---
id: CVE-2026-104635
title: >-
  Uncontrolled Recursion vulnerability in Protobuf.JSON.Decode in
  elixir-protobuf protobuf allows an unauthenticated remote attacker to crash
  the decoding process via a deeply nested JSON document
summary: >-
  Uncontrolled Recursion vulnerability in Protobuf.JSON.Decode in
  elixir-protobuf protobuf allows an unauthenticated remote attacker to crash
  the decoding process via a deeply nested JSON document. Any application that
  decodes attacker-sup…
severity: none
cwe:
  - CWE-674
published: '2026-10-09'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T10:16:37.143'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-104635'
references:
  - url: 'https://cna.erlef.org/cves/CVE-2026-104635.html'
    label: 6b3ad84c-e1a6-4bf7-a703-f496b71e49db
  - url: >-
      https://github.com/elixir-protobuf/protobuf/commit/b0a1d4eaffaf50012fa71a8e931a47cf252d0370
    label: 6b3ad84c-e1a6-4bf7-a703-f496b71e49db
  - url: >-
      https://github.com/elixir-protobuf/protobuf/commit/e9432ad1c4099511905353cebcececa3a1f7c3ff
    label: 6b3ad84c-e1a6-4bf7-a703-f496b71e49db
  - url: >-
      https://github.com/elixir-protobuf/protobuf/security/advisories/GHSA-m497-c2h9-rvw6
    label: 6b3ad84c-e1a6-4bf7-a703-f496b71e49db
  - url: 'https://osv.dev/vulnerability/EEF-CVE-2026-104635'
    label: 6b3ad84c-e1a6-4bf7-a703-f496b71e49db
tags:
  - nvd
ingestedAt: '2026-10-09T09:31:01.005Z'
---

## Overview

Uncontrolled Recursion vulnerability in Protobuf.JSON.Decode in elixir-protobuf protobuf allows an unauthenticated remote attacker to crash the decoding process via a deeply nested JSON document. Any application that decodes attacker-supplied JSON with Protobuf.JSON.decode/3, Protobuf.JSON.decode!/3, or Protobuf.JSON.from_decoded/3 into a schema that contains a self-referential or cyclic message type is affected.

In lib/protobuf/json/decode.ex, the embedded-message clause of decode_singular/3 recurses into internal_from_json_data/3 once per nesting level without incrementing or checking the decoder's depth counter. The depth guard increase_depth_and_maybe_throw/1 covers only the Google.Protobuf.ListValue and Google.Protobuf.Struct clauses, so the recursion_limit option has no effect on user-defined message types. Each nesting level allocates a stack frame and heap objects, and a sufficiently deep document exhausts the memory of the decoding process. Confidentiality and integrity are not affected.

This issue affects protobuf: from 0.8.0 before 0.17.1.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
