PyPI: protobuf

CVE-2026-0994

Safety vulnerability ID: SFTY-20260123-63124

Safety legacy ID: pyup.io-85151

Affected versions of the protobuf package are vulnerable to Denial of Service (DoS) due to missing recursion depth accounting that allows the max_recursion_depth limit to be bypassed. The google.protobuf.json_format.ParseDict() parser fails to increment or enforce max_recursion_depth when traversing nested google.protobuf.Any messages in its internal Any-handling logic, allowing attacker-controlled JSON to recurse far deeper than intended.

Created at: Jul 15, 2026Updated at: Jul 15, 2026

Overview

protobuf affected by a JSON recursion depth bypass

Advisory

Affected versions of the protobuf package are vulnerable to Denial of Service (DoS) due to missing recursion depth accounting that allows the max_recursion_depth limit to be bypassed. The google.protobuf.json_format.ParseDict() parser fails to increment or enforce max_recursion_depth when traversing nested google.protobuf.Any messages in its internal Any-handling logic, allowing attacker-controlled JSON to recurse far deeper than intended.

Affected Package

Affecting protobuf package, versions
>=6.30.0rc1,<=6.33.4
<5.29.6

Also affects

---

How to Fix

Upgrade
protobuf
to
6.33.5
5.29.6
or higher.

Mitigation and Workarounds

---

Vulnerable Functions

Functions linked to known vulnerabilities.

Vulnerable function data is available for Enterprise customers

Book a call with us to see Safety in action.

Safety

Verified by Safety

Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.

Learn more