Impact
The vulnerability arises from uncontrolled recursion in the JSON decoding routine of elixir-protobuf. When a decoder processes a JSON document that contains a deeply nested or cyclic self-referential message type, the internal recursive call stack grows without bounds. Each level consumes a stack frame and heap objects, eventually exhausting memory and crashing the decoding process. This loss of service is the primary impact; there is no direct confidentiality or integrity compromise. The weakness is identified as CWE-674 (Unchecked Input for Recursion).
Affected Systems
Any Elixir application that incorporates the elixir-protobuf protobuf library, version 0.8.0 or later, is affected. The vulnerability exists wherever Protobuf.JSON.decode/3, Protobuf.JSON.decode!/3, or Protobuf.JSON.from_decoded/3 is invoked on data that may contain user‑supplied JSON describing self‑referential or cyclic message types.
Risk and Exploitability
The CVSS score of 8.2 indicates a high severity issue. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited known exploitation but a realistic threat for exposed endpoints. The likely attack vector is an unauthenticated remote attacker delivering a deeply nested JSON document to any service that decodes JSON using the affected functions, forcing the process to crash and causing a denial‑of‑service condition. The exploit requires only the ability to send JSON to the application; no special privileges or authentication are needed.
OpenCVE Enrichment