CVE-2026-104635 PUBLISHED

Uncontrolled recursion in elixir-protobuf/protobuf JSON decoding of self-referential messages

Assigner: EEF
Reserved: 08.10.2026 Published: 09.10.2026 Updated: 09.10.2026

Uncontrolled Recursion vulnerability in Protobuf.JSON.Decode in elixir-protobuf protobuf allows an unauthenticated remote attacker to crash the decoding process via a deeply nested JSON document. Any application that decodes attacker-supplied JSON with Protobuf.JSON.decode/3, Protobuf.JSON.decode!/3, or Protobuf.JSON.from_decoded/3 into a schema that contains a self-referential or cyclic message type is affected.

In lib/protobuf/json/decode.ex, the embedded-message clause of decode_singular/3 recurses into internal_from_json_data/3 once per nesting level without incrementing or checking the decoder's depth counter. The depth guard increase_depth_and_maybe_throw/1 covers only the Google.Protobuf.ListValue and Google.Protobuf.Struct clauses, so the recursion_limit option has no effect on user-defined message types. Each nesting level allocates a stack frame and heap objects, and a sufficiently deep document exhausts the memory of the decoding process. Confidentiality and integrity are not affected.

This issue affects protobuf: from 0.8.0 before 0.17.1.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.2

Product Status

Vendor elixir-protobuf
Product protobuf
Versions Default: unaffected
  • affected from 0.8.0 to 0.17.1 (excl.)
Vendor elixir-protobuf
Product protobuf
Versions Default: unaffected
  • affected from b0a1d4eaffaf50012fa71a8e931a47cf252d0370 to e9432ad1c4099511905353cebcececa3a1f7c3ff (excl.)

Affected Configurations

The application decodes attacker-controlled JSON with Protobuf.JSON.decode/3, Protobuf.JSON.decode!/3, or Protobuf.JSON.from_decoded/3 into a message type whose schema contains a self-referential or cyclic embedded message.

Workarounds

Reject JSON documents whose nesting depth exceeds a fixed bound at the web or middleware layer before passing them to the decoder. No decoder option limits recursion for user-defined message types, so the check must happen before Protobuf.JSON.decode/3, Protobuf.JSON.decode!/3, or Protobuf.JSON.from_decoded/3 is called.

Credits

  • Daniel Coles reporter
  • Daniel Coles finder
  • Andrea Leopardi remediation developer
  • Jonatan Männchen / EEF coordinator

References

Problem Types

  • CWE-674 Uncontrolled Recursion CWE

Impacts

  • An unauthenticated client that can reach an endpoint decoding JSON into a self-referential message type can crash the decoding process through stack and memory exhaustion with a single request. Repeated or concurrent requests can exhaust the memory of the whole node and disrupt co-located workloads.