{"schema_version":"1.9.0","id":"CVE-2026-0994","published":"2026-01-23T14:55:16.876Z","modified":"2026-09-03T03:30:22.409734491Z","aliases":["GHSA-7gcm-g887-7qv7","PYSEC-2026-1805"],"related":["ALSA-2026:3094","ALSA-2026:3095","CGA-jgjc-r94m-fgp2","SUSE-SU-2026:0374-1","SUSE-SU-2026:0517-1","SUSE-SU-2026:0563-1","SUSE-SU-2026:0618-1","SUSE-SU-2026:1653-1","SUSE-SU-2026:20352-1","SUSE-SU-2026:20490-1","SUSE-SU-2026:20753-1","SUSE-SU-2026:20907-1","openSUSE-SU-2026:10515-1","openSUSE-SU-2026:20390-1"],"summary":"Denial of Service in Python Protobuf","details":"A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages.\n\nDue to missing recursion depth accounting inside the internal Any-handling logic, an attacker can supply deeply nested Any structures that bypass the intended recursion limit, eventually exhausting Python’s recursion stack and causing a RecursionError.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/protocolbuffers/protobuf","events":[{"introduced":"0"},{"last_affected":"edaa823d8b36a8656d7b2b9241b7d0bfe50af878"}],"database_specific":{"cpe":"cpe:2.3:a:google:protobuf:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"v33.4"},{"last_affected":"33.4"}],"source":["AFFECTED_FIELD","CPE_RANGE"]}}],"versions":["v27-dev","v26-dev","v28-dev","v4.33.4-objectivec","v33.4","v33-dev","v4.33.0-rc1-objectivec","v33.0-rc1","v32-dev","v31-dev","rust-prerelease-4.31.0-beta1","v30-dev","rust-prerelease-4.30.0-beta1","v29-dev","v3.20.0-rc2","v3.12.3","v3.0.0-beta-3-pre-1","v3.0.0-beta-2","v3.0.0-beta-1-bzl-fix","v3.0.0-beta-1","v3.0.0-alpha-4","v3.0.0-alpha-3","v2.6.1rc1","v2.6.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-0994.json"}}],"references":[{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-0994.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:16174"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:3059"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:3094"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:3095"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:3097"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:3218"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:3219"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:3220"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:3461"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:3462"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:3958"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:3959"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:61627"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:61629"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:8746"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:8747"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:8748"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2026-0994"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/0xxx/CVE-2026-0994.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-0994"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2432398"},{"type":"FIX","url":"https://github.com/protocolbuffers/protobuf/pull/25239"}],"database_specific":{"cna_assigner":"Google","cwe_ids":["CWE-674"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/0xxx/CVE-2026-0994.json"},"severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L"}]}