protobuf
Activity
- Latest release
- 1w ago
- Total releases
- 221
- Cadence
- ~13 days
- Last 12 months
- 24
Details
- License
- unknown
- First release
- Jul 10, 2008
| Version | Released | |
|---|---|---|
7.36.1
patch
|
7.36.1
patch
|
|
7.36.0
minor
|
7.36.0
minor
|
|
7.36.0rc2
pre
|
7.36.0rc2
pre
|
|
7.36.0rc1
pre
|
7.36.0rc1
pre
|
|
7.35.1
patch
|
7.35.1
patch
|
|
7.34.2
patch
|
7.34.2
patch
|
|
7.35.0
minor
|
7.35.0
minor
|
|
7.35.0rc2
pre
|
7.35.0rc2
pre
|
|
7.35.0rc1
pre
|
7.35.0rc1
pre
|
|
4.25.9
patch
1 CVE
CVE-2026-0994
PYSEC-2026-1805
GHSA-7gcm-g887-7qv7
Jul 07, 2026
protobuf affected by a JSON recursion depth bypass
High
Network
Low
None
None
A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages. Due to missing recursion depth accounting inside the internal Any-handling logic, an attacker can supply deeply nested Any structures that bypass the intended recursion limit, eventually exhausting Python’s recursion stack and causing a RecursionError. Affected versions
2.0.0beta
2.0.3
2.3.0
2.4.1
2.5.0
2.6.0
2.6.1
3.0.0
3.0.0a2
3.0.0a3
3.0.0b1
3.0.0b1.post1
+ 193 more Show less
3.0.0b1.post2
3.0.0b2
3.0.0b2.post1
3.0.0b2.post2
3.0.0b3
3.0.0b4
3.1.0
3.1.0.post1
3.10.0
3.10.0rc1
3.11.0
3.11.0rc1
3.11.0rc2
3.11.1
3.11.2
3.11.3
3.12.0
3.12.0rc1
3.12.0rc2
3.12.1
3.12.2
3.12.4
3.13.0
3.13.0rc3
3.14.0
3.14.0rc1
3.14.0rc2
3.14.0rc3
3.15.0
3.15.0rc1
3.15.0rc2
3.15.1
3.15.2
3.15.3
3.15.4
3.15.5
3.15.6
3.15.7
3.15.8
3.16.0
3.16.0rc1
3.16.0rc2
3.17.0
3.17.0rc1
3.17.0rc2
3.17.1
3.17.2
3.17.3
3.18.0
3.18.0rc1
3.18.0rc2
3.18.1
3.18.3
3.19.0
3.19.0rc1
3.19.0rc2
3.19.1
3.19.2
3.19.3
3.19.4
3.19.5
3.19.6
3.2.0
3.2.0rc1
3.2.0rc1.post1
3.2.0rc2
3.20.0
3.20.0rc1
3.20.0rc2
3.20.1
3.20.1rc1
3.20.2
3.20.3
3.3.0
3.4.0
3.5.0.post1
3.5.1
3.5.2
3.5.2.post1
3.6.0
3.6.1
3.7.0
3.7.0rc2
3.7.0rc3
3.7.1
3.8.0
3.8.0rc1
3.9.0
3.9.0rc1
3.9.1
3.9.2
4.0.0rc1
4.0.0rc2
4.21.0
4.21.0rc1
4.21.0rc2
4.21.1
4.21.10
4.21.11
4.21.12
4.21.2
4.21.3
4.21.4
4.21.5
4.21.6
4.21.7
4.21.8
4.21.9
4.22.0
4.22.0rc1
4.22.0rc2
4.22.0rc3
4.22.1
4.22.3
4.22.4
4.22.5
4.23.0
4.23.0rc2
4.23.0rc3
4.23.1
4.23.2
4.23.3
4.23.4
4.24.0
4.24.0rc1
4.24.0rc2
4.24.0rc3
4.24.1
4.24.2
4.24.3
4.24.4
4.25.0
4.25.0rc1
4.25.0rc2
4.25.1
4.25.2
4.25.3
4.25.4
4.25.5
4.25.6
4.25.7
4.25.8
4.25.9
5.26.0
5.26.0rc1
5.26.0rc2
5.26.0rc3
5.26.1
5.27.0
5.27.0rc1
5.27.0rc2
5.27.0rc3
5.27.1
5.27.2
5.27.3
5.27.4
5.27.5
5.28.0
5.28.0rc1
5.28.0rc2
5.28.0rc3
5.28.1
5.28.2
5.28.3
5.29.0
5.29.0rc1
5.29.0rc2
5.29.0rc3
5.29.1
5.29.2
5.29.3
5.29.4
5.29.5
6.30.0
6.30.0rc1
6.30.0rc2
6.30.1
6.30.2
6.31.0
6.31.0rc1
6.31.0rc2
6.31.1
6.32.0
6.32.0rc1
6.32.0rc2
6.32.1
6.33.0
6.33.0rc1
6.33.0rc2
6.33.1
6.33.2
6.33.3
6.33.4
Fixed in
5.29.6
6.33.5
References
Updated Jul 07, 2026 · Source: OSV.dev |
4.25.9
patch
|
|
7.34.1
patch
|
7.34.1
patch
|
|
6.33.6
patch
|
6.33.6
patch
|
|
7.34.0
major
|
7.34.0
major
|
|
7.34.0rc2
pre
|
7.34.0rc2
pre
|
|
5.29.6
patch
|
5.29.6
patch
|
|
6.33.5
patch
|
6.33.5
patch
|
|
7.34.0rc1
pre
|
7.34.0rc1
pre
|
|
6.33.4
patch
1 CVE
CVE-2026-0994
PYSEC-2026-1805
GHSA-7gcm-g887-7qv7
Jul 07, 2026
protobuf affected by a JSON recursion depth bypass
High
Network
Low
None
None
A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages. Due to missing recursion depth accounting inside the internal Any-handling logic, an attacker can supply deeply nested Any structures that bypass the intended recursion limit, eventually exhausting Python’s recursion stack and causing a RecursionError. Affected versions
2.0.0beta
2.0.3
2.3.0
2.4.1
2.5.0
2.6.0
2.6.1
3.0.0
3.0.0a2
3.0.0a3
3.0.0b1
3.0.0b1.post1
+ 193 more Show less
3.0.0b1.post2
3.0.0b2
3.0.0b2.post1
3.0.0b2.post2
3.0.0b3
3.0.0b4
3.1.0
3.1.0.post1
3.10.0
3.10.0rc1
3.11.0
3.11.0rc1
3.11.0rc2
3.11.1
3.11.2
3.11.3
3.12.0
3.12.0rc1
3.12.0rc2
3.12.1
3.12.2
3.12.4
3.13.0
3.13.0rc3
3.14.0
3.14.0rc1
3.14.0rc2
3.14.0rc3
3.15.0
3.15.0rc1
3.15.0rc2
3.15.1
3.15.2
3.15.3
3.15.4
3.15.5
3.15.6
3.15.7
3.15.8
3.16.0
3.16.0rc1
3.16.0rc2
3.17.0
3.17.0rc1
3.17.0rc2
3.17.1
3.17.2
3.17.3
3.18.0
3.18.0rc1
3.18.0rc2
3.18.1
3.18.3
3.19.0
3.19.0rc1
3.19.0rc2
3.19.1
3.19.2
3.19.3
3.19.4
3.19.5
3.19.6
3.2.0
3.2.0rc1
3.2.0rc1.post1
3.2.0rc2
3.20.0
3.20.0rc1
3.20.0rc2
3.20.1
3.20.1rc1
3.20.2
3.20.3
3.3.0
3.4.0
3.5.0.post1
3.5.1
3.5.2
3.5.2.post1
3.6.0
3.6.1
3.7.0
3.7.0rc2
3.7.0rc3
3.7.1
3.8.0
3.8.0rc1
3.9.0
3.9.0rc1
3.9.1
3.9.2
4.0.0rc1
4.0.0rc2
4.21.0
4.21.0rc1
4.21.0rc2
4.21.1
4.21.10
4.21.11
4.21.12
4.21.2
4.21.3
4.21.4
4.21.5
4.21.6
4.21.7
4.21.8
4.21.9
4.22.0
4.22.0rc1
4.22.0rc2
4.22.0rc3
4.22.1
4.22.3
4.22.4
4.22.5
4.23.0
4.23.0rc2
4.23.0rc3
4.23.1
4.23.2
4.23.3
4.23.4
4.24.0
4.24.0rc1
4.24.0rc2
4.24.0rc3
4.24.1
4.24.2
4.24.3
4.24.4
4.25.0
4.25.0rc1
4.25.0rc2
4.25.1
4.25.2
4.25.3
4.25.4
4.25.5
4.25.6
4.25.7
4.25.8
4.25.9
5.26.0
5.26.0rc1
5.26.0rc2
5.26.0rc3
5.26.1
5.27.0
5.27.0rc1
5.27.0rc2
5.27.0rc3
5.27.1
5.27.2
5.27.3
5.27.4
5.27.5
5.28.0
5.28.0rc1
5.28.0rc2
5.28.0rc3
5.28.1
5.28.2
5.28.3
5.29.0
5.29.0rc1
5.29.0rc2
5.29.0rc3
5.29.1
5.29.2
5.29.3
5.29.4
5.29.5
6.30.0
6.30.0rc1
6.30.0rc2
6.30.1
6.30.2
6.31.0
6.31.0rc1
6.31.0rc2
6.31.1
6.32.0
6.32.0rc1
6.32.0rc2
6.32.1
6.33.0
6.33.0rc1
6.33.0rc2
6.33.1
6.33.2
6.33.3
6.33.4
Fixed in
5.29.6
6.33.5
References
Updated Jul 07, 2026 · Source: OSV.dev |
6.33.4
patch
|
|
6.33.3
patch
1 CVE
CVE-2026-0994
PYSEC-2026-1805
GHSA-7gcm-g887-7qv7
Jul 07, 2026
protobuf affected by a JSON recursion depth bypass
High
Network
Low
None
None
A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages. Due to missing recursion depth accounting inside the internal Any-handling logic, an attacker can supply deeply nested Any structures that bypass the intended recursion limit, eventually exhausting Python’s recursion stack and causing a RecursionError. Affected versions
2.0.0beta
2.0.3
2.3.0
2.4.1
2.5.0
2.6.0
2.6.1
3.0.0
3.0.0a2
3.0.0a3
3.0.0b1
3.0.0b1.post1
+ 193 more Show less
3.0.0b1.post2
3.0.0b2
3.0.0b2.post1
3.0.0b2.post2
3.0.0b3
3.0.0b4
3.1.0
3.1.0.post1
3.10.0
3.10.0rc1
3.11.0
3.11.0rc1
3.11.0rc2
3.11.1
3.11.2
3.11.3
3.12.0
3.12.0rc1
3.12.0rc2
3.12.1
3.12.2
3.12.4
3.13.0
3.13.0rc3
3.14.0
3.14.0rc1
3.14.0rc2
3.14.0rc3
3.15.0
3.15.0rc1
3.15.0rc2
3.15.1
3.15.2
3.15.3
3.15.4
3.15.5
3.15.6
3.15.7
3.15.8
3.16.0
3.16.0rc1
3.16.0rc2
3.17.0
3.17.0rc1
3.17.0rc2
3.17.1
3.17.2
3.17.3
3.18.0
3.18.0rc1
3.18.0rc2
3.18.1
3.18.3
3.19.0
3.19.0rc1
3.19.0rc2
3.19.1
3.19.2
3.19.3
3.19.4
3.19.5
3.19.6
3.2.0
3.2.0rc1
3.2.0rc1.post1
3.2.0rc2
3.20.0
3.20.0rc1
3.20.0rc2
3.20.1
3.20.1rc1
3.20.2
3.20.3
3.3.0
3.4.0
3.5.0.post1
3.5.1
3.5.2
3.5.2.post1
3.6.0
3.6.1
3.7.0
3.7.0rc2
3.7.0rc3
3.7.1
3.8.0
3.8.0rc1
3.9.0
3.9.0rc1
3.9.1
3.9.2
4.0.0rc1
4.0.0rc2
4.21.0
4.21.0rc1
4.21.0rc2
4.21.1
4.21.10
4.21.11
4.21.12
4.21.2
4.21.3
4.21.4
4.21.5
4.21.6
4.21.7
4.21.8
4.21.9
4.22.0
4.22.0rc1
4.22.0rc2
4.22.0rc3
4.22.1
4.22.3
4.22.4
4.22.5
4.23.0
4.23.0rc2
4.23.0rc3
4.23.1
4.23.2
4.23.3
4.23.4
4.24.0
4.24.0rc1
4.24.0rc2
4.24.0rc3
4.24.1
4.24.2
4.24.3
4.24.4
4.25.0
4.25.0rc1
4.25.0rc2
4.25.1
4.25.2
4.25.3
4.25.4
4.25.5
4.25.6
4.25.7
4.25.8
4.25.9
5.26.0
5.26.0rc1
5.26.0rc2
5.26.0rc3
5.26.1
5.27.0
5.27.0rc1
5.27.0rc2
5.27.0rc3
5.27.1
5.27.2
5.27.3
5.27.4
5.27.5
5.28.0
5.28.0rc1
5.28.0rc2
5.28.0rc3
5.28.1
5.28.2
5.28.3
5.29.0
5.29.0rc1
5.29.0rc2
5.29.0rc3
5.29.1
5.29.2
5.29.3
5.29.4
5.29.5
6.30.0
6.30.0rc1
6.30.0rc2
6.30.1
6.30.2
6.31.0
6.31.0rc1
6.31.0rc2
6.31.1
6.32.0
6.32.0rc1
6.32.0rc2
6.32.1
6.33.0
6.33.0rc1
6.33.0rc2
6.33.1
6.33.2
6.33.3
6.33.4
Fixed in
5.29.6
6.33.5
References
Updated Jul 07, 2026 · Source: OSV.dev |
6.33.3
patch
|
|
6.33.2
patch
1 CVE
CVE-2026-0994
PYSEC-2026-1805
GHSA-7gcm-g887-7qv7
Jul 07, 2026
protobuf affected by a JSON recursion depth bypass
High
Network
Low
None
None
A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages. Due to missing recursion depth accounting inside the internal Any-handling logic, an attacker can supply deeply nested Any structures that bypass the intended recursion limit, eventually exhausting Python’s recursion stack and causing a RecursionError. Affected versions
2.0.0beta
2.0.3
2.3.0
2.4.1
2.5.0
2.6.0
2.6.1
3.0.0
3.0.0a2
3.0.0a3
3.0.0b1
3.0.0b1.post1
+ 193 more Show less
3.0.0b1.post2
3.0.0b2
3.0.0b2.post1
3.0.0b2.post2
3.0.0b3
3.0.0b4
3.1.0
3.1.0.post1
3.10.0
3.10.0rc1
3.11.0
3.11.0rc1
3.11.0rc2
3.11.1
3.11.2
3.11.3
3.12.0
3.12.0rc1
3.12.0rc2
3.12.1
3.12.2
3.12.4
3.13.0
3.13.0rc3
3.14.0
3.14.0rc1
3.14.0rc2
3.14.0rc3
3.15.0
3.15.0rc1
3.15.0rc2
3.15.1
3.15.2
3.15.3
3.15.4
3.15.5
3.15.6
3.15.7
3.15.8
3.16.0
3.16.0rc1
3.16.0rc2
3.17.0
3.17.0rc1
3.17.0rc2
3.17.1
3.17.2
3.17.3
3.18.0
3.18.0rc1
3.18.0rc2
3.18.1
3.18.3
3.19.0
3.19.0rc1
3.19.0rc2
3.19.1
3.19.2
3.19.3
3.19.4
3.19.5
3.19.6
3.2.0
3.2.0rc1
3.2.0rc1.post1
3.2.0rc2
3.20.0
3.20.0rc1
3.20.0rc2
3.20.1
3.20.1rc1
3.20.2
3.20.3
3.3.0
3.4.0
3.5.0.post1
3.5.1
3.5.2
3.5.2.post1
3.6.0
3.6.1
3.7.0
3.7.0rc2
3.7.0rc3
3.7.1
3.8.0
3.8.0rc1
3.9.0
3.9.0rc1
3.9.1
3.9.2
4.0.0rc1
4.0.0rc2
4.21.0
4.21.0rc1
4.21.0rc2
4.21.1
4.21.10
4.21.11
4.21.12
4.21.2
4.21.3
4.21.4
4.21.5
4.21.6
4.21.7
4.21.8
4.21.9
4.22.0
4.22.0rc1
4.22.0rc2
4.22.0rc3
4.22.1
4.22.3
4.22.4
4.22.5
4.23.0
4.23.0rc2
4.23.0rc3
4.23.1
4.23.2
4.23.3
4.23.4
4.24.0
4.24.0rc1
4.24.0rc2
4.24.0rc3
4.24.1
4.24.2
4.24.3
4.24.4
4.25.0
4.25.0rc1
4.25.0rc2
4.25.1
4.25.2
4.25.3
4.25.4
4.25.5
4.25.6
4.25.7
4.25.8
4.25.9
5.26.0
5.26.0rc1
5.26.0rc2
5.26.0rc3
5.26.1
5.27.0
5.27.0rc1
5.27.0rc2
5.27.0rc3
5.27.1
5.27.2
5.27.3
5.27.4
5.27.5
5.28.0
5.28.0rc1
5.28.0rc2
5.28.0rc3
5.28.1
5.28.2
5.28.3
5.29.0
5.29.0rc1
5.29.0rc2
5.29.0rc3
5.29.1
5.29.2
5.29.3
5.29.4
5.29.5
6.30.0
6.30.0rc1
6.30.0rc2
6.30.1
6.30.2
6.31.0
6.31.0rc1
6.31.0rc2
6.31.1
6.32.0
6.32.0rc1
6.32.0rc2
6.32.1
6.33.0
6.33.0rc1
6.33.0rc2
6.33.1
6.33.2
6.33.3
6.33.4
Fixed in
5.29.6
6.33.5
References
Updated Jul 07, 2026 · Source: OSV.dev |
6.33.2
patch
|
|
6.33.1
patch
1 CVE
CVE-2026-0994
PYSEC-2026-1805
GHSA-7gcm-g887-7qv7
Jul 07, 2026
protobuf affected by a JSON recursion depth bypass
High
Network
Low
None
None
A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages. Due to missing recursion depth accounting inside the internal Any-handling logic, an attacker can supply deeply nested Any structures that bypass the intended recursion limit, eventually exhausting Python’s recursion stack and causing a RecursionError. Affected versions
2.0.0beta
2.0.3
2.3.0
2.4.1
2.5.0
2.6.0
2.6.1
3.0.0
3.0.0a2
3.0.0a3
3.0.0b1
3.0.0b1.post1
+ 193 more Show less
3.0.0b1.post2
3.0.0b2
3.0.0b2.post1
3.0.0b2.post2
3.0.0b3
3.0.0b4
3.1.0
3.1.0.post1
3.10.0
3.10.0rc1
3.11.0
3.11.0rc1
3.11.0rc2
3.11.1
3.11.2
3.11.3
3.12.0
3.12.0rc1
3.12.0rc2
3.12.1
3.12.2
3.12.4
3.13.0
3.13.0rc3
3.14.0
3.14.0rc1
3.14.0rc2
3.14.0rc3
3.15.0
3.15.0rc1
3.15.0rc2
3.15.1
3.15.2
3.15.3
3.15.4
3.15.5
3.15.6
3.15.7
3.15.8
3.16.0
3.16.0rc1
3.16.0rc2
3.17.0
3.17.0rc1
3.17.0rc2
3.17.1
3.17.2
3.17.3
3.18.0
3.18.0rc1
3.18.0rc2
3.18.1
3.18.3
3.19.0
3.19.0rc1
3.19.0rc2
3.19.1
3.19.2
3.19.3
3.19.4
3.19.5
3.19.6
3.2.0
3.2.0rc1
3.2.0rc1.post1
3.2.0rc2
3.20.0
3.20.0rc1
3.20.0rc2
3.20.1
3.20.1rc1
3.20.2
3.20.3
3.3.0
3.4.0
3.5.0.post1
3.5.1
3.5.2
3.5.2.post1
3.6.0
3.6.1
3.7.0
3.7.0rc2
3.7.0rc3
3.7.1
3.8.0
3.8.0rc1
3.9.0
3.9.0rc1
3.9.1
3.9.2
4.0.0rc1
4.0.0rc2
4.21.0
4.21.0rc1
4.21.0rc2
4.21.1
4.21.10
4.21.11
4.21.12
4.21.2
4.21.3
4.21.4
4.21.5
4.21.6
4.21.7
4.21.8
4.21.9
4.22.0
4.22.0rc1
4.22.0rc2
4.22.0rc3
4.22.1
4.22.3
4.22.4
4.22.5
4.23.0
4.23.0rc2
4.23.0rc3
4.23.1
4.23.2
4.23.3
4.23.4
4.24.0
4.24.0rc1
4.24.0rc2
4.24.0rc3
4.24.1
4.24.2
4.24.3
4.24.4
4.25.0
4.25.0rc1
4.25.0rc2
4.25.1
4.25.2
4.25.3
4.25.4
4.25.5
4.25.6
4.25.7
4.25.8
4.25.9
5.26.0
5.26.0rc1
5.26.0rc2
5.26.0rc3
5.26.1
5.27.0
5.27.0rc1
5.27.0rc2
