{"id":"CVE-2026-45799","aliases":["GHSA-7xpr-hc2w-34m9"],"url":"https://o3.security/vulnerability/CVE-2026-45799","summary":"Wire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wire-decoding service","details":"Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.3.0 and 7.0.0-alpha03, ByteArrayProtoReader32.skipGroup() and ProtoReader.skipGroup() in wire-runtime do not validate that a LENGTH_DELIMITED field length is non-negative before skip(), allowing a crafted protobuf varint encoding -128 as a signed Int to make skip(-128) move the internal position negative and make the next readByte() throw ArrayIndexOutOfBoundsException instead of the documented IOException or ProtocolException, which can crash services using ProtoAdapter.decode(byte[]) on untrusted payloads. This issue is fixed in versions 6.3.0 and 7.0.0-alpha03.","published":"2026-07-17T19:49:30.331Z","modified":"2026-08-14T04:03:46.200438858Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":{"score":0.00546,"percentile":0.43197,"asOf":"2026-08-15"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"com.squareup.wire:wire-runtime-jvm","fixedVersion":"6.3.0"},{"ecosystem":"Maven","name":"com.squareup.wire:wire-runtime","fixedVersion":"6.3.0"},{"ecosystem":"Maven","name":"com.squareup.wire:wire-runtime","fixedVersion":"7.0.0-alpha03"},{"ecosystem":"Maven","name":"com.squareup.wire:wire-runtime-jvm","fixedVersion":"7.0.0-alpha03"}],"fix":{"url":"https://github.com/square/wire/commit/47d5b0dba53935d5332cd41a80a353b3fc90e7b0","label":"square/wire@47d5b0d"},"references":[{"type":"WEB","url":"https://github.com/square/wire/releases/tag/6.3.0"},{"type":"WEB","url":"https://github.com/square/wire/releases/tag/7.0.0-alpha03"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45799.json"},{"type":"ADVISORY","url":"https://github.com/square/wire/security/advisories/GHSA-7xpr-hc2w-34m9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45799"},{"type":"FIX","url":"https://github.com/square/wire/commit/47d5b0dba53935d5332cd41a80a353b3fc90e7b0"},{"type":"FIX","url":"https://github.com/square/wire/commit/e4e56fab38a547d9625f05c97f1d8f0bcc3a5773"},{"type":"FIX","url":"https://github.com/square/wire/pull/3595"},{"type":"FIX","url":"https://github.com/square/wire/pull/3597"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-14T04:03:46.200438858Z"}}