Impact
Google.Protobuf versions before 3.4.0 are associated with CVE-2015-5237 / GHSA-jwvw-v7c5-m82h, a heap-based buffer-overflow advisory for Protocol Buffers [S1][S2]. NVD rates the issue High with low privileges required [S2].
Root Cause
The upstream issue describes integer-overflow risk around very large serialized messages, where size calculations can lead to an undersized allocation and heap buffer overflow in serialization code [S3]. The NuGet advisory lists Google.Protobuf versions below 3.4.0 as affected and 3.4.0 as patched [S1].
How FixVibe covers it
FixVibe's GitHub repo scans flag NuGet project, central package and lockfile entries that resolve Google.Protobuf below 3.4.0, showing the file, line, version and fixed version.
Fix
Upgrade Google.Protobuf to 3.4.0 or newer in every active .NET project, central package props file, packages.config file, and lockfile that controls deployed apps, workers, services, test utilities, or shared libraries [S1]. Run dotnet restore, regenerate lockfiles, rebuild affected artifacts, and verify the active dependency graph with dotnet list package --include-transitive where supported. Use normal protobuf serialization and deserialization smoke tests only; do not add exploit fixtures or crash tests.
