Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-104635— Uncontrolled recursion in elixir-protobuf/protobuf JSON decoding of self-referential messages

Quick assessment

Affected
elixir-protobuf protobuf
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

漏洞描述: 库中的 存在不受控制的递归漏洞。未认证的远程攻击者可通过构造深层嵌套的 JSON 文档,导致 JSON 解码过程崩溃。任何使用 、 或 对攻击者提供的 JSON 进行解码,且该 JSON 映射到包含自引用或循环消息类型的 Protobuf 模式的 Elixir 应用,均受此漏洞影响。 技术细节: 在 文件中, 函数的 子句在处理每个嵌套层级时,会无条件地递归调用 ,而未递增或未检查解码器的深度计数器。尽管存在 深度保护机制,但该保护仅适用于 和 类型,对自定义消息类型无效。因此, 配置选项对用户自定义消

CVSS 8.2 · High

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-104635

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Uncontrolled recursion in elixir-protobuf/protobuf JSON decoding of self-referential messages
Source: CVE Program / CVE List V5
Vulnerability Description
Uncontrolled Recursion vulnerability in Protobuf.JSON.Decode in elixir-protobuf protobuf allows an unauthenticated remote attacker to crash the decoding process via a deeply nested JSON document. Any application that decodes attacker-supplied JSON with Protobuf.JSON.decode/3, Protobuf.JSON.decode!/3, or Protobuf.JSON.from_decoded/3 into a schema that contains a self-referential or cyclic message type is affected. In lib/protobuf/json/decode.ex, the embedded-message clause of decode_singular/3 recurses into internal_from_json_data/3 once per nesting level without incrementing or checking the decoder's depth counter. The depth guard increase_depth_and_maybe_throw/1 covers only the Google.Protobuf.ListValue and Google.Protobuf.Struct clauses, so the recursion_limit option has no effect on user-defined message types. Each nesting level allocates a stack frame and heap objects, and a sufficiently deep document exhausts the memory of the decoding process. Confidentiality and integrity are not affected. This issue affects protobuf: from 0.8.0 before 0.17.1.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
未经控制的递归
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
elixir-protobuf protobuf 0.8.0 ~ 0.17.1 cpe:2.3:a:elixir-protobuf:protobuf:*:*:*:*:*:*:*:*
elixir-protobuf protobuf b0a1d4eaffaf50012fa71a8e931a47cf252d0370 ~ e9432ad1c4099511905353cebcececa3a1f7c3ff cpe:2.3:a:elixir-protobuf:protobuf:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-104635

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-104635

请登录查看更多情报信息。

Other References for CVE-2026-104635 (4)

IV. Related Vulnerabilities

V. Comments for CVE-2026-104635

No comments yet


Leave a comment