CVE-2026-0994
EUVD-2026-432223.01.2026, 15:16
A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages. Due to missing recursion depth accounting inside the internal Any-handling logic, an attacker can supply deeply nested Any structures that bypass the intended recursion limit, eventually exhausting Python’s recursion stack and causing a RecursionError.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| protobuf | 𝑥 ≤ 33.4 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| Red Hat | Red Hat Ansible Automation Platform 2.5 for RHEL 8 | 0:5.29.6-1.el8ap ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Ansible Automation Platform 2.5 for RHEL 9 | 0:5.29.6-1.el9ap ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Ansible Automation Platform 2.6 for RHEL 9 | 0:5.29.6-1.el9ap ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 10 | 0:3.19.6-15.el10_1 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 10.0 Extended Update Support | 0:3.19.6-11.el10_0.1 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 9 | 0:3.14.0-17.el9_7 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | 0:3.14.0-9.el9_0.1 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | 0:3.14.0-13.el9_2.1 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 9.4 Extended Update Support | 0:3.14.0-13.el9_4.1 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 9.6 Extended Update Support | 0:3.14.0-16.el9_6.1 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat AI Inference Server 3.2 | 1772160593 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat AI Inference Server 3.2 | 1772160625 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat AI Inference Server 3.3 | 1778244546 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat AI Inference Server 3.3 | 1775680192 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat AI Inference Server 3.3 | 1775680262 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat AI Inference Server 3.3 | 1775749857 ≤ 𝑥 < * | ADP |
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| protobuf |
|
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libprotobuf-lite20 |
| ||||||||||||||
| libprotobuf-lite25_1_0 |
| ||||||||||||||
| libprotobuf20 |
| ||||||||||||||
| libprotobuf25_1_0 |
| ||||||||||||||
| libprotoc20 |
| ||||||||||||||
| libprotoc25_1_0 |
| ||||||||||||||
| protobuf-devel |
| ||||||||||||||
| python3-protobuf |
| ||||||||||||||
| python311-protobuf |
|
Red Hat Enterprise Linux Releases
Amazon Linux Releases
Amazon Package | |||
|---|---|---|---|
| protobuf |
| ||
| protobuf-compiler |
| ||
| protobuf-compiler-debuginfo |
| ||
| protobuf-debuginfo |
| ||
| protobuf-debugsource |
| ||
| protobuf-devel |
| ||
| protobuf-emacs |
| ||
| protobuf-lite |
| ||
| protobuf-lite-debuginfo |
| ||
| protobuf-lite-devel |
| ||
| protobuf-lite-static |
| ||
| protobuf-static |
| ||
| protobuf-vim |
| ||
| python3-protobuf |
| ||
| python3-protobuf-debuginfo |
|
Azure Linux Releases
Common Weakness Enumeration
References