← Vulnerability feed

Vulnerability record · CVE-2021-3121 · published 11 January 2021

CVE-2021-3121: Golang protobuf vulnerability

Golang · Protobuf

An issue was discovered in GoGo Protobuf before 1.3.2. plugin/unmarshal/unmarshal.go lacks certain index validation, aka the "skippy peanut butter" issue.

8.6 CVSS 3.1 High EPSS 3.5% · top 11.3% CWE-129 · CWE-129
8.6CVSS 3.1 base score, v2 7.5
3.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
14References
17 Jun 2026Last modified by NVD

Description

An issue was discovered in GoGo Protobuf before 1.3.2. plugin/unmarshal/unmarshal.go lacks certain index validation, aka the "skippy peanut butter" issue.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://discuss.hashicorp.com/t/hcsec-2021-23-consul-exposed-to-denial-of-service-in-gogo-protobuf-dependency/29025 Third Party Advisory
https://github.com/gogo/protobuf/commit/b03c65ea87cdc3521ede29f62fe3ce239267c1bc PatchThird Party Advisory
https://github.com/gogo/protobuf/compare/v1.3.1...v1.3.2 PatchThird Party Advisory
https://lists.apache.org/thread.html/r68032132c0399c29d6cdc7bd44918535da54060a10a12b1591328bff%40%3Cnotifications.skywal
https://lists.apache.org/thread.html/r88d69555cb74a129a7bf84838073b61259b4a3830190e05a3b87994e%40%3Ccommits.pulsar.apach
https://lists.apache.org/thread.html/rc1e9ff22c5641d73701ba56362fb867d40ed287cca000b131dcf4a44%40%3Ccommits.pulsar.apach
https://security.netapp.com/advisory/ntap-20210219-0006/ Third Party Advisory
https://discuss.hashicorp.com/t/hcsec-2021-23-consul-exposed-to-denial-of-service-in-gogo-protobuf-dependency/29025 Third Party Advisory
https://github.com/gogo/protobuf/commit/b03c65ea87cdc3521ede29f62fe3ce239267c1bc PatchThird Party Advisory
https://github.com/gogo/protobuf/compare/v1.3.1...v1.3.2 PatchThird Party Advisory
https://lists.apache.org/thread.html/r68032132c0399c29d6cdc7bd44918535da54060a10a12b1591328bff%40%3Cnotifications.skywal
https://lists.apache.org/thread.html/r88d69555cb74a129a7bf84838073b61259b4a3830190e05a3b87994e%40%3Ccommits.pulsar.apach
https://lists.apache.org/thread.html/rc1e9ff22c5641d73701ba56362fb867d40ed287cca000b131dcf4a44%40%3Ccommits.pulsar.apach
https://security.netapp.com/advisory/ntap-20210219-0006/ Third Party Advisory

Track CVE-2021-3121 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2021-41805Hashicorp consul incorrect authorization vulnerabilityHashiCorp Consul Enterprise before 1.8.17, 1.9.x before 1.9.11, and 1.10.x before 1.10.4 has Incorrect Access Control. An ACL token (with the default…EPSS 35%8.8CVE-2021-37219Hashicorp consul improper certificate validation vulnerabilityHashiCorp Consul and Consul Enterprise 1.10.1 Raft RPC layer allows non-server agents with a valid certificate signed by the same CA to access server…EPSS 1.1%8.1CVE-2023-5332Gitlab vulnerabilityPatch in third party library Consul requires 'enable-script-checks' to be set to False. This was required to enable a patch by the vendor. Without th…EPSS 0.74%8.1CVE-2019-8336Hashicorp consul vulnerabilityHashiCorp Consul (and Consul Enterprise) 1.4.x before 1.4.3 allows a client to bypass intended access restrictions and obtain the privileges of one o…EPSS 1.3%7.5CVE-2023-1297Hashicorp consul vulnerabilityConsul and Consul Enterprise's cluster peering implementation contained a flaw whereby a peer cluster with service of the same name as a local servic…EPSS 0.77%7.5CVE-2022-3920Hashicorp consul missing authorization vulnerabilityHashiCorp Consul and Consul Enterprise 1.13.0 up to 1.13.3 do not filter cluster filtering's imported nodes and services for HTTP or RPC endpoints us…EPSS 0.70%7.5CVE-2022-29153Hashicorp consul server-side request forgery (ssrf) vulnerabilityHashiCorp Consul and Consul Enterprise up to 1.9.16, 1.10.9, and 1.11.4 may allow server side request forgery when the Consul client agent follows re…EPSS 8.7%7.5CVE-2021-32574Hashicorp consul improper certificate validation vulnerabilityHashiCorp Consul and Consul Enterprise 1.3.0 through 1.10.0 Envoy proxy TLS configuration does not validate destination service identity in the encod…EPSS 1.5%

Source: NIST National Vulnerability Database (record CVE-2021-3121), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.