{"containers":{"cna":{"affected":[{"collectionURL":"https://repo.hex.pm","cpes":["cpe:2.3:a:elixir-protobuf:protobuf:*:*:*:*:*:*:*:*"],"defaultStatus":"unaffected","modules":["'Elixir.Protobuf.JSON.Decode'","'Elixir.Protobuf.JSON'"],"packageName":"protobuf","packageURL":"pkg:hex/protobuf","product":"protobuf","programFiles":["lib/protobuf/json/decode.ex","lib/protobuf/json.ex"],"programRoutines":[{"name":"'Elixir.Protobuf.JSON.Decode':from_json_data/3"},{"name":"'Elixir.Protobuf.JSON.Decode':decode_singular/3"},{"name":"'Elixir.Protobuf.JSON':decode/3"},{"name":"'Elixir.Protobuf.JSON':decode!/3"},{"name":"'Elixir.Protobuf.JSON':from_decoded/3"}],"repo":"https://github.com/elixir-protobuf/protobuf","vendor":"elixir-protobuf","versions":[{"lessThan":"0.17.1","status":"affected","version":"0.8.0","versionType":"semver"}]},{"collectionURL":"https://github.com","cpes":["cpe:2.3:a:elixir-protobuf:protobuf:*:*:*:*:*:*:*:*"],"defaultStatus":"unaffected","modules":["'Elixir.Protobuf.JSON.Decode'","'Elixir.Protobuf.JSON'"],"packageName":"elixir-protobuf/protobuf","packageURL":"pkg:github/elixir-protobuf/protobuf","product":"protobuf","programFiles":["lib/protobuf/json/decode.ex","lib/protobuf/json.ex"],"programRoutines":[{"name":"'Elixir.Protobuf.JSON.Decode':from_json_data/3"},{"name":"'Elixir.Protobuf.JSON.Decode':decode_singular/3"},{"name":"'Elixir.Protobuf.JSON':decode/3"},{"name":"'Elixir.Protobuf.JSON':decode!/3"},{"name":"'Elixir.Protobuf.JSON':from_decoded/3"}],"repo":"https://github.com/elixir-protobuf/protobuf","vendor":"elixir-protobuf","versions":[{"lessThan":"e9432ad1c4099511905353cebcececa3a1f7c3ff","status":"affected","version":"b0a1d4eaffaf50012fa71a8e931a47cf252d0370","versionType":"git"}]}],"configurations":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>The application decodes attacker-controlled JSON with <code>Protobuf.JSON.decode/3</code>, <code>Protobuf.JSON.decode!/3</code>, or <code>Protobuf.JSON.from_decoded/3</code> into a message type whose schema contains a self-referential or cyclic embedded message.</p>"},{"base64":false,"type":"text/markdown","value":"The application decodes attacker-controlled JSON with `Protobuf.JSON.decode/3`, `Protobuf.JSON.decode!/3`, or `Protobuf.JSON.from_decoded/3` into a message type whose schema contains a self-referential or cyclic embedded message."}],"value":"The application decodes attacker-controlled JSON with Protobuf.JSON.decode/3, Protobuf.JSON.decode!/3, or Protobuf.JSON.from_decoded/3 into a message type whose schema contains a self-referential or cyclic embedded message."}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:a:elixir-protobuf:protobuf:*:*:*:*:*:*:*:*","versionEndExcluding":"0.17.1","versionStartIncluding":"0.8.0","vulnerable":true}],"negate":false,"operator":"OR"}],"operator":"AND"}],"credits":[{"lang":"en","type":"reporter","value":"Daniel Coles"},{"lang":"en","type":"finder","value":"Daniel Coles"},{"lang":"en","type":"remediation developer","value":"Andrea Leopardi"},{"lang":"en","type":"coordinator","value":"Jonatan Männchen / EEF"}],"dateAssigned":"2026-10-08T15:40:42.000Z","datePublic":"2026-10-09T08:17:52.000Z","descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Uncontrolled Recursion vulnerability in <code>Protobuf.JSON.Decode</code> in elixir-protobuf protobuf allows an unauthenticated remote attacker to crash the decoding process via a deeply nested JSON document. Any application that decodes attacker-supplied JSON with <code>Protobuf.JSON.decode/3</code>, <code>Protobuf.JSON.decode!/3</code>, or <code>Protobuf.JSON.from_decoded/3</code> into a schema that contains a self-referential or cyclic message type is affected.</p>\n<p>In <code>lib/protobuf/json/decode.ex</code>, the embedded-message clause of <code>decode_singular/3</code> recurses into <code>internal_from_json_data/3</code> once per nesting level without incrementing or checking the decoder's depth counter. The depth guard <code>increase_depth_and_maybe_throw/1</code> covers only the <code>Google.Protobuf.ListValue</code> and <code>Google.Protobuf.Struct</code> clauses, so the <code>recursion_limit</code> option has no effect on user-defined message types. Each nesting level allocates a stack frame and heap objects, and a sufficiently deep document exhausts the memory of the decoding process. Confidentiality and integrity are not affected.</p>\n<p>This issue affects protobuf: from 0.8.0 before 0.17.1.</p>"},{"base64":false,"type":"text/markdown","value":"Uncontrolled Recursion vulnerability in `Protobuf.JSON.Decode` in elixir-protobuf protobuf allows an unauthenticated remote attacker to crash the decoding process via a deeply nested JSON document. Any application that decodes attacker-supplied JSON with `Protobuf.JSON.decode/3`, `Protobuf.JSON.decode!/3`, or `Protobuf.JSON.from_decoded/3` into a schema that contains a self-referential or cyclic message type is affected.\n\nIn `lib/protobuf/json/decode.ex`, the embedded-message clause of `decode_singular/3` recurses into `internal_from_json_data/3` once per nesting level without incrementing or checking the decoder's depth counter. The depth guard `increase_depth_and_maybe_throw/1` covers only the `Google.Protobuf.ListValue` and `Google.Protobuf.Struct` clauses, so the `recursion_limit` option has no effect on user-defined message types. Each nesting level allocates a stack frame and heap objects, and a sufficiently deep document exhausts the memory of the decoding process. Confidentiality and integrity are not affected.\n\nThis issue affects protobuf: from 0.8.0 before 0.17.1."}],"value":"Uncontrolled Recursion vulnerability in Protobuf.JSON.Decode in elixir-protobuf protobuf allows an unauthenticated remote attacker to crash the decoding process via a deeply nested JSON document. Any application that decodes attacker-supplied JSON with Protobuf.JSON.decode/3, Protobuf.JSON.decode!/3, or Protobuf.JSON.from_decoded/3 into a schema that contains a self-referential or cyclic message type is affected.\n\nIn lib/protobuf/json/decode.ex, the embedded-message clause of decode_singular/3 recurses into internal_from_json_data/3 once per nesting level without incrementing or checking the decoder's depth counter. The depth guard increase_depth_and_maybe_throw/1 covers only the Google.Protobuf.ListValue and Google.Protobuf.Struct clauses, so the recursion_limit option has no effect on user-defined message types. Each nesting level allocates a stack frame and heap objects, and a sufficiently deep document exhausts the memory of the decoding process. Confidentiality and integrity are not affected.\n\nThis issue affects protobuf: from 0.8.0 before 0.17.1."}],"impacts":[{"capecId":"CAPEC-230","descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>An unauthenticated client that can reach an endpoint decoding JSON into a self-referential message type can crash the decoding process through stack and memory exhaustion with a single request. Repeated or concurrent requests can exhaust the memory of the whole node and disrupt co-located workloads.</p>"},{"base64":false,"type":"text/markdown","value":"An unauthenticated client that can reach an endpoint decoding JSON into a self-referential message type can crash the decoding process through stack and memory exhaustion with a single request. Repeated or concurrent requests can exhaust the memory of the whole node and disrupt co-located workloads."}],"value":"An unauthenticated client that can reach an endpoint decoding JSON into a self-referential message type can crash the decoding process through stack and memory exhaustion with a single request. Repeated or concurrent requests can exhaust the memory of the whole node and disrupt co-located workloads."}]}],"metrics":[{"cvssV4_0":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"PRESENT","attackVector":"NETWORK","baseScore":8.2,"baseSeverity":"HIGH","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnerabilityResponseEffort":"NOT_DEFINED"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-674","description":"CWE-674 Uncontrolled Recursion","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-10-09T09:24:37.025Z","orgId":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db","shortName":"EEF"},"references":[{"name":"GitHub Advisory","tags":["related","vendor-advisory"],"url":"https://github.com/elixir-protobuf/protobuf/security/advisories/GHSA-m497-c2h9-rvw6"},{"name":"EEF CNA record for CVE-2026-104635","tags":["related"],"url":"https://cna.erlef.org/cves/CVE-2026-104635.html"},{"name":"OSV record EEF-CVE-2026-104635","tags":["related"],"url":"https://osv.dev/vulnerability/EEF-CVE-2026-104635"},{"name":"Introducing commit b0a1d4e in elixir-protobuf/protobuf","tags":["related"],"url":"https://github.com/elixir-protobuf/protobuf/commit/b0a1d4eaffaf50012fa71a8e931a47cf252d0370"},{"name":"Fix commit e9432ad in elixir-protobuf/protobuf","tags":["patch"],"url":"https://github.com/elixir-protobuf/protobuf/commit/e9432ad1c4099511905353cebcececa3a1f7c3ff"}],"source":{"discovery":"EXTERNAL"},"title":"Uncontrolled recursion in elixir-protobuf/protobuf JSON decoding of self-referential messages","workarounds":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Reject JSON documents whose nesting depth exceeds a fixed bound at the web or middleware layer before passing them to the decoder. No decoder option limits recursion for user-defined message types, so the check must happen before <code>Protobuf.JSON.decode/3</code>, <code>Protobuf.JSON.decode!/3</code>, or <code>Protobuf.JSON.from_decoded/3</code> is called.</p>"},{"base64":false,"type":"text/markdown","value":"Reject JSON documents whose nesting depth exceeds a fixed bound at the web or middleware layer before passing them to the decoder. No decoder option limits recursion for user-defined message types, so the check must happen before `Protobuf.JSON.decode/3`, `Protobuf.JSON.decode!/3`, or `Protobuf.JSON.from_decoded/3` is called."}],"value":"Reject JSON documents whose nesting depth exceeds a fixed bound at the web or middleware layer before passing them to the decoder. No decoder option limits recursion for user-defined message types, so the check must happen before Protobuf.JSON.decode/3, Protobuf.JSON.decode!/3, or Protobuf.JSON.from_decoded/3 is called."}],"x_proofOfConcept":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<ol>\n<li>Define and compile a self-referential proto3 message, for example a <code>TreeNode</code> message with a single embedded field <code>child</code> of type <code>TreeNode</code>.</li>\n<li>Build a JSON document that nests the <code>child</code> field several thousand levels deep, for example by wrapping <code>{}</code> in <code>{\"child\": ...}</code> 5,000 times.</li>\n<li>Decode it with <code>Protobuf.JSON.decode(json, TreeNode, recursion_limit: 100)</code>.</li>\n<li>Observe that no <code>Protobuf.JSON.DecodeError</code> for an exceeded recursion limit is raised and the decoder walks every level. The same depth in a <code>Google.Protobuf.Struct</code> payload raises <code>{:recursion_limit_exceeded, 100}</code>. At larger depths the decoding process consumes hundreds of megabytes and crashes with stack and heap exhaustion.</li>\n</ol>"},{"base64":false,"type":"text/markdown","value":"1. Define and compile a self-referential proto3 message, for example a `TreeNode` message with a single embedded field `child` of type `TreeNode`.\n2. Build a JSON document that nests the `child` field several thousand levels deep, for example by wrapping `{}` in `{\"child\": ...}` 5,000 times.\n3. Decode it with `Protobuf.JSON.decode(json, TreeNode, recursion_limit: 100)`.\n4. Observe that no `Protobuf.JSON.DecodeError` for an exceeded recursion limit is raised and the decoder walks every level. The same depth in a `Google.Protobuf.Struct` payload raises `{:recursion_limit_exceeded, 100}`. At larger depths the decoding process consumes hundreds of megabytes and crashes with stack and heap exhaustion."}],"value":"* Define and compile a self-referential proto3 message, for example a TreeNode message with a single embedded field child of type TreeNode.\n* Build a JSON document that nests the child field several thousand levels deep, for example by wrapping {} in {\"child\": ...} 5,000 times.\n* Decode it with Protobuf.JSON.decode(json, TreeNode, recursion_limit: 100).\n* Observe that no Protobuf.JSON.DecodeError for an exceeded recursion limit is raised and the decoder walks every level. The same depth in a Google.Protobuf.Struct payload raises {:recursion_limit_exceeded, 100}. At larger depths the decoding process consumes hundreds of megabytes and crashes with stack and heap exhaustion."}],"x_technicalAnalysis":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p><strong>1. Entry points.</strong> <code>Protobuf.JSON.decode/3</code>, <code>Protobuf.JSON.decode!/3</code>, and <code>Protobuf.JSON.from_decoded/3</code> in <code>lib/protobuf/json.ex</code> validate options and call <code>Protobuf.JSON.Decode.from_json_data/3</code>, which builds a <code>state</code> map carrying <code>depth: 0</code> and the <code>recursion_limit</code> (default 100). <code>from_decoded/3</code> accepts already-parsed data, so the underlying JSON parser never bounds the depth either.</p>\n<p><strong>2. Unguarded recursion.</strong> For a user-defined message module, <code>internal_from_json_data/3</code> calls <code>decode_message/4</code>, which calls <code>decode_regular_fields/3</code> and <code>decode_oneof_fields/3</code>. Each field value passes through <code>decode_value/3</code> and, for a singular embedded message, reaches the <code>decode_singular/3</code> clause matching <code>embedded?: true</code>. That clause calls <code>internal_from_json_data/3</code> with <code>state</code> unchanged, so <code>state.depth</code> stays at 0 at every nesting level. Repeated fields and map values reach the same clause through <code>decode_repeated/3</code> and <code>decode_map/3</code>.</p>\n<p><strong>3. Guard coverage.