Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-83420.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-83420
Upstream
Published
2026-04-16T15:17:41Z
Modified
2026-09-03T05:27:10Z
Summary
CVE-2026-6409 affecting package protobuf for versions less than 25.3-7
Details

A Denial of Service (DoS) vulnerability exists in the Protobuf PHP library during the parsing of untrusted input. Maliciously structured messages—specifically those containing negative varints or deep recursion—can be used to crash the application, impacting service availability.

References

Affected packages

Azure Linux:3 / protobuf

Package

Name
protobuf
Purl
pkg:rpm/azure-linux/protobuf

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
25.3-7

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-83420.json"