logo

High-Severity DoS Flaw Hits Google Protocol Buffers (CVE-2026-0994)

ID: ea254ba5-a3d6-5f99-a5c6-547a23bf9ae4

STIX ID: report--ea254ba5-a3d6-5f99-a5c6-547a23bf9ae4

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-01-27

Date Updated: 2026-04-23

Author: Ddos

...
...

A high-severity vulnerability (CVE-2026-0994) has been identified in Google Protocol Buffers' Python JSON parser (google.protobuf.json_format.ParseDict). An implementation flaw in handling nested google.protobuf.Any messages allows attackers to bypass max_recursion_depth checks, trigger unbounded recursion and exhaust Python's recursion stack, producing a RecursionError that can crash services (Denial-of-Service). The report recommends updating parsing logic to consistently enforce recursion limits or patching _ConvertAnyMessage() to correctly increment/decrement the recursion counter.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.