</strong> <code>increase_depth_and_maybe_throw/1</code> increments <code>depth</code> and throws <code>{:recursion_limit_exceeded, limit}</code> when it exceeds the limit. It is called only from the <code>Google.Protobuf.ListValue</code> and <code>Google.Protobuf.Struct</code> clauses, which the <code>Google.Protobuf.Value</code> clause delegates to. The <code>recursion_limit</code> documentation scopes the option to those wrappers, and no other path checks depth.</p>\n<p><strong>4. Result.</strong> A self-referential schema such as a <code>Tree</code> message with a <code>Tree child</code> field recurses once per JSON nesting level with no bound. Each level holds a live stack frame and allocates heap objects, so a sufficiently deep document exhausts the memory of the decoding process and crashes it. The BEAM <code>max_heap_size</code> process flag defaults to unlimited, so repeated or concurrent requests can exhaust the memory of the whole node.</p>"},{"base64":false,"type":"text/markdown","value":"**1. Entry points.** `Protobuf.JSON.decode/3`, `Protobuf.JSON.decode!/3`, and `Protobuf.JSON.from_decoded/3` in `lib/protobuf/json.ex` validate options and call `Protobuf.JSON.Decode.from_json_data/3`, which builds a `state` map carrying `depth: 0` and the `recursion_limit` (default 100). `from_decoded/3` accepts already-parsed data, so the underlying JSON parser never bounds the depth either.\n\n**2. Unguarded recursion.** For a user-defined message module, `internal_from_json_data/3` calls `decode_message/4`, which calls `decode_regular_fields/3` and `decode_oneof_fields/3`. Each field value passes through `decode_value/3` and, for a singular embedded message, reaches the `decode_singular/3` clause matching `embedded?: true`. That clause calls `internal_from_json_data/3` with `state` unchanged, so `state.depth` stays at 0 at every nesting level. Repeated fields and map values reach the same clause through `decode_repeated/3` and `decode_map/3`.\n\n**3. Guard coverage.** `increase_depth_and_maybe_throw/1` increments `depth` and throws `{:recursion_limit_exceeded, limit}` when it exceeds the limit. It is called only from the `Google.Protobuf.ListValue` and `Google.Protobuf.Struct` clauses, which the `Google.Protobuf.Value` clause delegates to. The `recursion_limit` documentation scopes the option to those wrappers, and no other path checks depth.\n\n**4. Result.** A self-referential schema such as a `Tree` message with a `Tree child` field recurses once per JSON nesting level with no bound. Each level holds a live stack frame and allocates heap objects, so a sufficiently deep document exhausts the memory of the decoding process and crashes it. The BEAM `max_heap_size` process flag defaults to unlimited, so repeated or concurrent requests can exhaust the memory of the whole node."}],"value":"1. Entry points. Protobuf.JSON.decode/3, Protobuf.JSON.decode!/3, and Protobuf.JSON.from_decoded/3 in lib/protobuf/json.ex validate options and call Protobuf.JSON.Decode.from_json_data/3, which builds a state map carrying depth: 0 and the recursion_limit (default 100). from_decoded/3 accepts already-parsed data, so the underlying JSON parser never bounds the depth either.\n\n2. Unguarded recursion. For a user-defined message module, internal_from_json_data/3 calls decode_message/4, which calls decode_regular_fields/3 and decode_oneof_fields/3. Each field value passes through decode_value/3 and, for a singular embedded message, reaches the decode_singular/3 clause matching embedded?: true. That clause calls internal_from_json_data/3 with state unchanged, so state.depth stays at 0 at every nesting level. Repeated fields and map values reach the same clause through decode_repeated/3 and decode_map/3.\n\n3. Guard coverage. increase_depth_and_maybe_throw/1 increments depth and throws {:recursion_limit_exceeded, limit} when it exceeds the limit. It is called only from the Google.Protobuf.ListValue and Google.Protobuf.Struct clauses, which the Google.Protobuf.Value clause delegates to. The recursion_limit documentation scopes the option to those wrappers, and no other path checks depth.\n\n4. Result. A self-referential schema such as a Tree message with a Tree child field recurses once per JSON nesting level with no bound. Each level holds a live stack frame and allocates heap objects, so a sufficiently deep document exhausts the memory of the decoding process and crashes it. The BEAM max_heap_size process flag defaults to unlimited, so repeated or concurrent requests can exhaust the memory of the whole node."}]}},"cveMetadata":{"assignerOrgId":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db","assignerShortName":"EEF","cveId":"CVE-2026-104635","datePublished":"2026-10-09T08:17:52.372Z","dateReserved":"2026-10-08T14:45:01.406Z","dateUpdated":"2026-10-09T09:24:37.025Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"}