Skip to content

CVE for protobuff CVE-2026-0994 #18

@ChandanSouL

Description

@ChandanSouL

A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages.

Due to missing recursion depth accounting inside the internal Any-handling logic, an attacker can supply deeply nested Any structures that bypass the intended recursion limit, eventually exhausting Python’s recursion stack and causing a RecursionError.

References
https://nvd.nist.gov/vuln/detail/CVE-2026-0994
protocolbuffers/protobuf#25239
protocolbuffers/protobuf#25070

update the protobuff version to latest

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions