{"id":"GHSA-c3h9-896r-86jm","summary":"Improper Input Validation in GoGo Protobuf","details":"An issue was discovered in GoGo Protobuf before 1.3.2. plugin/unmarshal/unmarshal.go lacks certain index validation, aka the \"skippy peanut butter\" issue.","aliases":["BIT-consul-2021-3121","BIT-protobuf-2021-3121","CVE-2021-3121","GO-2021-0053"],"modified":"2026-07-17T21:13:01.019727206Z","published":"2022-03-28T20:28:00Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2022-03-28T20:28:00Z","nvd_published_at":"2021-01-11T06:15:00Z","cwe_ids":["CWE-129","CWE-20"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-3121"},{"type":"WEB","url":"https://github.com/gogo/protobuf/commit/b03c65ea87cdc3521ede29f62fe3ce239267c1bc"},{"type":"WEB","url":"https://discuss.hashicorp.com/t/hcsec-2021-23-consul-exposed-to-denial-of-service-in-gogo-protobuf-dependency/29025"},{"type":"PACKAGE","url":"https://github.com/gogo/protobuf"},{"type":"WEB","url":"https://github.com/gogo/protobuf/compare/v1.3.1...v1.3.2"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r68032132c0399c29d6cdc7bd44918535da54060a10a12b1591328bff@%3Cnotifications.skywalking.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r88d69555cb74a129a7bf84838073b61259b4a3830190e05a3b87994e@%3Ccommits.pulsar.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/rc1e9ff22c5641d73701ba56362fb867d40ed287cca000b131dcf4a44@%3Ccommits.pulsar.apache.org%3E"},{"type":"WEB","url":"https://pkg.go.dev/vuln/GO-2021-0053"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20210219-0006"}],"affected":[{"package":{"name":"github.com/gogo/protobuf","ecosystem":"Go","purl":"pkg:golang/github.com/gogo/protobuf"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.3.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/03/GHSA-c3h9-896r-86jm/GHSA-c3h9-896r-86jm.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H"}]}