GHSA-9rm7-3qhh-h2mc
HIGHCVE-2026-63126Wire's protobuf decoders did not consistently validate attacker-controlled length-delimited sizes against the current reader bounds before computing cursor, limit, or pointer positions.
- Affected
- <= 6.4.4, >= 7.0.0-alpha01, < 7.0.0-alpha04
- Fixed in
- 6.4.5
- Weakness
- CWE-190
- Published
- 2026-09-17
- Source
- github
GHSANVDMITREreferencereferencereferencereferencereferencereference