Skip to content

Update module google.golang.org/protobuf to v1.33.0 [SECURITY] - #231

Open
red-hat-konflux[bot] wants to merge 1 commit into
mainfrom
deps-update/main/go-google.golang.org-protobuf-vulnerability
Open

Update module google.golang.org/protobuf to v1.33.0 [SECURITY]#231
red-hat-konflux[bot] wants to merge 1 commit into
mainfrom
deps-update/main/go-google.golang.org-protobuf-vulnerability

Conversation

@red-hat-konflux

@red-hat-konflux red-hat-konflux Bot commented Mar 11, 2026

Copy link
Copy Markdown

This PR contains the following updates:

Package Change Age Confidence
google.golang.org/protobuf v1.26.0v1.33.0 age confidence

Warning

Some dependencies could not be looked up. Check the warning logs for more information.


Golang protojson.Unmarshal function infinite loop when unmarshaling certain forms of invalid JSON

CVE-2024-24786 / GHSA-8r3f-844c-mc37 / GO-2024-2611

More information

Details

The protojson.Unmarshal function can enter an infinite loop when unmarshaling certain forms of invalid JSON. This condition can occur when unmarshaling into a message which contains a google.protobuf.Any value, or when the UnmarshalOptions.DiscardUnknown option is set.

Severity

  • CVSS Score: 6.6 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Infinite loop in JSON unmarshaling in google.golang.org/protobuf

CVE-2024-24786 / GHSA-8r3f-844c-mc37 / GO-2024-2611

More information

Details

The protojson.Unmarshal function can enter an infinite loop when unmarshaling certain forms of invalid JSON. This condition can occur when unmarshaling into a message which contains a google.protobuf.Any value, or when the UnmarshalOptions.DiscardUnknown option is set.

Severity

Unknown

References

This data is provided by OSV and the Go Vulnerability Database (CC-BY 4.0).


Release Notes

protocolbuffers/protobuf-go (google.golang.org/protobuf)

v1.33.0

Compare Source

This release contains one security fix:

  • encoding/protojson: Unmarshal could enter an infinite loop when unmarshaling certain forms of invalid JSON. This condition can occur when unmarshaling into a message which contains a google.protobuf.Any value, or when the UnmarshalOptions.DiscardUnknown option is set. Unmarshal now correctly returns an error when handling these inputs. This is CVE-2024-24786.

v1.32.0

Compare Source

Full Changelog: protocolbuffers/protobuf-go@v1.31.0...v1.32.0

This release contains commit bfcd647, which fixes a denial of service vulnerability by preventing a stack overflow through a default maximum recursion limit. See golang/protobuf#1583 and golang/protobuf#1584 for details.

v1.31.0

Compare Source

Notable changes

New Features

  • CL/489316: types/dynamicpb: add NewTypes
    • Add a function to construct a dynamic type registry from a protoregistry.Files
  • CL/489615: encoding: add MarshalAppend to protojson and prototext

Minor performance improvements

  • CL/491596: encoding/protodelim: If UnmarshalFrom gets a bufio.Reader, try to reuse its buffer instead of creating a new one
  • CL/500695: proto: store the size of tag to avoid multiple calculations

Bug fixes

  • CL/497935: internal/order: fix sorting of synthetic oneofs to be deterministic
  • CL/505555: encoding/protodelim: fix handling of io.EOF

v1.30.0

Compare Source

Announcement
In the previous two releases, v1.29.0 and v1.29.1, we associated the tags with the wrong commits and thus the tags do not reference any commit in this repository. This tag, v1.30.0, refers to an existing commit again. Sorry for the inconvenience.

Notable changes

New Features

  • CL/449576: protoadapt: helper functions to convert v1 or v2 message to either v1 or v2 message.

v1.29.1

Compare Source

Notable changes

Bug fixes

  • CL/475995: internal/encoding/text: fix parsing of incomplete numbers

v1.29.0

Compare Source

Overview

This version introduces a new package protodelim to marshal and unmarshal size-delimited messages.
It also brings the implementation up to date with the latest protobuf features.

