Ad

CVE-2026-6409

HIGH CVSS 4.0: 7.1
Updated Apr 17, 2026
PHP
Parameter Value
CVSS 7.1 (HIGH)
Type CWE-20 (Improper Input Validation)
Vendor PHP
Public PoC No

A Denial of Service (DoS) vulnerability exists in the Protobuf PHP library during the parsing of untrusted input. Maliciously structured messages—specifically those containing negative varints or deep recursion—can be used to crash the application, impacting service availability.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Attack Requirements
None
No additional conditions
Privileges Required
None
No privileges needed
User Interaction
Passive
Minimal interaction

Impact Assessment

Confidentiality
None
No data leak
Integrity
None
No data modification
Availability
High
Complete denial of service

CVSS Vector v4.0