PT-2026-4468 · Google+4 · Google.Protobuf+4

·

CVE-2026-0994

·

Published

2026-01-01

·

Updated

2026-09-01

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions google.protobuf (affected versions not specified)
Description A denial-of-service (DoS) issue exists in the ParseDict() function within google.protobuf.json format in Python. The vulnerability occurs because the max recursion depth limit can be bypassed when parsing nested google.protobuf.Any messages. Specifically, missing recursion depth accounting within the internal Any-handling logic allows an attacker to supply deeply nested Any structures that circumvent the intended recursion limit. This can exhaust Python’s recursion stack, resulting in a RecursionError.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Uncontrolled Recursion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:3094
ALSA-2026:3095
AZL-75830
AZL-76481
AZL-76487
AZL-76505
AZL-76602
BDU:2026-05124
CLEANSTART-2026-AN24336
CLEANSTART-2026-AZ09261
CLEANSTART-2026-CO74125
CLEANSTART-2026-FU07345
CLEANSTART-2026-GR10254
CLEANSTART-2026-HP19968
CLEANSTART-2026-IR98353
CLEANSTART-2026-KE11953
CLEANSTART-2026-MR94452
CLEANSTART-2026-NL78203
CLEANSTART-2026-NM83456
CLEANSTART-2026-QE89118
CLEANSTART-2026-VV80713
CLEANSTART-2026-WQ85001
CLEANSTART-2026-WU03167
CVE-2026-0994
ECHO-1995-FF5E-CE0C
GHSA-7GCM-G887-7QV7
OESA-2026-1432
OPENSUSE-SU-2026:10515-1
OPENSUSE-SU-2026:20390-1
PYSEC-2026-1805
RHSA-2026:3059
RHSA-2026:3094
RHSA-2026:3095
RHSA-2026:3097
RHSA-2026:3218
RHSA-2026:3219
RHSA-2026:3220
RHSA-2026:3958
RHSA-2026:3959
SUSE-SU-2026:0374-1
SUSE-SU-2026:0517-1
SUSE-SU-2026:0563-1
SUSE-SU-2026:0618-1
SUSE-SU-2026:1653-1
SUSE-SU-2026:20352-1
SUSE-SU-2026:20490-1
SUSE-SU-2026:20753-1
SUSE-SU-2026:20907-1
USN-8063-1
USN-8063-2

Affected Products

Linuxmint
Red Os
Rocky Linux
Ubuntu
Google.Protobuf