5.27.0rc3
5.27.1
5.27.2
5.27.3
5.27.4
5.27.5
5.28.0
5.28.0rc1
5.28.0rc2
5.28.0rc3
5.28.1
5.28.2
5.28.3
5.29.0
5.29.0rc1
5.29.0rc2
5.29.0rc3
5.29.1
5.29.2
5.29.3
5.29.4
5.29.5
6.30.0
6.30.0rc1
6.30.0rc2
6.30.1
6.30.2
6.31.0
6.31.0rc1
6.31.0rc2
6.31.1
6.32.0
6.32.0rc1
6.32.0rc2
6.32.1
6.33.0
6.33.0rc1
6.33.0rc2
6.33.1
6.33.2
6.33.3
6.33.4
Fixed in
5.29.6
6.33.5
References
Updated Jul 07, 2026 · Source: OSV.dev |
6.33.1
patch
|
|
6.33.0
minor
1 CVE
CVE-2026-0994
PYSEC-2026-1805
GHSA-7gcm-g887-7qv7
Jul 07, 2026
protobuf affected by a JSON recursion depth bypass
High
Network
Low
None
None
A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages. Due to missing recursion depth accounting inside the internal Any-handling logic, an attacker can supply deeply nested Any structures that bypass the intended recursion limit, eventually exhausting Python’s recursion stack and causing a RecursionError. Affected versions
2.0.0beta
2.0.3
2.3.0
2.4.1
2.5.0
2.6.0
2.6.1
3.0.0
3.0.0a2
3.0.0a3
3.0.0b1
3.0.0b1.post1
+ 193 more Show less
3.0.0b1.post2
3.0.0b2
3.0.0b2.post1
3.0.0b2.post2
3.0.0b3
3.0.0b4
3.1.0
3.1.0.post1
3.10.0
3.10.0rc1
3.11.0
3.11.0rc1
3.11.0rc2
3.11.1
3.11.2
3.11.3
3.12.0
3.12.0rc1
3.12.0rc2
3.12.1
3.12.2
3.12.4
3.13.0
3.13.0rc3
3.14.0
3.14.0rc1
3.14.0rc2
3.14.0rc3
3.15.0
3.15.0rc1
3.15.0rc2
3.15.1
3.15.2
3.15.3
3.15.4
3.15.5
3.15.6
3.15.7
3.15.8
3.16.0
3.16.0rc1
3.16.0rc2
3.17.0
3.17.0rc1
3.17.0rc2
3.17.1
3.17.2
3.17.3
3.18.0
3.18.0rc1
3.18.0rc2
3.18.1
3.18.3
3.19.0
3.19.0rc1
3.19.0rc2
3.19.1
3.19.2
3.19.3
3.19.4
3.19.5
3.19.6
3.2.0
3.2.0rc1
3.2.0rc1.post1
3.2.0rc2
3.20.0
3.20.0rc1
3.20.0rc2
3.20.1
3.20.1rc1
3.20.2
3.20.3
3.3.0
3.4.0
3.5.0.post1
3.5.1
3.5.2
3.5.2.post1
3.6.0
3.6.1
3.7.0
3.7.0rc2
3.7.0rc3
3.7.1
3.8.0
3.8.0rc1
3.9.0
3.9.0rc1
3.9.1
3.9.2
4.0.0rc1
4.0.0rc2
4.21.0
4.21.0rc1
4.21.0rc2
4.21.1
4.21.10
4.21.11
4.21.12
4.21.2
4.21.3
4.21.4
4.21.5
4.21.6
4.21.7
4.21.8
4.21.9
4.22.0
4.22.0rc1
4.22.0rc2
4.22.0rc3
4.22.1
4.22.3
4.22.4
4.22.5
4.23.0
4.23.0rc2
4.23.0rc3
4.23.1
4.23.2
4.23.3
4.23.4
4.24.0
4.24.0rc1
4.24.0rc2
4.24.0rc3
4.24.1
4.24.2
4.24.3
4.24.4
4.25.0
4.25.0rc1
4.25.0rc2
4.25.1
4.25.2
4.25.3
4.25.4
4.25.5
4.25.6
4.25.7
4.25.8
4.25.9
5.26.0
5.26.0rc1
5.26.0rc2
5.26.0rc3
5.26.1
5.27.0
5.27.0rc1
5.27.0rc2
5.27.0rc3
5.27.1
5.27.2
5.27.3
5.27.4
5.27.5
5.28.0
5.28.0rc1
5.28.0rc2
5.28.0rc3
5.28.1
5.28.2
5.28.3
5.29.0
5.29.0rc1
5.29.0rc2
5.29.0rc3
5.29.1
5.29.2
5.29.3
5.29.4
5.29.5
6.30.0
6.30.0rc1
6.30.0rc2
6.30.1
6.30.2
6.31.0
6.31.0rc1
6.31.0rc2
6.31.1
6.32.0
6.32.0rc1
6.32.0rc2
6.32.1
6.33.0
6.33.0rc1
6.33.0rc2
6.33.1
6.33.2
6.33.3
6.33.4
Fixed in
5.29.6
6.33.5
References
Updated Jul 07, 2026 · Source: OSV.dev |
6.33.0
minor
|
|
6.33.0rc2
pre
1 CVE
CVE-2026-0994
PYSEC-2026-1805
GHSA-7gcm-g887-7qv7
Jul 07, 2026
protobuf affected by a JSON recursion depth bypass
High
Network
Low
None
None
A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages. Due to missing recursion depth accounting inside the internal Any-handling logic, an attacker can supply deeply nested Any structures that bypass the intended recursion limit, eventually exhausting Python’s recursion stack and causing a RecursionError. Affected versions
2.0.0beta
2.0.3
2.3.0
2.4.1
2.5.0
2.6.0
2.6.1
3.0.0
3.0.0a2
3.0.0a3
3.0.0b1
3.0.0b1.post1
+ 193 more Show less
3.0.0b1.post2
3.0.0b2
3.0.0b2.post1
3.0.0b2.post2
3.0.0b3
3.0.0b4
3.1.0
3.1.0.post1
3.10.0
3.10.0rc1
3.11.0
3.11.0rc1
3.11.0rc2
3.11.1
3.11.2
3.11.3
3.12.0
3.12.0rc1
3.12.0rc2
3.12.1
3.12.2
3.12.4
3.13.0
3.13.0rc3
3.14.0
3.14.0rc1
3.14.0rc2
3.14.0rc3
3.15.0
3.15.0rc1
3.15.0rc2
3.15.1
3.15.2
3.15.3
3.15.4
3.15.5
3.15.6
3.15.7
3.15.8
3.16.0
3.16.0rc1
3.16.0rc2
3.17.0
3.17.0rc1
3.17.0rc2
3.17.1
3.17.2
3.17.3
3.18.0
3.18.0rc1
3.18.0rc2
3.18.1
3.18.3
3.19.0
3.19.0rc1
3.19.0rc2
3.19.1
3.19.2
3.19.3
3.19.4
3.19.5
3.19.6
3.2.0
3.2.0rc1
3.2.0rc1.post1
3.2.0rc2
3.20.0
3.20.0rc1
3.20.0rc2
3.20.1
3.20.1rc1
3.20.2
3.20.3
3.3.0
3.4.0
3.5.0.post1
3.5.1
3.5.2
3.5.2.post1
3.6.0
3.6.1
3.7.0
3.7.0rc2
3.7.0rc3
3.7.1
3.8.0
3.8.0rc1
3.9.0
3.9.0rc1
3.9.1
3.9.2
4.0.0rc1
4.0.0rc2
4.21.0
4.21.0rc1
4.21.0rc2
4.21.1
4.21.10
4.21.11
4.21.12
4.21.2
4.21.3
4.21.4
4.21.5
4.21.6
4.21.7
4.21.8
4.21.9
4.22.0
4.22.0rc1
4.22.0rc2
4.22.0rc3
4.22.1
4.22.3
4.22.4
4.22.5
4.23.0
4.23.0rc2
4.23.0rc3
4.23.1
4.23.2
4.23.3
4.23.4
4.24.0
4.24.0rc1
4.24.0rc2
4.24.0rc3
4.24.1
4.24.2
4.24.3
4.24.4
4.25.0
4.25.0rc1
4.25.0rc2
4.25.1
4.25.2
4.25.3
4.25.4
4.25.5
4.25.6
4.25.7
4.25.8
4.25.9
5.26.0
5.26.0rc1
5.26.0rc2
5.26.0rc3
5.26.1
5.27.0
5.27.0rc1
5.27.0rc2
5.27.0rc3
5.27.1
5.27.2
5.27.3
5.27.4
5.27.5
5.28.0
5.28.0rc1
5.28.0rc2
5.28.0rc3
5.28.1
5.28.2
5.28.3
5.29.0
5.29.0rc1
5.29.0rc2
5.29.0rc3
5.29.1
5.29.2
5.29.3
5.29.4
5.29.5
6.30.0
6.30.0rc1
6.30.0rc2
6.30.1
6.30.2
6.31.0
6.31.0rc1
6.31.0rc2
6.31.1
6.32.0
6.32.0rc1
6.32.0rc2
6.32.1
6.33.0
6.33.0rc1
6.33.0rc2
6.33.1
6.33.2
6.33.3
6.33.4
Fixed in
5.29.6
6.33.5
References
Updated Jul 07, 2026 · Source: OSV.dev |
6.33.0rc2
pre
|
|
6.33.0rc1
pre
1 CVE
CVE-2026-0994
PYSEC-2026-1805
GHSA-7gcm-g887-7qv7
Jul 07, 2026
protobuf affected by a JSON recursion depth bypass
High
Network
Low
None
None
A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages. Due to missing recursion depth accounting inside the internal Any-handling logic, an attacker can supply deeply nested Any structures that bypass the intended recursion limit, eventually exhausting Python’s recursion stack and causing a RecursionError. Affected versions
2.0.0beta
2.0.3
2.3.0
2.4.1
2.5.0
2.6.0
2.6.1
3.0.0
3.0.0a2
3.0.0a3
3.0.0b1
3.0.0b1.post1
+ 193 more Show less
3.0.0b1.post2
3.0.0b2
3.0.0b2.post1
3.0.0b2.post2
3.0.0b3
3.0.0b4
3.1.0
3.1.0.post1
3.10.0
3.10.0rc1
3.11.0
3.11.0rc1
3.11.0rc2
3.11.1
3.11.2
3.11.3
3.12.0
3.12.0rc1
3.12.0rc2
3.12.1
3.12.2
3.12.4
3.13.0
3.13.0rc3
3.14.0
3.14.0rc1
3.14.0rc2
