{"id":"CVE-2024-58103","aliases":["GHSA-pwf9-q62p-v7wc"],"url":"https://o3.security/vulnerability/CVE-2024-58103","summary":"Wire has Uncontrolled Recursion on Nested Groups","details":"Square Wire before 5.2.0 does not enforce a recursion limit on nested groups in ByteArrayProtoReader32.kt and ProtoReader.kt.","published":"2025-03-16T00:00:00Z","modified":"2026-08-08T03:48:09.463318893Z","cvss":{"score":5.8,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"com.squareup.wire:wire-runtime","fixedVersion":"5.2.0"}],"fix":{"url":"https://github.com/square/wire/commit/b90e60c09befaff836a2fc2ee4d678451b2ec75d","label":"square/wire@b90e60c"},"references":[{"type":"WEB","url":"https://github.com/square/wire/compare/5.1.0...5.2.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/58xxx/CVE-2024-58103.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-58103"},{"type":"FIX","url":"https://github.com/square/wire/commit/b90e60c09befaff836a2fc2ee4d678451b2ec75d"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-08T03:48:09.463318893Z"}}