
https://github.com/square/wire/commit/47d5b0dba53935d5332cd41a80a353b3fc90e7b0
Patch
https://github.com/square/wire/commit/e4e56fab38a547d9625f05c97f1d8f0bcc3a5773
Patch
https://github.com/square/wire/releases/tag/6.3.0
Release Notes
https://github.com/square/wire/releases/tag/7.0.0-alpha03
Release Notes