3.14.0rc3
3.15.0
3.15.0rc1
3.15.0rc2
3.15.1
3.15.2
3.15.3
3.15.4
3.15.5
3.15.6
3.15.7
3.15.8
3.16.0
3.16.0rc1
3.16.0rc2
3.17.0
3.17.0rc1
3.17.0rc2
3.17.1
3.17.2
3.17.3
3.18.0
3.18.0rc1
3.18.0rc2
3.18.1
3.18.3
3.19.0
3.19.0rc1
3.19.0rc2
3.19.1
3.19.2
3.19.3
3.19.4
3.19.5
3.19.6
3.2.0
3.2.0rc1
3.2.0rc1.post1
3.2.0rc2
3.20.0
3.20.0rc1
3.20.0rc2
3.20.1
3.20.1rc1
3.20.2
3.20.3
3.3.0
3.4.0
3.5.0.post1
3.5.1
3.5.2
3.5.2.post1
3.6.0
3.6.1
3.7.0
3.7.0rc2
3.7.0rc3
3.7.1
3.8.0
3.8.0rc1
3.9.0
3.9.0rc1
3.9.1
3.9.2
4.0.0rc1
4.0.0rc2
4.21.0
4.21.0rc1
4.21.0rc2
4.21.1
4.21.10
4.21.11
4.21.12
4.21.2
4.21.3
4.21.4
4.21.5
4.21.6
4.21.7
4.21.8
4.21.9
4.22.0
4.22.0rc1
4.22.0rc2
4.22.0rc3
4.22.1
4.22.3
4.22.4
4.22.5
4.23.0
4.23.0rc2
4.23.0rc3
4.23.1
4.23.2
4.23.3
4.23.4
4.24.0
4.24.0rc1
4.24.0rc2
4.24.0rc3
4.24.1
4.24.2
4.24.3
4.24.4
4.25.0
4.25.0rc1
4.25.0rc2
4.25.1
4.25.2
4.25.3
4.25.4
4.25.5
4.25.6
4.25.7
4.25.8
4.25.9
5.26.0
5.26.0rc1
5.26.0rc2
5.26.0rc3
5.26.1
5.27.0
5.27.0rc1
5.27.0rc2
5.27.0rc3
5.27.1
5.27.2
5.27.3
5.27.4
5.27.5
5.28.0
5.28.0rc1
5.28.0rc2
5.28.0rc3
5.28.1
5.28.2
5.28.3
5.29.0
5.29.0rc1
5.29.0rc2
5.29.0rc3
5.29.1
5.29.2
5.29.3
5.29.4
5.29.5
6.30.0
6.30.0rc1
6.30.0rc2
6.30.1
6.30.2
6.31.0
6.31.0rc1
6.31.0rc2
6.31.1
6.32.0
6.32.0rc1
6.32.0rc2
6.32.1
6.33.0
6.33.0rc1
6.33.0rc2
6.33.1
6.33.2
6.33.3
6.33.4
Fixed in
5.29.6
6.33.5
References
Updated Jul 07, 2026 · Source: OSV.dev |
6.33.0rc1
pre
|
|
6.32.1
patch
1 CVE
CVE-2026-0994
PYSEC-2026-1805
GHSA-7gcm-g887-7qv7
Jul 07, 2026
protobuf affected by a JSON recursion depth bypass
High
Network
Low
None
None
A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages. Due to missing recursion depth accounting inside the internal Any-handling logic, an attacker can supply deeply nested Any structures that bypass the intended recursion limit, eventually exhausting Python’s recursion stack and causing a RecursionError. Affected versions
2.0.0beta
2.0.3
2.3.0
2.4.1
2.5.0
2.6.0
2.6.1
3.0.0
3.0.0a2
3.0.0a3
3.0.0b1
3.0.0b1.post1
+ 193 more Show less
3.0.0b1.post2
3.0.0b2
3.0.0b2.post1
3.0.0b2.post2
3.0.0b3
3.0.0b4
3.1.0
3.1.0.post1
3.10.0
3.10.0rc1
3.11.0
3.11.0rc1
3.11.0rc2
3.11.1
3.11.2
3.11.3
3.12.0
3.12.0rc1
3.12.0rc2
3.12.1
3.12.2
3.12.4
3.13.0
3.13.0rc3
3.14.0
3.14.0rc1
3.14.0rc2
3.14.0rc3
3.15.0
3.15.0rc1
3.15.0rc2
3.15.1
3.15.2
3.15.3
3.15.4
3.15.5
3.15.6
3.15.7
3.15.8
3.16.0
3.16.0rc1
3.16.0rc2
3.17.0
3.17.0rc1
3.17.0rc2
3.17.1
3.17.2
3.17.3
3.18.0
3.18.0rc1
3.18.0rc2
3.18.1
3.18.3
3.19.0
3.19.0rc1
3.19.0rc2
3.19.1
3.19.2
3.19.3
3.19.4
3.19.5
3.19.6
3.2.0
3.2.0rc1
3.2.0rc1.post1
3.2.0rc2
3.20.0
3.20.0rc1
3.20.0rc2
3.20.1
3.20.1rc1
3.20.2
3.20.3
3.3.0
3.4.0
3.5.0.post1
3.5.1
3.5.2
3.5.2.post1
3.6.0
3.6.1
3.7.0
3.7.0rc2
3.7.0rc3
3.7.1
3.8.0
3.8.0rc1
3.9.0
3.9.0rc1
3.9.1
3.9.2
4.0.0rc1
4.0.0rc2
4.21.0
4.21.0rc1
4.21.0rc2
4.21.1
4.21.10
4.21.11
4.21.12
4.21.2
4.21.3
4.21.4
4.21.5
4.21.6
4.21.7
4.21.8
4.21.9
4.22.0
4.22.0rc1
4.22.0rc2
4.22.0rc3
4.22.1
4.22.3
4.22.4
4.22.5
4.23.0
4.23.0rc2
4.23.0rc3
4.23.1
4.23.2
4.23.3
4.23.4
4.24.0
4.24.0rc1
4.24.0rc2
4.24.0rc3
4.24.1
4.24.2
4.24.3
4.24.4
4.25.0
4.25.0rc1
4.25.0rc2
4.25.1
4.25.2
4.25.3
4.25.4
4.25.5
4.25.6
4.25.7
4.25.8
4.25.9
5.26.0
5.26.0rc1
5.26.0rc2
5.26.0rc3
5.26.1
5.27.0
5.27.0rc1
5.27.0rc2
5.27.0rc3
5.27.1
5.27.2
5.27.3
5.27.4
5.27.5
5.28.0
5.28.0rc1
5.28.0rc2
5.28.0rc3
5.28.1
5.28.2
5.28.3
5.29.0
5.29.0rc1
5.29.0rc2
5.29.0rc3
5.29.1
5.29.2
5.29.3
5.29.4
5.29.5
6.30.0
6.30.0rc1
6.30.0rc2
6.30.1
6.30.2
6.31.0
6.31.0rc1
6.31.0rc2
6.31.1
6.32.0
6.32.0rc1
6.32.0rc2
6.32.1
6.33.0
6.33.0rc1
6.33.0rc2
6.33.1
6.33.2
6.33.3
6.33.4
Fixed in
5.29.6
6.33.5
References
Updated Jul 07, 2026 · Source: OSV.dev |
6.32.1
patch
|
|
6.32.0
minor
1 CVE
CVE-2026-0994
PYSEC-2026-1805
GHSA-7gcm-g887-7qv7
Jul 07, 2026
protobuf affected by a JSON recursion depth bypass
High
Network
Low
None
None
A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages. Due to missing recursion depth accounting inside the internal Any-handling logic, an attacker can supply deeply nested Any structures that bypass the intended recursion limit, eventually exhausting Python’s recursion stack and causing a RecursionError. Affected versions
2.0.0beta
2.0.3
2.3.0
2.4.1
2.5.0
2.6.0
2.6.1
3.0.0
3.0.0a2
3.0.0a3
3.0.0b1
3.0.0b1.post1
+ 193 more Show less
3.0.0b1.post2
3.0.0b2
3.0.0b2.post1
3.0.0b2.post2
3.0.0b3
3.0.0b4
3.1.0
3.1.0.post1
3.10.0
3.10.0rc1
3.11.0
3.11.0rc1
3.11.0rc2
3.11.1
3.11.2
3.11.3
3.12.0
3.12.0rc1
3.12.0rc2
3.12.1
3.12.2
3.12.4
3.13.0
3.13.0rc3
3.14.0
3.14.0rc1
3.14.0rc2
3.14.0rc3
3.15.0
3.15.0rc1
3.15.0rc2
3.15.1
3.15.2
3.15.3
3.15.4
3.15.5
3.15.6
3.15.7
3.15.8
3.16.0
3.16.0rc1
3.16.0rc2
3.17.0
3.17.0rc1
3.17.0rc2
3.17.1
3.17.2
3.17.3
3.18.0
3.18.0rc1
3.18.0rc2
3.18.1
3.18.3
3.19.0
3.19.0rc1
3.19.0rc2
3.19.1
3.19.2
3.19.3
3.19.4
3.19.5
3.19.6
3.2.0
3.2.0rc1
3.2.0rc1.post1
3.2.0rc2
3.20.0
3.20.0rc1
3.20.0rc2
3.20.1
3.20.1rc1
3.20.2
3.20.3
3.3.0
3.4.0
3.5.0.post1
3.5.1
3.5.2
3.5.2.post1
3.6.0
3.6.1
3.7.0
3.7.0rc2
3.7.0rc3
3.7.1
3.8.0
3.8.0rc1
3.9.0
3.9.0rc1
3.9.1
3.9.2
4.0.0rc1
4.0.0rc2
4.21.0
4.21.0rc1
4.21.0rc2
4.21.1
4.21.10
4.21.11
4.21.12
4.21.2
4.21.3
4.21.4
4.21.5
4.21.6
4.21.7
4.21.8
4.21.9
4.22.0
4.22.0rc1
4.22.0rc2
4.22.0rc3
4.22.1
4.22.3
4.22.4
4.22.5
4.23.0
4.23.0rc2
4.23.0rc3
4.23.1
4.23.2
4.23.3
4.23.4
4.24.0
4.24.0rc1
4.24.0rc2
4.24.0rc3
4.24.1
4.24.2
4.24.3
4.24.4
4.25.0
4.25.0rc1
4.25.0rc2
4.25.1
4.25.2
4.25.3
4.25.4
4.25.5
4.25.6
4.25.7
4.25.8
4.25.9
5.26.0
5.26.0rc1
5.26.0rc2
5.26.0rc3
5.26.1
5.27.0
5.27.0rc1
5.27.0rc2
5.27.0rc3
5.27.1
5.27.2
5.27.3
5.27.4
5.27.5
5.28.0
5.28.0rc1
5.28.0rc2
5.28.0rc3
5.28.1
5.28.2
5.28.3
5.29.0
5.29.0rc1
5.29.0rc2
5.29.0rc3
5.29.1
5.29.2
5.29.3
5.29.4
5.29.5
6.30.0
6.30.0rc1
6.30.0rc2
6.30.1
6.30.2
6.31.0
6.31.0rc1
6.31.0rc2
6.31.1
6.32.0
6.32.0rc1
6.32.0rc2
6.32.1
