Denial of Service in Elixir Protobuf Implementation by Elixir
CVE-2026-54451

8.2HIGH

Key Information:

Status
Vendor
CVE Published:
17 September 2026

What is CVE-2026-54451?

A vulnerability in the Elixir Protobuf implementation allows an attacker to cause a Denial of Service by sending specially crafted protobuf bytes. This occurs when services decode these bytes using the Protobuf.Decoder in versions ranging from 0.8.0 to 0.16.1. The issue arises from the lack of a nesting-depth limit when handling self-referential or cyclic message types, leading to excessive CPU and memory consumption. As a result, a relatively small request can disrupt service by exhausting system resources and pinning the BEAM scheduler. This vulnerability has been addressed in version 0.16.1.

Affected Version(s)

protobuf >= 0.8.0, < 0.16.1

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.