Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-89418

Опубликовано: 17 сент. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

google-protobuf contains an unbounded recursion when parsing unknown protobuf group fields. An attacker can send a small crafted payload of deeply nested START_GROUP wire bytes to any Node.js service that calls the generated deserializeBinary() API, causing a RangeError: Maximum call stack size exceeded and crashing the process. No authentication or prior knowledge of the schema is required.

A flaw was found in google-protobuf. An unauthenticated remote attacker can send a specially crafted message containing deeply nested protobuf group fields to a Node.js service using the affected library. This uncontrolled recursion can cause the service to crash, leading to a Denial of Service (DoS) for legitimate users.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift AI (RHOAI)rhoai/odh-core-bff-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-dashboard-operator-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-dashboard-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-mod-arch-agent-ops-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-mod-arch-automl-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-mod-arch-autorag-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-mod-arch-eval-hub-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-mod-arch-gen-ai-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-mod-arch-maas-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-mod-arch-mlflow-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-606
https://bugzilla.redhat.com/show_bug.cgi?id=2536016google-protobuf: google-protobuf: Denial of Service via uncontrolled recursion in protobuf group field parsing

EPSS

Процентиль: 30%
0.00367
Низкий

7.5 High

CVSS3

Связанные уязвимости

nvd
6 дней назад

google-protobuf contains an unbounded recursion when parsing unknown protobuf group fields. An attacker can send a small crafted payload of deeply nested START_GROUP wire bytes to any Node.js service that calls the generated deserializeBinary() API, causing a RangeError: Maximum call stack size exceeded and crashing the process. No authentication or prior knowledge of the schema is required.

EPSS

Процентиль: 30%
0.00367
Низкий

7.5 High

CVSS3