6.33.0
6.33.0rc1
6.33.0rc2
6.33.1
6.33.2
6.33.3
6.33.4
Fixed in
5.29.6
6.33.5
References
Updated Jul 07, 2026 · Source: OSV.dev |
6.32.0
minor
|
|
6.32.0rc2
pre
1 CVE
CVE-2026-0994
PYSEC-2026-1805
GHSA-7gcm-g887-7qv7
Jul 07, 2026
protobuf affected by a JSON recursion depth bypass
High
Network
Low
None
None
A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages. Due to missing recursion depth accounting inside the internal Any-handling logic, an attacker can supply deeply nested Any structures that bypass the intended recursion limit, eventually exhausting Python’s recursion stack and causing a RecursionError. Affected versions
2.0.0beta
2.0.3
2.3.0
2.4.1
2.5.0
2.6.0
2.6.1
3.0.0
3.0.0a2
3.0.0a3
3.0.0b1
3.0.0b1.post1
+ 193 more Show less
3.0.0b1.post2
3.0.0b2
3.0.0b2.post1
3.0.0b2.post2
3.0.0b3
3.0.0b4
3.1.0
3.1.0.post1
3.10.0
3.10.0rc1
3.11.0
3.11.0rc1
3.11.0rc2
3.11.1
3.11.2
3.11.3
3.12.0
3.12.0rc1
3.12.0rc2
3.12.1
3.12.2
3.12.4
3.13.0
3.13.0rc3
3.14.0
3.14.0rc1
3.14.0rc2
3.14.0rc3
3.15.0
3.15.0rc1
3.15.0rc2
3.15.1
3.15.2
3.15.3
3.15.4
3.15.5
3.15.6
3.15.7
3.15.8
3.16.0
3.16.0rc1
3.16.0rc2
3.17.0
3.17.0rc1
3.17.0rc2
3.17.1
3.17.2
3.17.3
3.18.0
3.18.0rc1
3.18.0rc2
3.18.1
3.18.3
3.19.0
3.19.0rc1
3.19.0rc2
3.19.1
3.19.2
3.19.3
3.19.4
3.19.5
3.19.6
3.2.0
3.2.0rc1
3.2.0rc1.post1
3.2.0rc2
3.20.0
3.20.0rc1
3.20.0rc2
3.20.1
3.20.1rc1
3.20.2
3.20.3
3.3.0
3.4.0
3.5.0.post1
3.5.1
3.5.2
3.5.2.post1
3.6.0
3.6.1
3.7.0
3.7.0rc2
3.7.0rc3
3.7.1
3.8.0
3.8.0rc1
3.9.0
3.9.0rc1
3.9.1
3.9.2
4.0.0rc1
4.0.0rc2
4.21.0
4.21.0rc1
4.21.0rc2
4.21.1
4.21.10
4.21.11
4.21.12
4.21.2
4.21.3
4.21.4
4.21.5
4.21.6
4.21.7
4.21.8
4.21.9
4.22.0
4.22.0rc1
4.22.0rc2
4.22.0rc3
4.22.1
4.22.3
4.22.4
4.22.5
4.23.0
4.23.0rc2
4.23.0rc3
4.23.1
4.23.2
4.23.3
4.23.4
4.24.0
4.24.0rc1
4.24.0rc2
4.24.0rc3
4.24.1
4.24.2
4.24.3
4.24.4
4.25.0
4.25.0rc1
4.25.0rc2
4.25.1
4.25.2
4.25.3
4.25.4
4.25.5
4.25.6
4.25.7
4.25.8
4.25.9
5.26.0
5.26.0rc1
5.26.0rc2
5.26.0rc3
5.26.1
5.27.0
5.27.0rc1
5.27.0rc2
5.27.0rc3
5.27.1
5.27.2
5.27.3
5.27.4
5.27.5
5.28.0
5.28.0rc1
5.28.0rc2
5.28.0rc3
5.28.1
5.28.2
5.28.3
5.29.0
5.29.0rc1
5.29.0rc2
5.29.0rc3
5.29.1
5.29.2
5.29.3
5.29.4
5.29.5
6.30.0
6.30.0rc1
6.30.0rc2
6.30.1
6.30.2
6.31.0
6.31.0rc1
6.31.0rc2
6.31.1
6.32.0
6.32.0rc1
6.32.0rc2
6.32.1
6.33.0
6.33.0rc1
6.33.0rc2
6.33.1
6.33.2
6.33.3
6.33.4
Fixed in
5.29.6
6.33.5
References
Updated Jul 07, 2026 · Source: OSV.dev |
6.32.0rc2
pre
|
|
6.32.0rc1
pre
1 CVE
CVE-2026-0994
PYSEC-2026-1805
GHSA-7gcm-g887-7qv7
Jul 07, 2026
protobuf affected by a JSON recursion depth bypass
High
Network
Low
None
None
A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages. Due to missing recursion depth accounting inside the internal Any-handling logic, an attacker can supply deeply nested Any structures that bypass the intended recursion limit, eventually exhausting Python’s recursion stack and causing a RecursionError. Affected versions
2.0.0beta
2.0.3
2.3.0
2.4.1
2.5.0
2.6.0
2.6.1
3.0.0
3.0.0a2
3.0.0a3
3.0.0b1
3.0.0b1.post1
+ 193 more Show less
3.0.0b1.post2
3.0.0b2
3.0.0b2.post1
3.0.0b2.post2
3.0.0b3
3.0.0b4
3.1.0
3.1.0.post1
3.10.0
3.10.0rc1
3.11.0
3.11.0rc1
3.11.0rc2
3.11.1
3.11.2
3.11.3
3.12.0
3.12.0rc1
3.12.0rc2
3.12.1
3.12.2
3.12.4
3.13.0
3.13.0rc3
3.14.0
3.14.0rc1
3.14.0rc2
3.14.0rc3
3.15.0
3.15.0rc1
3.15.0rc2
3.15.1
3.15.2
3.15.3
3.15.4
3.15.5
3.15.6
3.15.7
3.15.8
3.16.0
3.16.0rc1
3.16.0rc2
3.17.0
3.17.0rc1
3.17.0rc2
3.17.1
3.17.2
3.17.3
3.18.0
3.18.0rc1
3.18.0rc2
3.18.1
3.18.3
3.19.0
3.19.0rc1
3.19.0rc2
3.19.1
3.19.2
3.19.3
3.19.4
3.19.5
3.19.6
3.2.0
3.2.0rc1
3.2.0rc1.post1
3.2.0rc2
3.20.0
3.20.0rc1
3.20.0rc2
3.20.1
3.20.1rc1
3.20.2
3.20.3
3.3.0
3.4.0
3.5.0.post1
3.5.1
3.5.2
3.5.2.post1
3.6.0
3.6.1
3.7.0
3.7.0rc2
3.7.0rc3
3.7.1
3.8.0
3.8.0rc1
3.9.0
3.9.0rc1
3.9.1
3.9.2
4.0.0rc1
4.0.0rc2
4.21.0
4.21.0rc1
4.21.0rc2
4.21.1
4.21.10
4.21.11
4.21.12
4.21.2
4.21.3
4.21.4
4.21.5
4.21.6
4.21.7
4.21.8
4.21.9
4.22.0
4.22.0rc1
4.22.0rc2
4.22.0rc3
4.22.1
4.22.3
4.22.4
4.22.5
4.23.0
4.23.0rc2
4.23.0rc3
4.23.1
4.23.2
4.23.3
4.23.4
4.24.0
4.24.0rc1
4.24.0rc2
4.24.0rc3
4.24.1
4.24.2
4.24.3
4.24.4
4.25.0
4.25.0rc1
4.25.0rc2
4.25.1
4.25.2
4.25.3
4.25.4
4.25.5
4.25.6
4.25.7
4.25.8
4.25.9
5.26.0
5.26.0rc1
5.26.0rc2
5.26.0rc3
5.26.1
5.27.0
5.27.0rc1
5.27.0rc2
5.27.0rc3
5.27.1
5.27.2
5.27.3
5.27.4
5.27.5
5.28.0
5.28.0rc1
5.28.0rc2
5.28.0rc3
5.28.1
5.28.2
5.28.3
5.29.0
5.29.0rc1
5.29.0rc2
5.29.0rc3
5.29.1
5.29.2
5.29.3
5.29.4
5.29.5
6.30.0
6.30.0rc1
6.30.0rc2
6.30.1
6.30.2
6.31.0
6.31.0rc1
6.31.0rc2
6.31.1
6.32.0
6.32.0rc1
6.32.0rc2
6.32.1
6.33.0
6.33.0rc1
6.33.0rc2
6.33.1
6.33.2
6.33.3
6.33.4
Fixed in
5.29.6
6.33.5
References
Updated Jul 07, 2026 · Source: OSV.dev |
6.32.0rc1
pre
|
|
5.29.5
patch
1 CVE
CVE-2026-0994
PYSEC-2026-1805
GHSA-7gcm-g887-7qv7
Jul 07, 2026
protobuf affected by a JSON recursion depth bypass
High
Network
Low
None
None
A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages. Due to missing recursion depth accounting inside the internal Any-handling logic, an attacker can supply deeply nested Any structures that bypass the intended recursion limit, eventually exhausting Python’s recursion stack and causing a RecursionError. Affected versions
2.0.0beta
2.0.3
2.3.0
2.4.1
2.5.0
2.6.0
2.6.1
3.0.0
3.0.0a2
3.0.0a3
3.0.0b1
3.0.0b1.post1
+ 193 more Show less
3.0.0b1.post2
3.0.0b2
3.0.0b2.post1
3.0.0b2.post2
3.0.0b3
3.0.0b4
3.1.0
3.1.0.post1
3.10.0
3.10.0rc1
3.11.0
3.11.0rc1
3.11.0rc2
3.11.1
3.11.2
3.11.3
3.12.0
3.12.0rc1
3.12.0rc2
3.12.1
3.12.2
3.12.4
3.13.0
3.13.0rc3
3.14.0
3.14.0rc1
3.14.0rc2
3.14.0rc3
3.15.0
3.15.0rc1
3.15.0rc2
3.15.1
3.15.2
3.15.3
3.15.4
3.15.5
3.15.6
3.15.7
3.15.8
3.16.0
3.16.0rc1
3.16.0rc2
3.17.0
3.17.0rc1
3.17.0rc2
3.17.1
3.17.2
3.17.3
3.18.0
3.18.0rc1
3.18.0rc2
3.18.1
3.18.3
3.19.0
3.19.0rc1
3.19.0rc2
3.19.1
3.19.2
3.19.3
3.19.4
3.19.5
3.19.6
3.2.0
