PT-2026-108772 · Hexpm · Elixir-Protobuf

·

CVE-2026-104635

·

Published

2026-10-09

·

Updated

2026-10-09

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions elixir-protobuf versions 0.8.0 through 0.17.0
Description An unauthenticated remote attacker can cause a crash of the decoding process by providing a deeply nested JSON document. This occurs when an application decodes attacker-supplied JSON into a schema containing a self-referential or cyclic message type using the functions Protobuf.JSON.decode/3, Protobuf.JSON.decode!/3, or Protobuf.JSON.from decoded/3.
In lib/protobuf/json/decode.ex, the embedded-message clause of the decode singular/3 function recurses into internal from json data/3 for each nesting level without incrementing or verifying the decoder's depth counter. While the increase depth and maybe throw/1 guard exists, it only applies to Google.Protobuf.ListValue and Google.Protobuf.Struct clauses, rendering the recursion limit option ineffective for user-defined message types. Consequently, each nesting level allocates a stack frame and heap objects, allowing a sufficiently deep document to exhaust the memory of the decoding process and crash it. If the BEAM max heap size process flag is set to unlimited, concurrent requests may exhaust the memory of the entire node.
Recommendations Update elixir-protobuf to version 0.17.1. As a temporary workaround, reject JSON documents whose nesting depth exceeds a fixed bound at the web or middleware layer before they are passed to the Protobuf.JSON.decode/3, Protobuf.JSON.decode!/3, or Protobuf.JSON.from decoded/3 functions.

Fix

Uncontrolled Recursion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-104635
GHSA-M497-C2H9-RVW6

Affected Products

Elixir-Protobuf