CVE-2020-26243 describes a memory leak vulnerability in Nanopb, a Protocol Buffers implementation, affecting versions prior to 0.4.4 and 0.3.9.7. Specifically crafted messages can cause memory leaks when dynamic allocation is enabled and certain conditions involving oneof fields and static submessages with dynamic fields are met. This vulnerability has a CVSS score of 7.5 (High), indicating it can be exploited remotely with low attack complexity, leading to high availability impact. While there are no known public exploits, Metasploit modules, or Nuclei templates, and minimal community discussion, the issue is addressed in updated Nanopb versions and has several workarounds.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.3.9.7CPE matchmatch criteria | cpe:2.3:a:nanopb_project:nanopb:*:*:*:*:*:*:*:* | ||
>= 0.4.0, < 0.4.4CPE matchmatch criteria | cpe:2.3:a:nanopb_project:nanopb:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.