CVE-2026-0994

Name
CVE-2026-0994
Description
A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages. Due to missing recursion depth accounting inside the internal Any-handling logic, an attacker can supply deeply nested Any structures that bypass the intended recursion limit, eventually exhausting Python’s recursion stack and causing a RecursionError.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
cve-coordination@google.com https://github.com/protocolbuffers/protobuf/pull/25239
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:16174
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:3059
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:3094
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:3095
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:3097
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:3218
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:3219
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:3220
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:3461
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:3462
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:3958
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:3959
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:8746
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:8747
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:8748
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/security/cve/CVE-2026-0994
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://bugzilla.redhat.com/show_bug.cgi?id=2432398
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-0994.json
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:61627
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:61629

Match rules

CPE URI Source package Min version Max version
protobuf == >= V33.0 == None
cpe:2.3:a:google:protobuf:*:*:*:*:*:*:*:* protobuf >= None <= 33.4

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
protobuf edge-main 31.1-r3 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
protobuf edge-main 31.1-r2 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
protobuf edge-main 31.1-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
protobuf edge-main 31.1-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
protobuf edge-main 29.4-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
protobuf edge-main 25.6-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
protobuf edge-main 24.4-r4 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
protobuf 3.24-main 31.1-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
protobuf 3.23-main 31.1-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
protobuf 3.22-main 29.4-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
protobuf 3.21-main 24.4-r4 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
protobuf 3.20-main 24.4-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
protobuf 3.19-main 24.4-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable