Uncontrolled Recursion Vulnerability in elixir-protobuf Product
CVE-2026-104635
What is CVE-2026-104635?
The elixir-protobuf library has a vulnerability in its JSON decoding mechanism that allows an unauthenticated remote attacker to cause denial-of-service conditions by utilizing deeply nested or cyclic JSON documents. The vulnerability arises from the Protobuf.JSON.Decode functions, which do not properly manage recursion depth leading to potential stack overflow and memory exhaustion. Specifically, the decode_singular function's implementation fails to adequately check the recursion limit for user-defined message types. Affected applications utilizing affected versions of this library to decode arbitrary JSON documents are at risk, making it essential for developers to review their dependency on elixir-protobuf and apply necessary mitigations.
Affected Version(s)
protobuf 0.8.0 < 0.17.1
protobuf b0a1d4eaffaf50012fa71a8e931a47cf252d0370
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
