以下是对该漏洞描述的中文翻译: Elixir protobuf 是 Google Protobuf 的纯 Elixir 实现。在 0.8.0 至 0.16.1 版本中,如果服务使用 解码由攻击者控制的 protobuf 字节流,且 schema 中包含自引用或循环消息类型时,服务可能会陷入离线状态(即服务不可用)。在 中, 在处理 字段时,会递归进入 的调用链,但没有限制嵌套深度。深层嵌套的嵌入字段会保留大量的非尾部递归栈帧,使得相对较小的请求也能消耗大量 CPU 和内存,从而占满 BEAM 调度器,最终耗尽节点资
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| elixir-protobuf | protobuf | >= 0.8.0, < 0.16.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| elixir-protobuf | protobuf | >= 0.8.0, < 0.16.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet