CYBER CODE RED

Get real-time updates on Telegram

Verified

CVE-2026-104635: protobuf 0.8.0 to before 0.17.1

Affected technology

protobuf · 0.8.0 to before 0.17.1
elixir-protobuf

protobuf · b0a1d4eaffaf50012fa71a8e931a47cf252d0370 to before e9432ad1c4099511905353cebcececa3a1f7c3ff
elixir-protobuf

Component: 'Elixir.Protobuf.JSON.Decode', 'Elixir.Protobuf.JSON'
Function: 'Elixir.Protobuf.JSON.Decode':from_json_data/3, 'Elixir.Protobuf.JSON.Decode':decode_singular/3, 'Elixir.Protobuf.JSON':decode/3, 'Elixir.Protobuf.JSON':decode!/3, 'Elixir.Protobuf.JSON':from_decoded/3
File: lib/protobuf/json/decode.ex, lib/protobuf/json.ex

Attack conditions (Source advisory, CVSS 4.0): Network (remote) · No privileges required · No user interaction required

What an attacker can do

An unauthenticated remote attacker can crash the decoding process via a deeply nested JSON document. Source advisory’s CVSS 4.0 assessment (base score 8.2/10) rates confidentiality and integrity impact as none; availability impact as high.

Published

CWE
CWE-674
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-104635.html