CVE-2026-0994 is a denial-of-service (DoS) vulnerability affecting the google.protobuf.json_format.ParseDict() function in Python. It allows an attacker to bypass the intended recursion depth limit by supplying deeply nested google.protobuf.Any messages, leading to a Python RecursionError and application crash. This vulnerability has a CVSS score of 8.2 (HIGH) due to its network-based attack vector, low attack complexity, and high impact on availability. While there is no evidence of active exploitation or publicly available exploit code, the vulnerability has garnered significant community discussion, indicating awareness and potential future interest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 33.4CPE matchmatch criteria | cpe:2.3:a:google:protobuf:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Protocol Buffers vulnerability
May 26, 2026Protocol Buffers vulnerability
Feb 25, 2026protobuf affected by a JSON recursion depth bypass
Jan 23, 2026python: protobuf: Protobuf: Denial of Service due to recursion depth bypass
Jan 23, 2026