3.2.0rc1
3.2.0rc1.post1
3.2.0rc2
3.20.0
3.20.0rc1
3.20.0rc2
3.20.1
3.20.1rc1
3.20.2
3.20.3
3.3.0
3.4.0
3.5.0.post1
3.5.1
3.5.2
3.5.2.post1
3.6.0
3.6.1
3.7.0
3.7.0rc2
3.7.0rc3
3.7.1
3.8.0
3.8.0rc1
3.9.0
3.9.0rc1
3.9.1
3.9.2
4.0.0rc1
4.0.0rc2
4.21.0
4.21.0rc1
4.21.0rc2
4.21.1
4.21.10
4.21.11
4.21.12
4.21.2
4.21.3
4.21.4
4.21.5
4.21.6
4.21.7
4.21.8
4.21.9
4.22.0
4.22.0rc1
4.22.0rc2
4.22.0rc3
4.22.1
4.22.3
4.22.4
4.22.5
4.23.0
4.23.0rc2
4.23.0rc3
4.23.1
4.23.2
4.23.3
4.23.4
4.24.0
4.24.0rc1
4.24.0rc2
4.24.0rc3
4.24.1
4.24.2
4.24.3
4.24.4
4.25.0
4.25.0rc1
4.25.0rc2
4.25.1
4.25.2
4.25.3
4.25.4
4.25.5
4.25.6
4.25.7
4.25.8
4.25.9
5.26.0
5.26.0rc1
5.26.0rc2
5.26.0rc3
5.26.1
5.27.0
5.27.0rc1
5.27.0rc2
5.27.0rc3
5.27.1
5.27.2
5.27.3
5.27.4
5.27.5
5.28.0
5.28.0rc1
5.28.0rc2
5.28.0rc3
5.28.1
5.28.2
5.28.3
5.29.0
5.29.0rc1
5.29.0rc2
5.29.0rc3
5.29.1
5.29.2
5.29.3
5.29.4
5.29.5
6.30.0
6.30.0rc1
6.30.0rc2
6.30.1
6.30.2
6.31.0
6.31.0rc1
6.31.0rc2
6.31.1
6.32.0
6.32.0rc1
6.32.0rc2
6.32.1
6.33.0
6.33.0rc1
6.33.0rc2
6.33.1
6.33.2
6.33.3
6.33.4
Fixed in
5.29.6
6.33.5
References
Updated Jul 07, 2026 · Source: OSV.dev |
5.29.5
patch
|
|
6.31.1
patch
1 CVE
CVE-2026-0994
PYSEC-2026-1805
GHSA-7gcm-g887-7qv7
Jul 07, 2026
protobuf affected by a JSON recursion depth bypass
High
Network
Low
None
None
A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages. Due to missing recursion depth accounting inside the internal Any-handling logic, an attacker can supply deeply nested Any structures that bypass the intended recursion limit, eventually exhausting Python’s recursion stack and causing a RecursionError. Affected versions
2.0.0beta
2.0.3
2.3.0
2.4.1
2.5.0
2.6.0
2.6.1
3.0.0
3.0.0a2
3.0.0a3
3.0.0b1
3.0.0b1.post1
+ 193 more Show less
3.0.0b1.post2
3.0.0b2
3.0.0b2.post1
3.0.0b2.post2
3.0.0b3
3.0.0b4
3.1.0
3.1.0.post1
3.10.0
3.10.0rc1
3.11.0
3.11.0rc1
3.11.0rc2
3.11.1
3.11.2
3.11.3
3.12.0
3.12.0rc1
3.12.0rc2
3.12.1
3.12.2
3.12.4
3.13.0
3.13.0rc3
3.14.0
3.14.0rc1
3.14.0rc2
3.14.0rc3
3.15.0
3.15.0rc1
3.15.0rc2
3.15.1
3.15.2
3.15.3
3.15.4
3.15.5
3.15.6
3.15.7
3.15.8
3.16.0
3.16.0rc1
3.16.0rc2
3.17.0
3.17.0rc1
3.17.0rc2
3.17.1
3.17.2
3.17.3
3.18.0
3.18.0rc1
3.18.0rc2
3.18.1
3.18.3
3.19.0
3.19.0rc1
3.19.0rc2
3.19.1
3.19.2
3.19.3
3.19.4
3.19.5
3.19.6
3.2.0
3.2.0rc1
3.2.0rc1.post1
3.2.0rc2
3.20.0
3.20.0rc1
3.20.0rc2
3.20.1
3.20.1rc1
3.20.2
3.20.3
3.3.0
3.4.0
3.5.0.post1
3.5.1
3.5.2
3.5.2.post1
3.6.0
3.6.1
3.7.0
3.7.0rc2
3.7.0rc3
3.7.1
3.8.0
3.8.0rc1
3.9.0
3.9.0rc1
3.9.1
3.9.2
4.0.0rc1
4.0.0rc2
4.21.0
4.21.0rc1
4.21.0rc2
4.21.1
4.21.10
4.21.11
4.21.12
4.21.2
4.21.3
4.21.4
4.21.5
4.21.6
4.21.7
4.21.8
4.21.9
4.22.0
4.22.0rc1
4.22.0rc2
4.22.0rc3
4.22.1
4.22.3
4.22.4
4.22.5
4.23.0
4.23.0rc2
4.23.0rc3
4.23.1
4.23.2
4.23.3
4.23.4
4.24.0
4.24.0rc1
4.24.0rc2
4.24.0rc3
4.24.1
4.24.2
4.24.3
4.24.4
4.25.0
4.25.0rc1
4.25.0rc2
4.25.1
4.25.2
4.25.3
4.25.4
4.25.5
4.25.6
4.25.7
4.25.8
4.25.9
5.26.0
5.26.0rc1
5.26.0rc2
5.26.0rc3
5.26.1
5.27.0
5.27.0rc1
5.27.0rc2
5.27.0rc3
5.27.1
5.27.2
5.27.3
5.27.4
5.27.5
5.28.0
5.28.0rc1
5.28.0rc2
5.28.0rc3
5.28.1
5.28.2
5.28.3
5.29.0
5.29.0rc1
5.29.0rc2
5.29.0rc3
5.29.1
5.29.2
5.29.3
5.29.4
5.29.5
6.30.0
6.30.0rc1
6.30.0rc2
6.30.1
6.30.2
6.31.0
6.31.0rc1
6.31.0rc2
6.31.1
6.32.0
6.32.0rc1
6.32.0rc2
6.32.1
6.33.0
6.33.0rc1
6.33.0rc2
6.33.1
6.33.2
6.33.3
6.33.4
Fixed in
5.29.6
6.33.5
References
Updated Jul 07, 2026 · Source: OSV.dev |
6.31.1
patch
|
|
4.25.8
patch
1 CVE
CVE-2026-0994
PYSEC-2026-1805
GHSA-7gcm-g887-7qv7
Jul 07, 2026
protobuf affected by a JSON recursion depth bypass
High
Network
Low
None
None
A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages. Due to missing recursion depth accounting inside the internal Any-handling logic, an attacker can supply deeply nested Any structures that bypass the intended recursion limit, eventually exhausting Python’s recursion stack and causing a RecursionError. Affected versions
2.0.0beta
2.0.3
2.3.0
2.4.1
2.5.0
2.6.0
2.6.1
3.0.0
3.0.0a2
3.0.0a3
3.0.0b1
3.0.0b1.post1
+ 193 more Show less
3.0.0b1.post2
3.0.0b2
3.0.0b2.post1
3.0.0b2.post2
3.0.0b3
3.0.0b4
3.1.0
3.1.0.post1
3.10.0
3.10.0rc1
3.11.0
3.11.0rc1
3.11.0rc2
3.11.1
3.11.2
3.11.3
3.12.0
3.12.0rc1
3.12.0rc2
3.12.1
3.12.2
3.12.4
3.13.0
3.13.0rc3
3.14.0
3.14.0rc1
3.14.0rc2
3.14.0rc3
3.15.0
3.15.0rc1
3.15.0rc2
3.15.1
3.15.2
3.15.3
3.15.4
3.15.5
3.15.6
3.15.7
3.15.8
3.16.0
3.16.0rc1
3.16.0rc2
3.17.0
3.17.0rc1
3.17.0rc2
3.17.1
3.17.2
3.17.3
3.18.0
3.18.0rc1
3.18.0rc2
3.18.1
3.18.3
3.19.0
3.19.0rc1
3.19.0rc2
3.19.1
3.19.2
3.19.3
3.19.4
3.19.5
3.19.6
3.2.0
3.2.0rc1
3.2.0rc1.post1
3.2.0rc2
3.20.0
3.20.0rc1
3.20.0rc2
3.20.1
3.20.1rc1
3.20.2
3.20.3
3.3.0
3.4.0
3.5.0.post1
3.5.1
3.5.2
3.5.2.post1
3.6.0
3.6.1
3.7.0
3.7.0rc2
3.7.0rc3
3.7.1
3.8.0
3.8.0rc1
3.9.0
3.9.0rc1
3.9.1
3.9.2
4.0.0rc1
4.0.0rc2
4.21.0
4.21.0rc1
4.21.0rc2
4.21.1
4.21.10
4.21.11
4.21.12
4.21.2
4.21.3
4.21.4
4.21.5
4.21.6
4.21.7
4.21.8
4.21.9
4.22.0
4.22.0rc1
4.22.0rc2
4.22.0rc3
4.22.1
4.22.3
4.22.4
4.22.5
4.23.0
4.23.0rc2
4.23.0rc3
4.23.1
4.23.2
4.23.3
4.23.4
4.24.0
4.24.0rc1
4.24.0rc2
4.24.0rc3
4.24.1
4.24.2
4.24.3
4.24.4
4.25.0
4.25.0rc1
4.25.0rc2
4.25.1
4.25.2
4.25.3
4.25.4
4.25.5
4.25.6
4.25.7
4.25.8
4.25.9
5.26.0
5.26.0rc1
5.26.0rc2
5.26.0rc3
5.26.1
5.27.0
5.27.0rc1
5.27.0rc2
5.27.0rc3
5.27.1
5.27.2
5.27.3
5.27.4
5.27.5
5.28.0
5.28.0rc1
5.28.0rc2
5.28.0rc3
5.28.1
5.28.2
5.28.3
5.29.0
5.29.0rc1
5.29.0rc2
5.29.0rc3
5.29.1
5.29.2
5.29.3
5.29.4
5.29.5
6.30.0
6.30.0rc1
6.30.0rc2
6.30.1
6.30.2
6.31.0
6.31.0rc1
6.31.0rc2
6.31.1
6.32.0
6.32.0rc1
6.32.0rc2
6.32.1
6.33.0
6.33.0rc1
6.33.0rc2
6.33.1
6.33.2
6.33.3
6.33.4
Fixed in
5.29.6
6.33.5
References
Updated Jul 07, 2026 · Source: OSV.dev |
4.25.8
patch
|
|
6.31.0
minor
2 CVEs
CVE-2026-0994
PYSEC-2026-1805
GHSA-7gcm-g887-7qv7
Jul 07, 2026
protobuf affected by a JSON recursion depth bypass
High
Network
