{"id":"CVE-2020-26243","aliases":["GHSA-85rr-4rh9-hhwh","PYSEC-2026-684"],"url":"https://o3.security/vulnerability/CVE-2020-26243","summary":"Memory leak in Nanopb","details":"### Impact\nDecoding specifically formed message can leak memory if dynamic allocation is enabled and an oneof field contains a static submessage that contains a dynamic field, and the message being decoded contains the submessage multiple times. This is rare in normal messages, but it is a concern when untrusted data is parsed.\n\n### Patches\nPreliminary patch is [available on git](https://github.com/nanopb/nanopb/commit/edf6dcbffee4d614ac0c2c1b258ab95185bdb6e9) and problem will be patched in versions 0.3.9.7 and 0.4.4 once testing has been completed.\n\n### Workarounds\nFollowing workarounds are available:\n* Set the option `no_unions` for the oneof field. This will generate fields as separate instead of C union, and avoids triggering the problematic code.\n* Set the type of the submessage field inside oneof to `FT_POINTER`. This way the whole submessage will be dynamically allocated and the problematic code is not executed.\n* Use an arena allocator for nanopb, to make sure all memory can be released afterwards.\n\n### References\nBug report: https://github.com/nanopb/nanopb/issues/615\n\n### For more information\nIf you have any questions or comments about this advisory, comment on the bug report linked above.","published":"2020-11-25T17:15:12.200Z","modified":"2026-07-09T00:06:42.683716Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":{"score":0.02642,"percentile":0.84384,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"PyPI","name":"nanopb","fixedVersion":"0.3.9.7"},{"ecosystem":"PyPI","name":"nanopb","fixedVersion":"0.4.4"}],"fix":{"url":"https://github.com/nanopb/nanopb/commit/4fe23595732b6f1254cfc11a9b8d6da900b55b0c","label":"nanopb/nanopb@4fe2359"},"references":[{"type":"ADVISORY","url":"https://github.com/nanopb/nanopb/blob/2b48a361786dfb1f63d229840217a93aae064667/CHANGELOG.txt"},{"type":"ADVISORY","url":"https://github.com/nanopb/nanopb/security/advisories/GHSA-85rr-4rh9-hhwh"},{"type":"FIX","url":"https://github.com/nanopb/nanopb/commit/4fe23595732b6f1254cfc11a9b8d6da900b55b0c"},{"type":"FIX","url":"https://github.com/nanopb/nanopb/issues/615"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-26243"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T00:06:42.683716Z"}}