Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-0994

33
FAUCET Score

CVE-2026-0994 is a denial-of-service (DoS) vulnerability affecting the google.protobuf.json_format.ParseDict() function in Python. It allows an attacker to bypass the intended recursion depth limit by supplying deeply nested google.protobuf.Any messages, leading to a Python RecursionError and application crash. This vulnerability has a CVSS score of 8.2 (HIGH) due to its network-based attack vector, low attack complexity, and high impact on availability. While there is no evidence of active exploitation or publicly available exploit code, the vulnerability has garnered significant community discussion, indicating awareness and potential future interest.

Impacted Technologies

VendorProductVersion(s)CPE
<= 33.4CPE matchmatch criteria
cpe:2.3:a:google:protobuf:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

8.2HIGH

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
PRESENT
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
NONE
VS Integrity
NONE
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
LOW
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.66%
Probability of exploitation in next 30 days
EPSS Percentile
47.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0066 is in the 24th percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (18)

github_advisorypatch availablevia nvd_reference
View patch
pippatch availablevia ghsa
Product: protobufFixed in: 5.29.6
pippatch availablevia ghsa
Product: protobufFixed in: 6.33.5
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 10.0 Extended Update SupportFixed in: protobuf-0:3.19.6-11.el10_0.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: protobuf-0:3.14.0-17.el9_7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsFixed in: protobuf-0:3.14.0-9.el9_0.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsFixed in: protobuf-0:3.14.0-13.el9_2.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.4 Extended Update SupportFixed in: protobuf-0:3.14.0-13.el9_4.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.6 Extended Update SupportFixed in: protobuf-0:3.14.0-16.el9_6.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: protobuf-0:3.19.6-15.el10_1
View patch
ubuntupatch availablevia ubuntu_usn
Product: protobuf (bionic)Fixed in: 3.0.0-9.1ubuntu1.1+esm4
ubuntupatch availablevia ubuntu_usn
Product: protobuf (focal)Fixed in: 3.6.1.3-2ubuntu5.2+esm3
ubuntupatch availablevia ubuntu_usn
Product: protobuf (jammy)Fixed in: 3.12.4-1ubuntu7.22.04.6
ubuntupatch availablevia ubuntu_usn
Product: protobuf (noble)Fixed in: 3.21.12-8.2ubuntu0.3
ubuntupatch availablevia ubuntu_usn
Product: protobuf (questing)Fixed in: 3.21.12-11ubuntu3.1
redhatno patchvia redhat_api
Product: AMQ ClientsFixed in: protobuf
redhatno patchvia redhat_api
Product: Red Hat OpenStack Platform 16.2Fixed in: protobuf
redhatno patchvia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: python3.11-protobuf

Vendor Advisories (4)

ubuntuUSN-8063-2

Protocol Buffers vulnerability

May 26, 2026
ubuntuUSN-8063-1

Protocol Buffers vulnerability

Feb 25, 2026
pipGHSA-7gcm-g887-7qv7high

protobuf affected by a JSON recursion depth bypass

Jan 23, 2026
redhatCVE-2026-0994Important

python: protobuf: Protobuf: Denial of Service due to recursion depth bypass

Jan 23, 2026

References

access.redhat.com / errata/RHSA-2026:16174
access.redhat.com / errata/RHSA-2026:3059
access.redhat.com / errata/RHSA-2026:3094
access.redhat.com / errata/RHSA-2026:3095
access.redhat.com / errata/RHSA-2026:3097
access.redhat.com / errata/RHSA-2026:3218
access.redhat.com / errata/RHSA-2026:3219
access.redhat.com / errata/RHSA-2026:3220
access.redhat.com / errata/RHSA-2026:3461
access.redhat.com / errata/RHSA-2026:3462
access.redhat.com / errata/RHSA-2026:3958
access.redhat.com / errata/RHSA-2026:3959
access.redhat.com / errata/RHSA-2026:8746
access.redhat.com / errata/RHSA-2026:8747
access.redhat.com / errata/RHSA-2026:8748
access.redhat.com / security/cve/CVE-2026-0994
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-0994.json
github.com / protocolbuffers/protobuf/pull/25239
PatchVendor Advisory