FixVibe

high

Buffer Overflow in Google.Protobuf (CVE-2015-5237)

Google.Protobuf versions before 3.4.0 are associated with CVE-2015-5237 / GHSA-jwvw-v7c5-m82h. FixVibe GitHub repo scans flag affected Google.Protobuf versions in NuGet projects and lockfiles.

CVE-2015-5237GHSA-jwvw-v7c5-m82hCWE-787

Impact

Google.Protobuf versions before 3.4.0 are associated with CVE-2015-5237 / GHSA-jwvw-v7c5-m82h, a heap-based buffer-overflow advisory for Protocol Buffers [S1][S2]. NVD rates the issue High with low privileges required [S2].

Root Cause

The upstream issue describes integer-overflow risk around very large serialized messages, where size calculations can lead to an undersized allocation and heap buffer overflow in serialization code [S3]. The NuGet advisory lists Google.Protobuf versions below 3.4.0 as affected and 3.4.0 as patched [S1].

How FixVibe covers it

FixVibe's GitHub repo scans flag NuGet project, central package and lockfile entries that resolve Google.Protobuf below 3.4.0, showing the file, line, version and fixed version.

Fix

Upgrade Google.Protobuf to 3.4.0 or newer in every active .NET project, central package props file, packages.config file, and lockfile that controls deployed apps, workers, services, test utilities, or shared libraries [S1]. Run dotnet restore, regenerate lockfiles, rebuild affected artifacts, and verify the active dependency graph with dotnet list package --include-transitive where supported. Use normal protobuf serialization and deserialization smoke tests only; do not add exploit fixtures or crash tests.