Notable changes

New Features

  • CL/419254: encoding: add protodelim package
  • CL/450775: reflect/protoreflect: add Value.Equal method
  • CL/462315: cmd/protoc-gen-go: make deprecated messages more descriptive
  • CL/473015: encoding/prototext: allow whitespace and comments between minus sign and number in negative numeric literal

Alignment with protobuf

  • CL/426054: types/descriptorpb: update *.pb.go to use latest protoc release, 21.5
  • CL/425554: encoding/protojson: fix parsing of google.protobuf.Timestamp
  • CL/461238: protobuf: remove the check for reserved field numbers
  • CL/469255: types/descriptorpb: regenerate using latest protobuf v22.0 release
  • CL/472696: cmd/protoc-gen-go: support protobuf retention feature

Documentation improvements:

  • CL/464275: proto: document Equal behavior of invalid messages
  • CL/466375: all: update links to Protocol Buffer documentation

Minor performance improvements

  • CL/460215: types/known/structpb: preallocate map in AsMap
  • CL/465115: internal/strs: avoid unnecessary allocations in Builder

Breaking changes

  • CL/461238: protobuf: remove the check for reserved field numbers
    • protowire.(Number).IsValid() no longer returns false for reserved fields because reserved fields are considered semantically valid by the protobuf spec.

v1.28.1

Compare Source

This release contains protoc-gen-go binaries for arm64.

Notable changes since v1.28.0:

  • CL/418677: internal/impl: improve MessageInfo.New performance
  • CL/411377: proto: short-circuit Equal when inputs are identical
  • CL/419714: all: Add prebuild binaries for arm64

v1.28.0

Compare Source

Overview

The release provides a new unmarshal option for limiting the recursion depth when unmarshalling nested messages to prevent stack overflows. (UnmarshalOptions.RecursionLimit).

Notable changes

New features:

  • CL/340489: testing/protocmp: add Message.Unwrap

Documentation improvements:

  • CL/339569: reflect/protoreflect: add more docs on Value aliasing

Updated supported versions:

UnmarshalOption RecursionLimit
  • CL/385854: all: implement depth limit for unmarshalling

The new UnmarshalOptions.RecursionLimit limits the maximum recursion depth when unmarshalling messages. The limit is applied for nested messages. When messages are nested deeper than the specified limit the unmarshalling will fail. If unspecified, a default limit of 10,000 is applied.

In addition to the configurable limit for message nesting a non-configurable recursion limit for group nesting of 10,000 was introduced.

Upcoming breakage changes

The default recursion limit of 10,000 introduced in the release is subject to change. We want to align this limit with implementations for other languages in the long term. C++ and Java use a limit of 100 which is also the target for the Go implementation.

v1.27.1

Compare Source

Notable changes since v1.27.0:

  • CL/331149: cmd/protoc-gen-go: fix generation of enum defaults

v1.27.0

Compare Source

Overview

The release provides new functionality for iterating through a message using protobuf reflection. There are some minor changes to the code generator.

Notable changes

New features:

  • CL/309669: testing/protopack: add Message.UnmarshalAbductive

Bug fixes:

  • CL/317430: encoding/prototext: fix skipping of unknown fields
  • CL/321529: internal/impl: support typed nil source for Merge of aberrant messages

Generator changes

  • CL/305574: cmd/protoc-gen-go: remove generation of the ExtensionRangeArray method
  • CL/319649: cmd/protoc-gen-go: avoid referencing remote enum values by name
  • CL/316949: compiler/protogen: relax rules for valid import paths
  • CL/306209: cmd/protoc-gen-go: add protoc suffix
Reflectively ranging over a message
  • CL/236540: reflect: add protopath and protorange packages

The new reflect/protorange package supports recursively ranging through all populated fields of a message. There are many use cases for such a feature. See the examples for inspiration.

Upcoming breakage changes

This release removes generation of the ExtensionRangeArray method, as originally announced since the v1.20.0 release on March 2nd, 2020. Our analysis of the entire public module proxy found no static usages of this method. This method is pseudo-internal to the implementation and we expect removal of it to have no material impact. If something is broken by this change, please file an issue and we can consider re-generating this method in a patch release.

There are no new upcoming breaking changes to announce in this release.


Configuration

📅 Schedule: (in timezone UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.


Documentation

Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.

@openshift-ci

openshift-ci Bot commented Mar 11, 2026

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: red-hat-konflux[bot]

