Denial of Service in Elixir Protobuf Implementation by Elixir
CVE-2026-54451
8.2HIGH
What is CVE-2026-54451?
A vulnerability in the Elixir Protobuf implementation allows an attacker to cause a Denial of Service by sending specially crafted protobuf bytes. This occurs when services decode these bytes using the Protobuf.Decoder in versions ranging from 0.8.0 to 0.16.1. The issue arises from the lack of a nesting-depth limit when handling self-referential or cyclic message types, leading to excessive CPU and memory consumption. As a result, a relatively small request can disrupt service by exhausting system resources and pinning the BEAM scheduler. This vulnerability has been addressed in version 0.16.1.
Affected Version(s)
protobuf >= 0.8.0, < 0.16.1
