Executive brief
A security vulnerability has been identified in the Python implementation of Google Protocol Buffers (Protobuf), a widely used tool for serializing and exchanging data between applications. An attacker can send specially crafted, deeply nested data structures that bypass safety limits, causing the application to crash. This results in a denial-of-service (DoS) condition, potentially disrupting business operations and service availability.
Technical details
A denial-of-service vulnerability (CWE-674) exists in the Python implementation of Google Protocol Buffers within the `google.protobuf.json_format.ParseDict()` function. The root cause is missing recursion depth accounting in the internal `Any`-handling logic; specifically, `_ConvertAnyMessage()` recursively calls itself via `methodcaller()` for nested well-known types, bypassing the intended `max_recursion_depth` limit. A remote, unauthenticated attacker can exploit this by providing deeply nested `google.protobuf.Any` structures, leading to a `RecursionError` and process crash due to stack exhaustion. A fix has been developed to route well-known type parsing through `ConvertMessage()` to ensure proper depth tracking. Red Hat has released several advisories (e.g., RHSA-2026:3059) to patch affected enterprise software.
Affected products
- Google Protobuf Python implementation prior to fix in PR 25239
- Red Hat Enterprise Linux 8, 9, 10
- Red Hat Ansible Automation Platform 2.5, 2.6
Timeline
- 2026-01-09: other: Fix submitted via GitHub Pull Request 25239
- 2026-01-23: disclosed: CVE published and fix approved
- 2026-02-23: patched: Red Hat begins releasing security updates for RHEL 9.4
References
- https://github.com/protocolbuffers/protobuf/pull/25239
- https://access.redhat.com/errata/RHSA-2026:16174
- https://access.redhat.com/errata/RHSA-2026:3059
- https://access.redhat.com/errata/RHSA-2026:3094
- https://access.redhat.com/errata/RHSA-2026:3095
- https://access.redhat.com/errata/RHSA-2026:3097
- https://access.redhat.com/errata/RHSA-2026:3218