HIGH8.6CVE-2021-3121Panic due to improper input validation in github.com/gogo/protobuf
from 0, < 1.3.2-r0
MEDIUM5.5CVE-2022-33070Protobuf-c v1.4.0 was discovered to contain an invalid arithmetic shift via the function parse_tag_and_wiretype in protobuf-c/protobuf-c.c.