CVE-2021-3121

HIGH

GoGo Protobuf < 1.3.2 - Denial of Service via Improper Array Index Validation

Title source: llm
STIX 2.1

Description

An issue was discovered in GoGo Protobuf before 1.3.2. plugin/unmarshal/unmarshal.go lacks certain index validation, aka the "skippy peanut butter" issue.

Scores

CVSS v3 8.6
EPSS 0.0014
EPSS Percentile 32.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H

Details

CWE
CWE-129
Status published
Products (3)
gogo/protobuf 0 - 1.3.2Go
golang/protobuf < 1.3.2
hashicorp/consul < 1.8.15 (2 CPE variants)
Published Jan 11, 2021
Tracked Since Feb 18, 2026