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@red-hat-konflux
red-hat-konflux Bot force-pushed the deps-update/main/go-google.golang.org-protobuf-vulnerability branch 6 times, most recently from e2ca177 to c34bf2a Compare March 11, 2026 14:28
@red-hat-konflux red-hat-konflux Bot changed the title fix(deps): update module google.golang.org/protobuf to v1.33.0 [security] Update module google.golang.org/protobuf to v1.33.0 [SECURITY] Mar 18, 2026
@red-hat-konflux red-hat-konflux Bot changed the title fix(deps): update module google.golang.org/protobuf to v1.33.0 [security] Update module google.golang.org/protobuf to v1.33.0 [SECURITY] Mar 18, 2026
@red-hat-konflux red-hat-konflux Bot changed the title fix(deps): update module google.golang.org/protobuf to v1.33.0 [security] Update module google.golang.org/protobuf to v1.33.0 [SECURITY] Mar 18, 2026
@red-hat-konflux red-hat-konflux Bot changed the title Update module google.golang.org/protobuf to v1.33.0 [SECURITY] fix(deps): update module google.golang.org/protobuf to v1.33.0 [security] Mar 26, 2026
@red-hat-konflux red-hat-konflux Bot changed the title Update module google.golang.org/protobuf to v1.33.0 [SECURITY] fix(deps): update module google.golang.org/protobuf to v1.33.0 [security] Mar 26, 2026
@red-hat-konflux red-hat-konflux Bot changed the title fix(deps): update module google.golang.org/protobuf to v1.33.0 [security] Update module google.golang.org/protobuf to v1.33.0 [SECURITY] Mar 26, 2026
@red-hat-konflux red-hat-konflux Bot changed the title Update module google.golang.org/protobuf to v1.33.0 [SECURITY] fix(deps): update module google.golang.org/protobuf to v1.33.0 [security] Apr 2, 2026
@red-hat-konflux red-hat-konflux Bot changed the title fix(deps): update module google.golang.org/protobuf to v1.33.0 [security] Update module google.golang.org/protobuf to v1.33.0 [SECURITY] Apr 3, 2026
@red-hat-konflux red-hat-konflux Bot changed the title Update module google.golang.org/protobuf to v1.33.0 [SECURITY] fix(deps): update module google.golang.org/protobuf to v1.33.0 [security] Apr 8, 2026
@red-hat-konflux red-hat-konflux Bot changed the title Update module google.golang.org/protobuf to v1.33.0 [SECURITY] fix(deps): update module google.golang.org/protobuf to v1.33.0 [security] Apr 8, 2026
@red-hat-konflux red-hat-konflux Bot changed the title fix(deps): update module google.golang.org/protobuf to v1.33.0 [security] fix(deps): update module google.golang.org/protobuf to v1.33.0 [security] - autoclosed May 3, 2026
@red-hat-konflux red-hat-konflux Bot closed this May 3, 2026
@red-hat-konflux
red-hat-konflux Bot deleted the deps-update/main/go-google.golang.org-protobuf-vulnerability branch May 3, 2026 09:12
@red-hat-konflux red-hat-konflux Bot changed the title fix(deps): update module google.golang.org/protobuf to v1.33.0 [security] - autoclosed fix(deps): update module google.golang.org/protobuf to v1.33.0 [security] May 3, 2026
@red-hat-konflux red-hat-konflux Bot reopened this May 3, 2026
@red-hat-konflux
red-hat-konflux Bot force-pushed the deps-update/main/go-google.golang.org-protobuf-vulnerability branch 7 times, most recently from c0d2028 to c34bf2a Compare May 3, 2026 13:10
@red-hat-konflux red-hat-konflux Bot reopened this May 4, 2026
@red-hat-konflux
red-hat-konflux Bot force-pushed the deps-update/main/go-google.golang.org-protobuf-vulnerability branch 14 times, most recently from f030d80 to 35a86f1 Compare May 4, 2026 09:28
@red-hat-konflux red-hat-konflux Bot changed the title fix(deps): update module google.golang.org/protobuf to v1.33.0 [security] fix(deps): update module google.golang.org/protobuf to v1.33.0 [security] - autoclosed Jun 18, 2026
@red-hat-konflux red-hat-konflux Bot closed this Jun 18, 2026
@red-hat-konflux red-hat-konflux Bot changed the title fix(deps): update module google.golang.org/protobuf to v1.33.0 [security] - autoclosed fix(deps): update module google.golang.org/protobuf to v1.33.0 [security] Jun 18, 2026
@red-hat-konflux red-hat-konflux Bot reopened this Jun 18, 2026
@red-hat-konflux
red-hat-konflux Bot force-pushed the deps-update/main/go-google.golang.org-protobuf-vulnerability branch 4 times, most recently from e95ce2f to a345e85 Compare June 18, 2026 04:38
@red-hat-konflux red-hat-konflux Bot changed the title fix(deps): update module google.golang.org/protobuf to v1.33.0 [security] fix(deps): update module google.golang.org/protobuf to v1.33.0 [security] - autoclosed Jun 21, 2026
@red-hat-konflux red-hat-konflux Bot closed this Jun 21, 2026
@red-hat-konflux red-hat-konflux Bot changed the title fix(deps): update module google.golang.org/protobuf to v1.33.0 [security] - autoclosed fix(deps): update module google.golang.org/protobuf to v1.33.0 [security] Jun 21, 2026
@red-hat-konflux red-hat-konflux Bot reopened this Jun 21, 2026
@red-hat-konflux
red-hat-konflux Bot force-pushed the deps-update/main/go-google.golang.org-protobuf-vulnerability branch 2 times, most recently from a345e85 to 252031b Compare June 21, 2026 12:53
Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants