CVE-2026-45799: Kotlin Protobuf Missing Negative Length Check

A protobuf parser skipped a length-delimited group by passing an unvalidated varint length to a `skip` function. An attacker can craft a payload with a negative length, causing the skip operation to throw an unhandled exception and leading to a Denial of Service (DoS). Validate that the length is non-negative before skipping bytes.

Provally CuratedPublic repositoryHighMedium confidenceVerifiedApache-2.0Kotlin
greprules fetch cve-2026-45799-kotlin-protobuf-missing-negative-length-check --engine opengrep

Description

A protobuf parser skipped a length-delimited group by passing an unvalidated varint length to a `skip` function. An attacker can craft a payload with a negative length, causing the skip operation to throw an unhandled exception and leading to a Denial of Service (DoS). Validate that the length is non-negative before skipping bytes.