protobuf vulnerabilities
CVEs whose affected-version data names the protobuf package (erlang, nuget, pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
5 CVEsRSS
CVE-2026-54451High· 8.2PoCElixir protobuf is a pure Elixir implementation of Google Protobuf
Elixir protobuf is a pure Elixir implementation of Google Protobuf. From 0.8.0 until 0.16.1, services that decode attacker-controlled protobuf bytes with Protobuf.Decoder can be taken offline when the schema contains a self-referential o…
CVE-2026-0994High· 7.5PoCA denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages. Due to missing recursion depth ac…
A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages. Due to missing recursion depth ac…
CVE-2025-4565Highprotobuf-python has a potential Denial of Service issue
protobuf-python has a potential Denial of Service issue
CVE-2022-1941High· 7.5protobuf-cpp and protobuf-python have potential Denial of Service issue
protobuf-cpp and protobuf-python have potential Denial of Service issue
CVE-2015-5237High· 8.8protobuf susceptible to buffer overflow
protobuf susceptible to buffer overflow