PT-2026-108772 · Hexpm · Elixir-Protobuf
CVSS v4.0
8.2
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
elixir-protobuf versions 0.8.0 through 0.17.0
Description
An unauthenticated remote attacker can cause a crash of the decoding process by providing a deeply nested JSON document. This occurs when an application decodes attacker-supplied JSON into a schema containing a self-referential or cyclic message type using the functions
Protobuf.JSON.decode/3, Protobuf.JSON.decode!/3, or Protobuf.JSON.from decoded/3.In
lib/protobuf/json/decode.ex, the embedded-message clause of the decode singular/3 function recurses into internal from json data/3 for each nesting level without incrementing or verifying the decoder's depth counter. While the increase depth and maybe throw/1 guard exists, it only applies to Google.Protobuf.ListValue and Google.Protobuf.Struct clauses, rendering the recursion limit option ineffective for user-defined message types. Consequently, each nesting level allocates a stack frame and heap objects, allowing a sufficiently deep document to exhaust the memory of the decoding process and crash it. If the BEAM max heap size process flag is set to unlimited, concurrent requests may exhaust the memory of the entire node.Recommendations
Update elixir-protobuf to version 0.17.1.
As a temporary workaround, reject JSON documents whose nesting depth exceeds a fixed bound at the web or middleware layer before they are passed to the
Protobuf.JSON.decode/3, Protobuf.JSON.decode!/3, or Protobuf.JSON.from decoded/3 functions.Fix
Uncontrolled Recursion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Elixir-Protobuf