High-Severity DoS Flaw Hits Google Protocol Buffers (CVE-2026-0994)
ID: ea254ba5-a3d6-5f99-a5c6-547a23bf9ae4
STIX ID: report--ea254ba5-a3d6-5f99-a5c6-547a23bf9ae4
Feed Name: securityonline.info
A high-severity vulnerability (CVE-2026-0994) has been identified in Google Protocol Buffers' Python JSON parser (google.protobuf.json_format.ParseDict). An implementation flaw in handling nested google.protobuf.Any messages allows attackers to bypass max_recursion_depth checks, trigger unbounded recursion and exhaust Python's recursion stack, producing a RecursionError that can crash services (Denial-of-Service). The report recommends updating parsing logic to consistently enforce recursion limits or patching _ConvertAnyMessage() to correctly increment/decrement the recursion counter.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
