First published: Tue Mar 14 2023(Updated: )
Parsing invalid messages can panic. Parsing a text-format message which contains a potential number consisting of a minus sign, one or more characters of whitespace, and no further input will cause a panic.
Credit: security@golang.org security@golang.org
Affected Software | Affected Version | How to fix |
---|---|---|
go/google.golang.org/protobuf | >=1.29.0<1.29.1 | 1.29.1 |
Google Protocol Buffers | =1.29.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.