CVE-2026-104635 elixir-protobuf Protobuf.JSON.Decode 递归失控漏洞
影响未认证远程攻击者可构造深层嵌套 JSON 使解码进程内存耗尽崩溃
elixir-protobuf 的 Protobuf.JSON.Decode 在处理内嵌消息类型时存在不受控递归问题。当解码的 schema 包含自引用或循环消息类型时,攻击者可通过深度嵌套的 JSON 文档触发无限递归,最终耗尽解码进程内存导致拒绝服务。该漏洞不影响机密性与完整性。
影响范围
protobuf 库 0.8.0 起至 0.17.1 之前的版本受影响。
漏洞详情
漏洞位于 lib/protobuf/json/decode.ex 的 decode_singular/3 内嵌消息分支,该分支每层嵌套都会递归调用 internal_from_json_data/3,但未递增或检查解码器的深度计数器。深度保护 increase_depth_and_maybe_throw/1 仅覆盖 Google.Protobuf.ListValue 与 Google.Protobuf.Struct 分支,导致 recursion_limit 选项对用户自定义消息类型无效。每层嵌套都会分配栈帧与堆对象,足够深的文档即可耗尽解码进程内存。
利用条件与风险
利用前提是应用使用 Protobuf.JSON.decode/3、decode!/3 或 from_decoded/3 解码攻击者可控的 JSON,且目标 schema 含自引用或循环消息类型;无需认证即可远程触发拒绝服务。
修复建议
升级 protobuf 至 0.17.1 或更高版本以修复该递归深度检查缺陷;暂无公开信息说明其他临时缓解措施,可考虑在解码前限制输入 JSON 的嵌套深度或大小。
Uncontrolled Recursion vulnerability in Protobuf.JSON.Decode in elixir-protobuf protobuf allows an unauthenticated remote attacker to crash the decoding process via a deeply nested JSON document. Any application that decodes attacker-supplied JSON with Protobuf.JSON.decode/3, Protobuf.JSON.decode!/3, or Protobuf.JSON.from_decoded/3 into a schema that contains a self-referential or cyclic message type is affected.
In lib/protobuf/json/decode.ex, the embedded-message clause of decode_singular/3 recurses into internal_from_json_data/3 once per nesting level without incrementing or checking the decoder’s depth counter. The depth guard increase_depth_and_maybe_throw/1 covers only the Google.Protobuf.ListValue and Google.Protobuf.Struct clauses, so the recursion_limit option has no effect on user-defined message types. Each nesting level allocates a stack frame and heap objects, and a sufficiently deep document exhausts the memory of the decoding process. Confidentiality and integrity are not affected.
This issue affects protobuf: from 0.8.0 before 0.17.1.