Description
Uncontrolled Recursion vulnerability in Protobuf.JSON.Decode in elixir-protobuf protobuf allows an unauthenticated remote attacker to crash the decoding process via a deeply nested JSON document. Any application that decodes attacker-supplied JSON with Protobuf.JSON.decode/3, Protobuf.JSON.decode!/3, or Protobuf.JSON.from_decoded/3 into a schema that contains a self-referential or cyclic message type is affected.

In lib/protobuf/json/decode.ex, the embedded-message clause of decode_singular/3 recurses into internal_from_json_data/3 once per nesting level without incrementing or checking the decoder's depth counter. The depth guard increase_depth_and_maybe_throw/1 covers only the Google.Protobuf.ListValue and Google.Protobuf.Struct clauses, so the recursion_limit option has no effect on user-defined message types. Each nesting level allocates a stack frame and heap objects, and a sufficiently deep document exhausts the memory of the decoding process. Confidentiality and integrity are not affected.

This issue affects protobuf: from 0.8.0 before 0.17.1.
Published: 2026-10-09
Score: 8.2 High
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Apply Workaround
AI Analysis

Impact

The vulnerability arises from uncontrolled recursion in the JSON decoding routine of elixir-protobuf. When a decoder processes a JSON document that contains a deeply nested or cyclic self-referential message type, the internal recursive call stack grows without bounds. Each level consumes a stack frame and heap objects, eventually exhausting memory and crashing the decoding process. This loss of service is the primary impact; there is no direct confidentiality or integrity compromise. The weakness is identified as CWE-674 (Unchecked Input for Recursion).

Affected Systems

Any Elixir application that incorporates the elixir-protobuf protobuf library, version 0.8.0 or later, is affected. The vulnerability exists wherever Protobuf.JSON.decode/3, Protobuf.JSON.decode!/3, or Protobuf.JSON.from_decoded/3 is invoked on data that may contain user‑supplied JSON describing self‑referential or cyclic message types.

Risk and Exploitability

The CVSS score of 8.2 indicates a high severity issue. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited known exploitation but a realistic threat for exposed endpoints. The likely attack vector is an unauthenticated remote attacker delivering a deeply nested JSON document to any service that decodes JSON using the affected functions, forcing the process to crash and causing a denial‑of‑service condition. The exploit requires only the ability to send JSON to the application; no special privileges or authentication are needed.

Generated by OpenCVE AI on October 9, 2026 at 09:22 UTC.

Remediation

Vendor Workaround

Reject JSON documents whose nesting depth exceeds a fixed bound at the web or middleware layer before passing them to the decoder. No decoder option limits recursion for user-defined message types, so the check must happen before Protobuf.JSON.decode/3, Protobuf.JSON.decode!/3, or Protobuf.JSON.from_decoded/3 is called.


OpenCVE Recommended Actions

  • Check the depth of incoming JSON documents and reject any that exceed a fixed safe bound before invoking Protobuf.JSON.decode/3, Protobuf.JSON.decode!/3, or Protobuf.JSON.from_decoded/3.
  • Upgrade the elixir‑protobuf library to the latest release if it contains an official fix for the recursion guard.
  • Restrict or rate‑limit access to any endpoints that perform JSON decoding to reduce the risk of automated DoS attacks.

Generated by OpenCVE AI on October 9, 2026 at 09:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 09:30:00 +0000

Type Values Removed Values Added
Description Uncontrolled Recursion vulnerability in Protobuf.JSON.Decode in elixir-protobuf protobuf allows an unauthenticated remote attacker to crash the decoding process via a deeply nested JSON document. Any application that decodes attacker-supplied JSON with Protobuf.JSON.decode/3, Protobuf.JSON.decode!/3, or Protobuf.JSON.from_decoded/3 into a schema that contains a self-referential or cyclic message type is affected. In lib/protobuf/json/decode.ex, the embedded-message clause of decode_singular/3 recurses into internal_from_json_data/3 once per nesting level without incrementing or checking the decoder's depth counter. The depth guard increase_depth_and_maybe_throw/1 covers only the Google.Protobuf.ListValue and Google.Protobuf.Struct clauses, so the recursion_limit option has no effect on user-defined message types. Each nesting level allocates a stack frame and heap objects, and a sufficiently deep document exhausts the memory of the decoding process. Confidentiality and integrity are not affected. This issue affects protobuf: from 0.8.0 onward. Uncontrolled Recursion vulnerability in Protobuf.JSON.Decode in elixir-protobuf protobuf allows an unauthenticated remote attacker to crash the decoding process via a deeply nested JSON document. Any application that decodes attacker-supplied JSON with Protobuf.JSON.decode/3, Protobuf.JSON.decode!/3, or Protobuf.JSON.from_decoded/3 into a schema that contains a self-referential or cyclic message type is affected. In lib/protobuf/json/decode.ex, the embedded-message clause of decode_singular/3 recurses into internal_from_json_data/3 once per nesting level without incrementing or checking the decoder's depth counter. The depth guard increase_depth_and_maybe_throw/1 covers only the Google.Protobuf.ListValue and Google.Protobuf.Struct clauses, so the recursion_limit option has no effect on user-defined message types. Each nesting level allocates a stack frame and heap objects, and a sufficiently deep document exhausts the memory of the decoding process. Confidentiality and integrity are not affected. This issue affects protobuf: from 0.8.0 before 0.17.1.
References

Fri, 09 Oct 2026 08:45:00 +0000

Type Values Removed Values Added
Description Uncontrolled Recursion vulnerability in Protobuf.JSON.Decode in elixir-protobuf protobuf allows an unauthenticated remote attacker to crash the decoding process via a deeply nested JSON document. Any application that decodes attacker-supplied JSON with Protobuf.JSON.decode/3, Protobuf.JSON.decode!/3, or Protobuf.JSON.from_decoded/3 into a schema that contains a self-referential or cyclic message type is affected. In lib/protobuf/json/decode.ex, the embedded-message clause of decode_singular/3 recurses into internal_from_json_data/3 once per nesting level without incrementing or checking the decoder's depth counter. The depth guard increase_depth_and_maybe_throw/1 covers only the Google.Protobuf.ListValue and Google.Protobuf.Struct clauses, so the recursion_limit option has no effect on user-defined message types. Each nesting level allocates a stack frame and heap objects, and a sufficiently deep document exhausts the memory of the decoding process. Confidentiality and integrity are not affected. This issue affects protobuf: from 0.8.0 onward.
Title Uncontrolled recursion in elixir-protobuf/protobuf JSON decoding of self-referential messages
First Time appeared Elixir-protobuf
Elixir-protobuf protobuf
Weaknesses CWE-674
CPEs cpe:2.3:a:elixir-protobuf:protobuf:*:*:*:*:*:*:*:*
Vendors & Products Elixir-protobuf
Elixir-protobuf protobuf
References
Metrics cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Elixir-protobuf Protobuf
cve-icon MITRE

Status: PUBLISHED

Assigner: EEF

Published:

Updated: 2026-10-09T09:24:37.025Z

Reserved: 2026-10-08T14:45:01.406Z

Link: CVE-2026-104635

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T09:17:07.360

Modified: 2026-10-09T10:16:37.143

Link: CVE-2026-104635

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T09:30:03Z

Weaknesses