<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 22:25:05 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-373331</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-373331</link>
      <description>EUVD-2026-373331</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-373331</guid>
    </item>
    <item>
      <title>fkie_cve-2026-54451</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-54451</link>
      <description>&lt;p&gt;Elixir protobuf is a pure Elixir implementation of Google Protobuf. From 0.8.0 until 0.16.1, services that decode attacker-controlled protobuf bytes with Protobuf.Decoder can be taken offline when the schema contains a self-referential or cyclic message type. In lib/protobuf/decoder.ex, Protobuf.Decoder.value_for_field/3 handles an embedded?: true field by recursively entering the decode / build_message / handle_value / value_for_field call chain without enforcing a nesting-depth limit. Deeply nested embedded fields retain non-tail recursive frames, allowing a comparatively small request to consume substantial CPU and memory, pin a BEAM scheduler, and exhaust the node. This issue is fixed in version 0.16.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Elixir protobuf is a pure Elixir implementation of Google Protobuf. From 0.8.0 until 0.16.1, services that decode attacker-controlled protobuf bytes with Protobuf.Decoder can be taken offline when the schema contains a self-referential or cyclic message type. In lib/protobuf/decoder.ex, Protobuf.Decoder.value_for_field/3 handles an embedded?: true field by recursively entering the decode / build_message / handle_value / value_for_field call chain without enforcing a nesting-depth limit. Deeply nested embedded fields retain non-tail recursive frames, allowing a comparatively small request to consume substantial CPU and memory, pin a BEAM scheduler, and exhaust the node. This issue is fixed in version 0.16.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-54451</guid>
    </item>
    <item>
      <title>GHSA-rv48-qqj5-crxg — Protobuf: Unbounded recursion depth in embedded-message decoding</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-rv48-qqj5-crxg</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Hex: protobuf&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Unbounded recursion depth in `Protobuf.Decoder` (Hex package `protobuf`, versions `&amp;gt;= 0.8.0, &amp;lt; 0.16.1`) lets an unauthenticated attacker crash any service that decodes untrusted protobuf messages whose schema contains a self-referential or cyclic message type. A small request body (a few KB to a few MB) that nests an embedded field hundreds of thousands to millions of levels deep forces the BEAM to recurse once per level, exhausting memory and pinning a scheduler. A handful of such requests can take the node offline (a request-amplification denial of service).&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;`Protobuf.Decoder.value_for_field/3` handles embedded message fields in its `embedded?: true` branch at `lib/protobuf/decoder.ex:218-243`. For an embedded field it calls `decode(bin, type)` recursively, which re-enters `build_message → handle_value → value_for_field`. The recursive call is not in tail position (its result is consumed by the surrounding decode after it returns), so every nesting level retains a live frame on the process stack and heap.&lt;/p&gt;
&lt;p&gt;There is no recursion-depth counter anywhere in the decoder. For any schema with a self-referential message type (e.g. `message Tree { Tree child = 1; }`, a common shape for comment threads, org charts, file trees, and ASTs) or any cycle of message types, the attacker controls the nesting depth entirely through the input bytes. Each additional level costs only a 1-byte field tag plus a varint length prefix, so depth grows roughly inversely with…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Hex: protobuf&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Unbounded recursion depth in `Protobuf.Decoder` (Hex package `protobuf`, versions `&amp;gt;= 0.8.0, &amp;lt; 0.16.1`) lets an unauthenticated attacker crash any service that decodes untrusted protobuf messages whose schema contains a self-referential or cyclic message type. A small request body (a few KB to a few MB) that nests an embedded field hundreds of thousands to millions of levels deep forces the BEAM to recurse once per level, exhausting memory and pinning a scheduler. A handful of such requests can take the node offline (a request-amplification denial of service).&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;`Protobuf.Decoder.value_for_field/3` handles embedded message fields in its `embedded?: true` branch at `lib/protobuf/decoder.ex:218-243`. For an embedded field it calls `decode(bin, type)` recursively, which re-enters `build_message → handle_value → value_for_field`. The recursive call is not in tail position (its result is consumed by the surrounding decode after it returns), so every nesting level retains a live frame on the process stack and heap.&lt;/p&gt;
&lt;p&gt;There is no recursion-depth counter anywhere in the decoder. For any schema with a self-referential message type (e.g. `message Tree { Tree child = 1; }`, a common shape for comment threads, org charts, file trees, and ASTs) or any cycle of message types, the attacker controls the nesting depth entirely through the input bytes. Each additional level costs only a 1-byte field tag plus a varint length prefix, so depth grows roughly inversely with…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-rv48-qqj5-crxg</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-54451</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-54451</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: elixir, Ubuntu:16.04:LTS: elixir, Ubuntu:18.04:LTS: elixir&lt;/p&gt;
&lt;p&gt;Elixir protobuf is a pure Elixir implementation of Google Protobuf. From 0.8.0 until 0.16.1, services that decode attacker-controlled protobuf bytes with Protobuf.Decoder can be taken offline when the schema contains a self-referential or cyclic message type. In lib/protobuf/decoder.ex, Protobuf.Decoder.value_for_field/3 handles an embedded?: true field by recursively entering the decode / build_message / handle_value / value_for_field call chain without enforcing a nesting-depth limit. Deeply nested embedded fields retain non-tail recursive frames, allowing a comparatively small request to consume substantial CPU and memory, pin a BEAM scheduler, and exhaust the node. This issue is fixed in version 0.16.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: elixir, Ubuntu:16.04:LTS: elixir, Ubuntu:18.04:LTS: elixir&lt;/p&gt;
&lt;p&gt;Elixir protobuf is a pure Elixir implementation of Google Protobuf. From 0.8.0 until 0.16.1, services that decode attacker-controlled protobuf bytes with Protobuf.Decoder can be taken offline when the schema contains a self-referential or cyclic message type. In lib/protobuf/decoder.ex, Protobuf.Decoder.value_for_field/3 handles an embedded?: true field by recursively entering the decode / build_message / handle_value / value_for_field call chain without enforcing a nesting-depth limit. Deeply nested embedded fields retain non-tail recursive frames, allowing a comparatively small request to consume substantial CPU and memory, pin a BEAM scheduler, and exhaust the node. This issue is fixed in version 0.16.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-54451</guid>
    </item>
  </channel>
</rss>
