CVE-2026-55407Disclosure

LOWCVSS 6.3 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Buffa is a pure-Rust Protocol Buffers implementation with first-class protobuf editions support. Prior to 0.8.0, the decode_unknown_field function in buffa's protobuf decoder allocated heap memory in proportion to untrusted input (unknown fields in the serialized protobuf) without enforcing an allocation budget, affecting any message decoded from untrusted input using code generated with preserve_unknown_fields=true (the default); a small, well-formed payload of nested unknown fields inside a StartGroup could trigger roughly 22x memory amplification (for example a 64 MiB input forcing about 1.4 GB of heap allocation), and length-delimited unknown fields could be sized arbitrarily, so an unauthenticated attacker could crash a process through memory exhaustion because the top-level message size cap did not account for in-decode amplification. This issue is fixed in version 0.8.0.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400CWE-770CWE-789

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 3 mentions (2026-07-01); latest day: 1
  • 5 total mentions across 3 days

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-07-01: 3Mentions · 2026-07-02: 1Mentions · 2026-07-09: 1PoC Mentioned / Linked · 2026-07-01: 1Technical Details · 2026-07-01: 3Technical Details · 2026-07-09: 107-0107-0207-09
Signal classification2 categories
Disclosure
360.0%
General
240.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-07-013
Disclosure2General1
2026-07-021
General1
2026-07-091
Disclosure1
Full discourse5 posts
  • Nicolas Krassas@Dinosn
    Disclosure

    CVE-2026-55407: 22x memory amplification bug in Anthropic's buffa protobuf decoder https://www.endorlabs.com/learn/endor-labs-ai-sast-finds-zero-day-cve-2026-55407-buffa

    Post summary

    The post announces a new zero‑day memory amplification bug (CVE-2026-55407) in Anthropic's buffa protobuf decoder, providing a link to Endor Labs' findings but no evidence of exploitation or mitigation.

    050912.4K
    160.8K followersView on X
  • Frank@jedisct1
    Disclosure

    CVE-2026-55407.: ~22x memory-amplification denial of service in Anthropic buffa library https://www.endorlabs.com/learn/endor-labs-ai-sast-finds-zero-day-cve-2026-55407-buffa

    Post summary

    This post announces the discovery of CVE-2026-55407, a memory‑amplification denial‑of‑service flaw in Anthropic's buffa library, without mentioning active exploitation, mitigation, or a PoC.

    010611.0K
    17.7K followersView on X
  • durp@durpxmr
    General

    @usr_bin_roygbiv @zekramu Ok i stand corrected its shitty code built on rust. CVE-2026-55407 CVE-2026-35195 CVE-2026-34942 RUSTSEC-2026-0185

    Post summary

    The user lists several 2026 CVEs but provides no technical details, PoC, exploit, patch, or mitigation information.

    0001086
    441 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Anthropic buffa ライブラリのゼロデイ脆弱性 CVE-2026-55407 が FIX:22 倍のメモリ増幅で DoS を誘発 https://iototsecnews.jp/2026/07/01/anthropic-buffa-library-zero-day-lets-attackers-trigger-memory-amplification-dos/ この記事で特定された脆弱性 CVE-2026-55407 は、 Anthropic の protobuf ライブラリにおける未知フィールドのデコード処理に起因します。 Rust はメモリ安全性の高い言語ですが、制御されないリソース割り当てを防ぐことはできません。今回の問題は、攻撃者が制御する入力値がヒープ割り当てのサイズに直接影響し、上限のないベクターの割り当てが行われてしまうというロジック上の欠陥が原因となります。特に、ネストされたフィールドを処理するループ内では、わずか 2 バイトの入力に対して約 40 バイトのメモリが動的に割り当てられ、約 22 倍もの深刻なメモリ増幅が発生します。リクエストのサイズ制限をすり抜けて、メモリ枯渇( OOM )によるクラッシュを引き起こすため、注意が必要です。ご利用のチームは、ご注意ください。 #Anthropic #buffa #CVE202655407 #Vulnerability

    Post summary

    A new zero‑day CVE-2026-55407 in Anthropic’s buffa protobuf library causes a memory‑amplification driven DoS with 22× amplification from a 2‑byte input, but no PoC, exploit, or patch details are provided.

    00000169
    500 followersView on X
  • The Signal@thesignalnow
    General

    Everyone obsessed with alignment. Anthropic's buffa protobuf decoder: CVE-2026-55407. One malformed message. 22x RAM. That's not safety. That's theater.

    Post summary

    The post briefly notes a CVE related to a memory‑increase vulnerability triggered by a malformed protobuf message, without mentioning PoC, exploitation, or mitigation.

    0000030
    540 followersView on X

Explore more