CVE-2026-104635
Received Received - Intake

Uncontrolled Recursion in Elixir Protobuf JSON Decode

Vulnerability report for CVE-2026-104635, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: EEF

Description

Uncontrolled Recursion vulnerability in Protobuf.JSON.Decode in elixir-protobuf protobuf allows an unauthenticated remote attacker to crash the decoding process via a deeply nested JSON document. Any application that decodes attacker-supplied JSON with Protobuf.JSON.decode/3, Protobuf.JSON.decode!/3, or Protobuf.JSON.from_decoded/3 into a schema that contains a self-referential or cyclic message type is affected. In lib/protobuf/json/decode.ex, the embedded-message clause of decode_singular/3 recurses into internal_from_json_data/3 once per nesting level without incrementing or checking the decoder's depth counter. The depth guard increase_depth_and_maybe_throw/1 covers only the Google.Protobuf.ListValue and Google.Protobuf.Struct clauses, so the recursion_limit option has no effect on user-defined message types. Each nesting level allocates a stack frame and heap objects, and a sufficiently deep document exhausts the memory of the decoding process. Confidentiality and integrity are not affected. This issue affects protobuf: from 0.8.0 before 0.17.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
elixir-protobuf protobuf 0.8.0
elixir-protobuf protobuf b0a1d4eaffaf50012fa71a8e931a47cf252d0370

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-674 The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an uncontrolled recursion issue in the Protobuf.JSON.Decode function of the elixir-protobuf library. It occurs when decoding deeply nested JSON documents into schemas with self-referential or cyclic message types. The decoder recurses without properly tracking or limiting recursion depth, leading to stack and memory exhaustion that crashes the process.

Detection Guidance

To detect this vulnerability, monitor for crashes in applications using elixir-protobuf's JSON decoder during JSON processing. Check for stack overflow errors or memory exhaustion in logs. Use tools like Wireshark to inspect incoming JSON payloads for excessive nesting levels. Implement logging for Protobuf.JSON.decode/3 calls to track unusually deep recursion.

Impact Analysis

An unauthenticated remote attacker can send a deeply nested JSON document to crash the decoding process, causing a denial-of-service. Sustained or concurrent requests may exhaust system resources, disrupting services. Confidentiality and integrity are not affected.

Compliance Impact

This vulnerability primarily impacts availability by causing denial-of-service through memory exhaustion, which could disrupt services handling sensitive data. While confidentiality and integrity are not directly affected, prolonged service disruption may lead to compliance violations under GDPR (e.g., data processing delays) or HIPAA (e.g., service unavailability for critical systems).

Mitigation Strategies
  • Upgrade elixir-protobuf to version 0.17.1 or later to apply the recursion depth fix.
  • Set a strict request body size limit in your web server or application to prevent large JSON payloads.
  • Implement external validation to check JSON nesting depth before decoding with Protobuf.JSON.decode/3.
  • Use a reverse proxy or WAF to filter or block excessively nested JSON requests.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104635. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart