CVE-2026-0994Disclosure(google / protobuf)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch google protobuf systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages. Due to missing recursion depth accounting inside the internal Any-handling logic, an attacker can supply deeply nested Any structures that bypass the intended recursion limit, eventually exhausting Python’s recursion stack and causing a RecursionError.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-674

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • protobuf

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • Peaked 3d ago at 2 mentions (2026-01-27); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
protobuf

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-01-27: 2Mentions · 2026-02-04: 1Mentions · 2026-03-04: 1Mentions · 2026-04-25: 1Patch / Workaround · 2026-01-27: 1Patch / Workaround · 2026-04-25: 1Technical Details · 2026-01-27: 2Technical Details · 2026-02-04: 1Technical Details · 2026-03-04: 1Technical Details · 2026-04-25: 101-2702-0403-0404-25
Signal classification2 categories
Disclosure
480.0%
Patch
120.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-01-272
Disclosure2
2026-02-041
Disclosure1
2026-03-041
Disclosure1
2026-04-251
Patch1
Full discourse5 posts
  • kubesimplify@kubesimplify
    Patch

    Recent K8s + AI updates worth catching up on vLLM v0.19.1 → Patch release fixing CVE-2026-0994 (protobuf deserialization). If you’re running vLLM in production, this is a required upgrade. Most major features : async scheduling by default, Gemma 4 support, KV cache optimizations) landed in v0.19.0 / v0.18 this is stabilization + security. llm-d → Cloud Native Computing Foundation Sandbox (March 2026) Donated by IBM Research, Red Hat, and Google Cloud, with backing from NVIDIA, AMD, Hugging Face, Intel, etc.The important shift is treating distributed inference as a first-class Kubernetes workload. Concepts like prefill/decode disaggregation and prefix-cache-aware routing (EPP) are pushing infra closer to model-aware scheduling. Karpenter v1.11.x → NodePool limits, topology-aware scheduling, and provider-level hooks are now part of the baseline. If your mental model of Karpenter is pre-1.0, you’re already behind. Kubernetes AI Conformance v1.35 → Not another “drop,” but a directional signal. In-place pod resizing (scale inference without restarts) Workload-aware scheduling (reduce deadlocks in distributed training) Takeaway: This isn’t hype cycles. The Kubernetes ecosystem is actively evolving to natively support AI workloads from inference runtimes to scheduling semantics. If you’re building in this space, these aren’t optional reads.

    Post summary

    The post announces a patch release for CVE‑2026‑0994, noting the vulnerability involves protobuf deserialization and advises upgrading to vLLM v0.19.1.

    600126692
    12.6K followersView on X
  • Misbar | مسبار@MisbarSec
    Disclosure

    🚨 ثغرة DoS عالية الخطورة في Google Protocol Buffers اكتُشفت ثغرة خطيرة في Protocol Buffers، وهي أداة شائعة من جوجل لتنظيم البيانات. هذه الثغرة، CVE-2026-0994، تؤثر على استخدام Python وتسمح بتعطيل الخدمة DoS. 💡 خطوات الحماية: * التأكد من تحديث مكتبات Protocol Buffers. * مراقبة حركة المرور المشبوهة التي تستهدف الخدمات التي تستخدم Protocol Buffers. * تطبيق إجراءات صارمة للتحقق من صحة المدخلات. 🔗 https://securityonline.info/high-severity-dos-flaw-hits-google-protocol-buffers-cve-2026-0994/ #الأمن_السيبراني #ثغرات #Google

    Post summary

    A high‑severity DoS vulnerability (CVE‑2026‑0994) affecting Python usage of Google Protocol Buffers is disclosed, with recommended updates and mitigations, but no active exploitation or PoC is reported.

    0003066
    51 followersView on X
  • キタきつね@foxbook
    Disclosure

    Google プロトコル バッファに重大な DoS 脆弱性 (CVE-2026-0994) が発生 High-Severity DoS Flaw Hits Google Protocol Buffers (CVE-2026-0994) #DailyCyberSecurity (Jan 27) https://securityonline.info/high-severity-dos-flaw-hits-google-protocol-buffers-cve-2026-0994/

    Post summary

    The article announces a new high‑severity denial‑of‑service vulnerability, CVE‑2026‑0994, in Google Protocol Buffers. No proof of concept, exploit, or patch details are disclosed.

    00010262
    4.7K followersView on X
  • Komodo Cyber Security@Komodosec
    Disclosure

    #VulnerabilityReport #APIsecurity High-Severity DoS Flaw Hits Google Protocol Buffers (CVE-2026-0994) https://securityonline.info/high-severity-dos-flaw-hits-google-protocol-buffers-cve-2026-0994/?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    A new high‑severity DoS vulnerability (CVE‑2026‑0994) affecting Google Protocol Buffers has been disclosed, with limited technical detail but no PoC, exploit code, or patch mentioned.

    0000050
    1.5K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Disclosure

    🚨 SECURITY ADVISORY: CVE-2026-0994 - Protobuf vulnerability in #SUSE Linux (CVSS 8.4) allows recursion depth bypass in Python's json_format.ParseDict. Read more: 👉 https://tinyurl.com/4wt7zpff #Security https://t.co/3NaueW9MVu

    Post summary

    The advisory announces a Protobuf recursion depth bypass vulnerability (CVE-2026-0994) in SUSE Linux with a CVSS score of 8.4, providing technical details but no evidence of exploitation, PoC, or patch information.

    0000053
    1.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgoogleprotobuf---

Explore more