An issue was discovered in GoGo Protobuf before 1.3.2. plugin/unmarshal/unmarshal.go lacks certain index validation, aka the "skippy peanut butter" issue.
No PoCs from references.
- https://github.com/8-cm/kube-dump
- https://github.com/ARPSyndicate/cvemon
- https://github.com/De30/osv-scanner
- https://github.com/anmalkov/osv-scanner
- https://github.com/godepsresolve/gomodtrace
- https://github.com/google/osv-scanner
- https://github.com/k1LoW/oshka
- https://github.com/kyverno/policy-reporter-plugins
- https://github.com/pranavanil47/ci-cd-test-
- https://github.com/pranavanil47/snyk_workflow
- https://github.com/sonatype-nexus-community/nancy