Get real-time updates on Telegram
CVE-2026-104635: protobuf 0.8.0 to before 0.17.1
Affected technology
protobuf · 0.8.0 to before 0.17.1
elixir-protobuf
protobuf · b0a1d4eaffaf50012fa71a8e931a47cf252d0370 to before e9432ad1c4099511905353cebcececa3a1f7c3ff
elixir-protobuf
Component: 'Elixir.Protobuf.JSON.Decode', 'Elixir.Protobuf.JSON'
Function: 'Elixir.Protobuf.JSON.Decode':from_json_data/3, 'Elixir.Protobuf.JSON.Decode':decode_singular/3, 'Elixir.Protobuf.JSON':decode/3, 'Elixir.Protobuf.JSON':decode!/3, 'Elixir.Protobuf.JSON':from_decoded/3
File: lib/protobuf/json/decode.ex, lib/protobuf/json.ex
Attack conditions (Source advisory, CVSS 4.0): Network (remote) · No privileges required · No user interaction required
What an attacker can do
An unauthenticated remote attacker can crash the decoding process via a deeply nested JSON document. Source advisory’s CVSS 4.0 assessment (base score 8.2/10) rates confidentiality and integrity impact as none; availability impact as high.
- CWE
- CWE-674
- KEV
- no
Provenance
- NVD CVE API 2.0 · Source record · observed 2026-10-09 12:21:30.679837+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-104635.html