Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.7%top 50%

CVE-2026-0994: CWE-674: Uncontrolled Recursion in Python Protobuf

0
High
Published: 01/23/2026 (01/23/2026, 14:55:16 UTC)
Source: GCVE Database
Vendor/Project: Python
Product: Protobuf

Description

A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages. Due to missing recursion depth accounting inside the internal Any-handling logic, an attacker can supply deeply nested Any structures that bypass the intended recursion limit, eventually exhausting Python’s recursion stack and causing a RecursionError.

CVSS v4.0

Score 8.2high

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
Present
Privileges Required
None
User Interaction
None
Vuln. Confidentiality
None
Vuln. Integrity
None
Vuln. Availability
High
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
Low
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L

Affected software

Affected versions
<=v33.4<=33.4Red HatRed Hat Enterprise LinuxRed Hat Enterprise Linux AppStream EUS (v.9.4)Red Hat CodeReady Linux Builder EUS (v.9.4)src

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/15/2026, 16:14:00 UTC

Technical Analysis

The vulnerability CVE-2026-0994 involves uncontrolled recursion in the Python Protobuf library's json_format.ParseDict() function. Specifically, the internal logic handling google.protobuf.Any messages does not account for recursion depth properly, allowing deeply nested Any messages to bypass the intended recursion limit. This leads to exhaustion of Python's recursion stack and triggers a RecursionError, causing a denial-of-service condition. The issue affects all Python Protobuf versions up to and including 33.4. Red Hat has published security advisories (RHSA-2026:3220 and RHSA-2026:3959) that include this vulnerability in their security updates.

Potential Impact

An attacker can cause a denial-of-service by supplying maliciously crafted deeply nested protobuf Any messages that bypass the recursion depth limit, leading to a RecursionError and potential application crash or service disruption. This impacts any system using vulnerable versions of Python Protobuf that parse such messages, potentially affecting availability.

Mitigation Recommendations

Red Hat has released security advisories addressing this vulnerability and recommends applying the provided updates. Users should upgrade Python Protobuf to a version later than 33.4 where this issue is resolved. Since this is not a cloud service, remediation requires updating the affected software. Patch status is not explicitly stated in the input data, so users should consult the vendor advisory for the latest patch information and apply official fixes accordingly.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:3220
Cve Count
1
Additional Cves
[]
Cvss Version
null

Threat ID: 6a20982ce29bf47b50ebd970

Added to database: 06/03/2026, 21:10:04 UTC

Last enriched: 07/15/2026, 16:14:00 UTC

Last updated: 09/07/2026, 22:52:08 UTC

Views: 154

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses