CVE-2026-0994: CWE-674: Uncontrolled Recursion in Python Protobuf
A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages. Due to missing recursion depth accounting inside the internal Any-handling logic, an attacker can supply deeply nested Any structures that bypass the intended recursion limit, eventually exhausting Python’s recursion stack and causing a RecursionError.
AI Analysis
Technical Summary
The vulnerability CVE-2026-0994 involves uncontrolled recursion in the Python Protobuf library's json_format.ParseDict() function. Specifically, the internal logic handling google.protobuf.Any messages does not account for recursion depth properly, allowing deeply nested Any messages to bypass the intended recursion limit. This leads to exhaustion of Python's recursion stack and triggers a RecursionError, causing a denial-of-service condition. The issue affects all Python Protobuf versions up to and including 33.4. Red Hat has published security advisories (RHSA-2026:3220 and RHSA-2026:3959) that include this vulnerability in their security updates.
Potential Impact
An attacker can cause a denial-of-service by supplying maliciously crafted deeply nested protobuf Any messages that bypass the recursion depth limit, leading to a RecursionError and potential application crash or service disruption. This impacts any system using vulnerable versions of Python Protobuf that parse such messages, potentially affecting availability.
Mitigation Recommendations
Red Hat has released security advisories addressing this vulnerability and recommends applying the provided updates. Users should upgrade Python Protobuf to a version later than 33.4 where this issue is resolved. Since this is not a cloud service, remediation requires updating the affected software. Patch status is not explicitly stated in the input data, so users should consult the vendor advisory for the latest patch information and apply official fixes accordingly.
CVE-2026-0994: CWE-674: Uncontrolled Recursion in Python Protobuf
Description
A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages. Due to missing recursion depth accounting inside the internal Any-handling logic, an attacker can supply deeply nested Any structures that bypass the intended recursion limit, eventually exhausting Python’s recursion stack and causing a RecursionError.
CVSS v4.0
Score 8.2high
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability CVE-2026-0994 involves uncontrolled recursion in the Python Protobuf library's json_format.ParseDict() function. Specifically, the internal logic handling google.protobuf.Any messages does not account for recursion depth properly, allowing deeply nested Any messages to bypass the intended recursion limit. This leads to exhaustion of Python's recursion stack and triggers a RecursionError, causing a denial-of-service condition. The issue affects all Python Protobuf versions up to and including 33.4. Red Hat has published security advisories (RHSA-2026:3220 and RHSA-2026:3959) that include this vulnerability in their security updates.
Potential Impact
An attacker can cause a denial-of-service by supplying maliciously crafted deeply nested protobuf Any messages that bypass the recursion depth limit, leading to a RecursionError and potential application crash or service disruption. This impacts any system using vulnerable versions of Python Protobuf that parse such messages, potentially affecting availability.
Mitigation Recommendations
Red Hat has released security advisories addressing this vulnerability and recommends applying the provided updates. Users should upgrade Python Protobuf to a version later than 33.4 where this issue is resolved. Since this is not a cloud service, remediation requires updating the affected software. Patch status is not explicitly stated in the input data, so users should consult the vendor advisory for the latest patch information and apply official fixes accordingly.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:3220
- Cve Count
- 1
- Additional Cves
- []
- Cvss Version
- null
Threat ID: 6a20982ce29bf47b50ebd970
Added to database: 06/03/2026, 21:10:04 UTC
Last enriched: 07/15/2026, 16:14:00 UTC
Last updated: 09/07/2026, 22:52:08 UTC
Views: 154
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.