Skip to content

Comments

Fix protobuf-javalite version to mitigate crashes#6393

Merged
TimoPtr merged 1 commit intomainfrom
fix_protobuf-javalite
Feb 5, 2026
Merged

Fix protobuf-javalite version to mitigate crashes#6393
TimoPtr merged 1 commit intomainfrom
fix_protobuf-javalite

Conversation

@TimoPtr
Copy link
Member

@TimoPtr TimoPtr commented Feb 5, 2026

Summary

We had transitive dependencies to protobuf-javalite on 3.22.3 but this version is known to have a flow that can lead to a crash of the app if a badly formed (intentionally or not) unknown field is parsed. It has been fixed in 3.25.8 and we are already using this version in the full flavor from our sentry dependency (so it mostly only impacts :wear module and minimal flavor).

This is not the latest version of protobuf-javalite (today it is 4.33.5) but we can't bump to protobuf 4 since the underlying dependencies are not yet compatible with it. I expect renovate to open a PR to bump the version but we should close it.

@TimoPtr TimoPtr merged commit 80bd1f2 into main Feb 5, 2026
22 checks passed
@TimoPtr TimoPtr deleted the fix_protobuf-javalite branch February 5, 2026 09:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant