{"id":"GHSA-pwf9-q62p-v7wc","summary":"Wire has Uncontrolled Recursion on Nested Groups","details":"Square Wire before 5.2.0 does not enforce a recursion limit on nested groups in ByteArrayProtoReader32.kt and ProtoReader.kt.","aliases":["CVE-2024-58103"],"modified":"2026-07-17T21:15:24.555971379Z","published":"2025-03-16T06:30:23Z","database_specific":{"nvd_published_at":"2025-03-16T04:15:12Z","cwe_ids":["CWE-674"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2025-03-18T21:06:13Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-58103"},{"type":"WEB","url":"https://github.com/square/wire/commit/b90e60c09befaff836a2fc2ee4d678451b2ec75d"},{"type":"PACKAGE","url":"https://github.com/square/wire"},{"type":"WEB","url":"https://github.com/square/wire/compare/5.1.0...5.2.0"}],"affected":[{"package":{"name":"com.squareup.wire:wire-runtime","ecosystem":"Maven","purl":"pkg:maven/com.squareup.wire/wire-runtime"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.2.0"}]}],"versions":["1.0.0","1.0.1","1.1.0","1.1.1","1.2.0","1.3.0","1.3.1","1.3.2","1.3.3","1.4.0","1.5.0","1.5.1","1.5.2","1.6.0","1.6.1","1.7.0","1.8.0","2.0.0","2.0.0-BETA1","2.0.0-BETA10","2.0.0-BETA2","2.0.0-BETA3","2.0.0-BETA4","2.0.0-BETA5","2.0.0-BETA6","2.0.0-BETA7","2.0.0-BETA8","2.0.0-BETA9","2.0.1","2.0.2","2.0.3","2.1.0","2.1.1","2.1.2","2.2.0","2.3.0-RC1","3.0.0","3.0.0-alpha01","3.0.0-alpha02","3.0.0-alpha03","3.0.0-rc01","3.0.0-rc02","3.0.0-rc03","3.0.1","3.0.2","3.0.3","3.1.0","3.2.0","3.2.1","3.2.2","3.3.0","3.3.0-alpha1","3.4.0","3.5.0","3.6.0","3.6.1","3.7.0","3.7.1","4.0.0","4.0.0-alpha.1","4.0.0-alpha.10","4.0.0-alpha.11","4.0.0-alpha.12","4.0.0-alpha.15","4.0.0-alpha.16","4.0.0-alpha.17","4.0.0-alpha.18","4.0.0-alpha.19","4.0.0-alpha.2","4.0.0-alpha.20","4.0.0-alpha.3","4.0.0-alpha.4","4.0.0-alpha.5","4.0.0-alpha.6","4.0.0-alpha.7","4.0.0-alpha.8","4.0.0-alpha.9","4.0.1","4.1.0","4.1.1","4.2.0","4.3.0","4.4.0","4.4.1","4.4.2","4.4.3","4.5.0","4.5.1","4.5.2","4.5.3","4.5.4","4.5.5","4.5.6","4.6.0","4.6.1","4.6.2","4.7.0","4.7.1","4.7.2","4.8.0","4.8.1","4.9.0","4.9.1","4.9.11","4.9.2","4.9.3","4.9.4","4.9.5","4.9.6","4.9.7","4.9.8","4.9.9","5.0.0","5.0.0-alpha01","5.0.0-alpha02","5.0.0-alpha03","5.0.0-alpha04","5.1.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/03/GHSA-pwf9-q62p-v7wc/GHSA-pwf9-q62p-v7wc.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L"}]}