{"id":"CVE-2026-0994","aliases":["GHSA-7gcm-g887-7qv7","PYSEC-2026-1805"],"url":"https://o3.security/vulnerability/CVE-2026-0994","summary":"Denial of Service in Python Protobuf","details":"A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages.\n\nDue to missing recursion depth accounting inside the internal Any-handling logic, an attacker can supply deeply nested Any structures that bypass the intended recursion limit, eventually exhausting Python’s recursion stack and causing a RecursionError.","published":"2026-01-23T14:55:16.876Z","modified":"2026-09-03T03:30:22.409734491Z","cvss":null,"epss":{"score":0.00688,"percentile":0.50861,"asOf":"2026-09-15"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"protobuf","fixedVersion":"6.33.5"},{"ecosystem":"PyPI","name":"protobuf","fixedVersion":"5.29.6"}],"fix":{"url":"https://github.com/protocolbuffers/protobuf/pull/25239","label":"protocolbuffers/protobuf#25239"},"references":[{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-0994.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:16174"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:3059"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:3094"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:3095"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:3097"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:3218"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:3219"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:3220"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:3461"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:3462"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:3958"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:3959"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:61627"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:61629"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:8746"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:8747"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:8748"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2026-0994"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/0xxx/CVE-2026-0994.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-0994"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2432398"},{"type":"FIX","url":"https://github.com/protocolbuffers/protobuf/pull/25239"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-03T03:30:22.409734491Z"}}