Low
None
None
A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages. Due to missing recursion depth accounting inside the internal Any-handling logic, an attacker can supply deeply nested Any structures that bypass the intended recursion limit, eventually exhausting Python’s recursion stack and causing a RecursionError. Affected versions
2.0.0beta
2.0.3
2.3.0
2.4.1
2.5.0
2.6.0
2.6.1
3.0.0
3.0.0a2
3.0.0a3
3.0.0b1
3.0.0b1.post1
+ 193 more Show less
3.0.0b1.post2
3.0.0b2
3.0.0b2.post1
3.0.0b2.post2
3.0.0b3
3.0.0b4
3.1.0
3.1.0.post1
3.10.0
3.10.0rc1
3.11.0
3.11.0rc1
3.11.0rc2
3.11.1
3.11.2
3.11.3
3.12.0
3.12.0rc1
3.12.0rc2
3.12.1
3.12.2
3.12.4
3.13.0
3.13.0rc3
3.14.0
3.14.0rc1
3.14.0rc2
3.14.0rc3
3.15.0
3.15.0rc1
3.15.0rc2
3.15.1
3.15.2
3.15.3
3.15.4
3.15.5
3.15.6
3.15.7
3.15.8
3.16.0
3.16.0rc1
3.16.0rc2
3.17.0
3.17.0rc1
3.17.0rc2
3.17.1
3.17.2
3.17.3
3.18.0
3.18.0rc1
3.18.0rc2
3.18.1
3.18.3
3.19.0
3.19.0rc1
3.19.0rc2
3.19.1
3.19.2
3.19.3
3.19.4
3.19.5
3.19.6
3.2.0
3.2.0rc1
3.2.0rc1.post1
3.2.0rc2
3.20.0
3.20.0rc1
3.20.0rc2
3.20.1
3.20.1rc1
3.20.2
3.20.3
3.3.0
3.4.0
3.5.0.post1
3.5.1
3.5.2
3.5.2.post1
3.6.0
3.6.1
3.7.0
3.7.0rc2
3.7.0rc3
3.7.1
3.8.0
3.8.0rc1
3.9.0
3.9.0rc1
3.9.1
3.9.2
4.0.0rc1
4.0.0rc2
4.21.0
4.21.0rc1
4.21.0rc2
4.21.1
4.21.10
4.21.11
4.21.12
4.21.2
4.21.3
4.21.4
4.21.5
4.21.6
4.21.7
4.21.8
4.21.9
4.22.0
4.22.0rc1
4.22.0rc2
4.22.0rc3
4.22.1
4.22.3
4.22.4
4.22.5
4.23.0
4.23.0rc2
4.23.0rc3
4.23.1
4.23.2
4.23.3
4.23.4
4.24.0
4.24.0rc1
4.24.0rc2
4.24.0rc3
4.24.1
4.24.2
4.24.3
4.24.4
4.25.0
4.25.0rc1
4.25.0rc2
4.25.1
4.25.2
4.25.3
4.25.4
4.25.5
4.25.6
4.25.7
4.25.8
4.25.9
5.26.0
5.26.0rc1
5.26.0rc2
5.26.0rc3
5.26.1
5.27.0
5.27.0rc1
5.27.0rc2
5.27.0rc3
5.27.1
5.27.2
5.27.3
5.27.4
5.27.5
5.28.0
5.28.0rc1
5.28.0rc2
5.28.0rc3
5.28.1
5.28.2
5.28.3
5.29.0
5.29.0rc1
5.29.0rc2
5.29.0rc3
5.29.1
5.29.2
5.29.3
5.29.4
5.29.5
6.30.0
6.30.0rc1
6.30.0rc2
6.30.1
6.30.2
6.31.0
6.31.0rc1
6.31.0rc2
6.31.1
6.32.0
6.32.0rc1
6.32.0rc2
6.32.1
6.33.0
6.33.0rc1
6.33.0rc2
6.33.1
6.33.2
6.33.3
6.33.4
Fixed in
5.29.6
6.33.5
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-4565
PYSEC-2026-1806
GHSA-8qvm-5x2c-j2w7
Jul 07, 2026
protobuf-python has a potential Denial of Service issue
High
Network
Low
None
None
SummaryAny project that uses Protobuf pure-Python backend to parse untrusted Protocol Buffers data containing an arbitrary number of recursive groups, recursive messages or a series of Reporter: Alexis Challande, Trail of Bits Ecosystem Security Team ecosystem@trailofbits.com Affected versions: This issue only affects the pure-Python implementation of protobuf-python backend. This is the implementation when This is a Python variant of a previous issue affecting protobuf-java. SeverityThis is a potential Denial of Service. Parsing nested protobuf data creates unbounded recursions that can be abused by an attacker. Proof of ConceptFor reproduction details, please refer to the unit tests decoder_test.py and message_test Remediation and MitigationA mitigation is available now. Please update to the latest available versions of the following packages:
Affected versions
2.0.0beta
2.0.3
2.3.0
2.4.1
2.5.0
2.6.0
2.6.1
3.0.0
3.0.0a2
3.0.0a3
3.0.0b1
3.0.0b1.post1
+ 178 more Show less
3.0.0b1.post2
3.0.0b2
3.0.0b2.post1
3.0.0b2.post2
3.0.0b3
3.0.0b4
3.1.0
3.1.0.post1
3.10.0
3.10.0rc1
3.11.0
3.11.0rc1
3.11.0rc2
3.11.1
3.11.2
3.11.3
3.12.0
3.12.0rc1
3.12.0rc2
3.12.1
3.12.2
3.12.4
3.13.0
3.13.0rc3
3.14.0
3.14.0rc1
3.14.0rc2
3.14.0rc3
3.15.0
3.15.0rc1
3.15.0rc2
3.15.1
3.15.2
3.15.3
3.15.4
3.15.5
3.15.6
3.15.7
3.15.8
3.16.0
3.16.0rc1
3.16.0rc2
3.17.0
3.17.0rc1
3.17.0rc2
3.17.1
3.17.2
3.17.3
3.18.0
3.18.0rc1
3.18.0rc2
3.18.1
3.18.3
3.19.0
3.19.0rc1
3.19.0rc2
3.19.1
3.19.2
3.19.3
3.19.4
3.19.5
3.19.6
3.2.0
3.2.0rc1
3.2.0rc1.post1
3.2.0rc2
3.20.0
3.20.0rc1
3.20.0rc2
3.20.1
3.20.1rc1
3.20.2
3.20.3
3.3.0
3.4.0
3.5.0.post1
3.5.1
3.5.2
3.5.2.post1
3.6.0
3.6.1
3.7.0
3.7.0rc2
3.7.0rc3
3.7.1
3.8.0
3.8.0rc1
3.9.0
3.9.0rc1
3.9.1
3.9.2
4.0.0rc1
4.0.0rc2
4.21.0
4.21.0rc1
4.21.0rc2
4.21.1
4.21.10
4.21.11
4.21.12
4.21.2
4.21.3
4.21.4
4.21.5
4.21.6
4.21.7
4.21.8
4.21.9
4.22.0
4.22.0rc1
4.22.0rc2
4.22.0rc3
4.22.1
4.22.3
4.22.4
4.22.5
4.23.0
4.23.0rc2
4.23.0rc3
4.23.1
4.23.2
4.23.3
4.23.4
4.24.0
4.24.0rc1
4.24.0rc2
4.24.0rc3
4.24.1
4.24.2
4.24.3
4.24.4
4.25.0
4.25.0rc1
4.25.0rc2
4.25.1
4.25.2
4.25.3
4.25.4
4.25.5
4.25.6
4.25.7
5.26.0
5.26.0rc1
5.26.0rc2
5.26.0rc3
5.26.1
5.27.0
5.27.0rc1
5.27.0rc2
5.27.0rc3
5.27.1
5.27.2
5.27.3
5.27.4
5.27.5
5.28.0
5.28.0rc1
5.28.0rc2
5.28.0rc3
5.28.1
5.28.2
5.28.3
5.29.0
5.29.0rc1
5.29.0rc2
5.29.0rc3
5.29.1
5.29.2
5.29.3
5.29.4
6.30.0
6.30.0rc1
6.30.0rc2
6.30.1
6.30.2
6.31.0
6.31.0rc1
6.31.0rc2
Fixed in
4.25.8
5.29.5
6.31.1
References
Updated Jul 07, 2026 · Source: OSV.dev |
6.31.0
minor
|
|
6.31.0rc2
pre
2 CVEs
CVE-2026-0994
PYSEC-2026-1805
GHSA-7gcm-g887-7qv7
Jul 07, 2026
protobuf affected by a JSON recursion depth bypass
High
Network
Low
None
None
A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages. Due to missing recursion depth accounting inside the internal Any-handling logic, an attacker can supply deeply nested Any structures that bypass the intended recursion limit, eventually exhausting Python’s recursion stack and causing a RecursionError. Affected versions
2.0.0beta
2.0.3
2.3.0
2.4.1
2.5.0
2.6.0
2.6.1
3.0.0
3.0.0a2
3.0.0a3
3.0.0b1
3.0.0b1.post1
+ 193 more Show less
3.0.0b1.post2
3.0.0b2
3.0.0b2.post1
3.0.0b2.post2
3.0.0b3
3.0.0b4
3.1.0
3.1.0.post1
3.10.0
3.10.0rc1
3.11.0
3.11.0rc1
3.11.0rc2
3.11.1
3.11.2
3.11.3
3.12.0
3.12.0rc1
3.12.0rc2
3.12.1
3.12.2
3.12.4
3.13.0
3.13.0rc3
3.14.0
3.14.0rc1
3.14.0rc2
3.14.0rc3
3.15.0
3.15.0rc1
3.15.0rc2
3.15.1
3.15.2
3.15.3
3.15.4
3.15.5
3.15.6
3.15.7
3.15.8
3.16.0
3.16.0rc1
3.16.0rc2
3.17.0
3.17.0rc1
3.17.0rc2
3.17.1
3.17.2
3.17.3
3.18.0
3.18.0rc1
3.18.0rc2
3.18.1
3.18.3
3.19.0
3.19.0rc1
3.19.0rc2
3.19.1
3.19.2
3.19.3
3.19.4
3.19.5
3.19.6
3.2.0
3.2.0rc1
3.2.0rc1.post1
3.2.0rc2
3.20.0
3.20.0rc1
3.20.0rc2
3.20.1
3.20.1rc1
3.20.2
3.20.3
3.3.0
3.4.0
3.5.0.post1
3.5.1
3.5.2
3.5.2.post1
3.6.0
3.6.1
3.7.0
3.7.0rc2
3.7.0rc3
3.7.1
3.8.0
3.8.0rc1
3.9.0
3.9.0rc1
3.9.1
3.9.2
4.0.0rc1
4.0.0rc2
4.21.0
4.21.0rc1
4.21.0rc2
4.21.1
4.21.10
4.21.11
4.21.12
4.21.2
4.21.3
4.21.4
4.21.5
4.21.6
4.21.7
4.21.8
4.21.9
4.22.0
4.22.0rc1
4.22.0rc2
4.22.0rc3
4.22.1
4.22.3
4.22.4
4.22.5
4.23.0
4.23.0rc2
4.23.0rc3
4.23.1
4.23.2
4.23.3
4.23.4
4.24.0
4.24.0rc1
4.24.0rc2
4.24.0rc3
4.24.1
4.24.2
4.24.3
4.24.4
4.25.0
4.25.0rc1
4.25.0rc2
4.25.1
4.25.2
4.25.3
4.25.4
4.25.5
4.25.6
4.25.7
4.25.8
4.25.9
5.26.0
5.26.0rc1
5.26.0rc2
5.26.0rc3
5.26.1
5.27.0
5.27.0rc1
5.27.0rc2
5.27.0rc3
5.27.1
5.27.2
5.27.3
5.27.4
5.27.5
5.28.0
5.28.0rc1
5.28.0rc2
5.28.0rc3
5.28.1
5.28.2
5.28.3
5.29.0
5.29.0rc1
5.29.0rc2
5.29.0rc3
5.29.1
5.29.2
5.29.3
5.29.4
5.29.5
6.30.0
6.30.0rc1
6.30.0rc2
6.30.1
6.30.2
6.31.0
6.31.0rc1
6.31.0rc2
6.31.1
6.32.0
6.32.0rc1
6.32.0rc2
6.32.1
6.33.0
6.33.0rc1
6.33.0rc2
6.33.1
6.33.2
6.33.3
6.33.4
Fixed in
5.29.6
6.33.5
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-4565
PYSEC-2026-1806
GHSA-8qvm-5x2c-j2w7
Jul 07, 2026
protobuf-python has a potential Denial of Service issue
High
Network
Low
None
None
SummaryAny project that uses Protobuf pure-Python backend to parse untrusted Protocol Buffers data containing an arbitrary number of recursive groups, recursive messages or a series of Reporter: Alexis Challande, Trail of Bits Ecosystem Security Team ecosystem@trailofbits.com Affected versions: This issue only affects the pure-Python implementation of protobuf-python backend. This is the implementation when This is a Python variant of a previous issue affecting protobuf-java. SeverityThis is a potential Denial of Service. Parsing nested protobuf data creates unbounded recursions that can be abused by an attacker. Proof of ConceptFor reproduction details, please refer to the unit tests decoder_test.py and message_test Remediation and MitigationA mitigation is available now. Please update to the latest available versions of the following packages:
Affected versions
2.0.0beta
2.0.3
2.3.0
2.4.1
2.5.0
2.6.0
2.6.1
3.0.0
3.0.0a2
3.0.0a3
3.0.0b1
3.0.0b1.post1
+ 178 more Show less
3.0.0b1.post2
3.0.0b2
3.0.0b2.post1
3.0.0b2.post2
3.0.0b3
3.0.0b4
3.1.0
3.1.0.post1
3.10.0
3.10.0rc1
3.11.0
3.11.0rc1
3.11.0rc2
3.11.1
3.11.2
3.11.3
3.12.0
3.12.0rc1
3.12.0rc2
3.12.1
3.12.2
3.12.4
3.13.0
3.13.0rc3
3.14.0
3.14.0rc1
3.14.0rc2
3.14.0rc3
3.15.0
3.15.0rc1
3.15.0rc2
3.15.1
3.15.2
3.15.3
3.15.4
3.15.5
3.15.6
3.15.7
3.15.8
3.16.0
3.16.0rc1
3.16.0rc2
3.17.0
3.17.0rc1
3.17.0rc2
3.17.1
3.17.2
3.17.3
3.18.0
3.18.0rc1
3.18.0rc2
3.18.1
3.18.3
3.19.0
3.19.0rc1
3.19.0rc2
3.19.1
3.19.2
3.19.3
3.19.4
3.19.5
3.19.6
3.2.0
3.2.0rc1
3.2.0rc1.post1
3.2.0rc2
3.20.0
3.20.0rc1
3.20.0rc2
3.20.1
3.20.1rc1
3.20.2
3.20.3
3.3.0
3.4.0
3.5.0.post1
3.5.1
3.5.2
3.5.2.post1
3.6.0
3.6.1
3.7.0
3.7.0rc2
3.7.0rc3
3.7.1
3.8.0
3.8.0rc1
3.9.0
3.9.0rc1
3.9.1
3.9.2
4.0.0rc1
4.0.0rc2
4.21.0
4.21.0rc1
4.21.0rc2
4.21.1
4.21.10
4.21.11
4.21.12
4.21.2
4.21.3
4.21.4
4.21.5
4.21.6
4.21.7
4.21.8
4.21.9
4.22.0
4.22.0rc1
4.22.0rc2
4.22.0rc3
4.22.1
4.22.3
4.22.4
4.22.5
4.23.0
4.23.0rc2
4.23.0rc3
4.23.1
4.23.2
4.23.3
4.23.4
4.24.0
4.24.0rc1
4.24.0rc2
4.24.0rc3
4.24.1
4.24.2
4.24.3
4.24.4
4.25.0
4.25.0rc1
4.25.0rc2
4.25.1
4.25.2
4.25.3
4.25.4
4.25.5
4.25.6
4.25.7
5.26.0
5.26.0rc1
5.26.0rc2
5.26.0rc3
5.26.1
5.27.0
5.27.0rc1
5.27.0rc2
5.27.0rc3
5.27.1
5.27.2
5.27.3
5.27.4
5.27.5
5.28.0
5.28.0rc1
5.28.0rc2
5.28.0rc3
5.28.1
5.28.2
5.28.3
5.29.0
5.29.0rc1
5.29.0rc2
5.29.0rc3
5.29.1
5.29.2
5.29.3
5.29.4
6.30.0
6.30.0rc1
6.30.0rc2
6.30.1
6.30.2
6.31.0
6.31.0rc1
6.31.0rc2
Fixed in
4.25.8
5.29.5
6.31.1
References
Updated Jul 07, 2026 · Source: OSV.dev |
6.31.0rc2
pre
|
|
4.25.7
patch
2 CVEs
CVE-2026-0994
PYSEC-2026-1805
GHSA-7gcm-g887-7qv7
Jul 07, 2026
protobuf affected by a JSON recursion depth bypass
High
Network
Low
None
None
A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages. Due to missing recursion depth accounting inside the internal Any-handling logic, an attacker can supply deeply nested Any structures that bypass the intended recursion limit, eventually exhausting Python’s recursion stack and causing a RecursionError. Affected versions
2.0.0beta
2.0.3
2.3.0
2.4.1
2.5.0
2.6.0
2.6.1
3.0.0
3.0.0a2
3.0.0a3
3.0.0b1
3.0.0b1.post1
+ 193 more Show less
3.0.0b1.post2
3.0.0b2
3.0.0b2.post1
3.0.0b2.post2
3.0.0b3
3.0.0b4
3.1.0
3.1.0.post1
3.10.0
3.10.0rc1
3.11.0
3.11.0rc1
3.11.0rc2
3.11.1
3.11.2
3.11.3
3.12.0
3.12.0rc1
3.12.0rc2
3.12.1
3.12.2
3.12.4
3.13.0
3.13.0rc3
3.14.0
3.14.0rc1
3.14.0rc2
3.14.0rc3
3.15.0
3.15.0rc1
3.15.0rc2
3.15.1
3.15.2
3.15.3
3.15.4
3.15.5
3.15.6
3.15.7
3.15.8
3.16.0
3.16.0rc1
3.16.0rc2
3.17.0
3.17.0rc1
3.17.0rc2
3.17.1
3.17.2
3.17.3
3.18.0
3.18.0rc1
3.18.0rc2
3.18.1
3.18.3
3.19.0
3.19.0rc1
3.19.0rc2
3.19.1
3.19.2
3.19.3
3.19.4
3.19.5
3.19.6
3.2.0
3.2.0rc1
3.2.0rc1.post1
3.2.0rc2
3.20.0
3.20.0rc1
3.20.0rc2
3.20.1
3.20.1rc1
3.20.2
3.20.3
3.3.0
3.4.0
3.5.0.post1
3.5.1
3.5.2
3.5.2.post1
3.6.0
3.6.1
3.7.0
3.7.0rc2
3.7.0rc3
3.7.1
3.8.0
3.8.0rc1
3.9.0
3.9.0rc1
3.9.1
3.9.2
4.0.0rc1
4.0.0rc2
4.21.0
4.21.0rc1
4.21.0rc2
4.21.1
4.21.10
4.21.11
4.21.12
4.21.2
4.21.3
4.21.4
4.21.5
4.21.6
4.21.7
4.21.8
4.21.9
4.22.0
4.22.0rc1
4.22.0rc2
4.22.0rc3
4.22.1
4.22.3
4.22.4
4.22.5
4.23.0
4.23.0rc2
4.23.0rc3
4.23.1
4.23.2
4.23.3
4.23.4
4.24.0
4.24.0rc1
4.24.0rc2
4.24.0rc3
4.24.1
4.24.2
4.24.3
4.24.4
4.25.0
4.25.0rc1
4.25.0rc2
4.25.1
4.25.2
4.25.3
4.25.4
4.25.5
4.25.6
4.25.7
4.25.8
4.25.9
5.26.0
5.26.0rc1
5.26.0rc2
5.26.0rc3
5.26.1
5.27.0
5.27.0rc1
5.27.0rc2
5.27.0rc3
5.27.1
5.27.2
5.27.3
5.27.4
5.27.5
5.28.0
5.28.0rc1
5.28.0rc2
5.28.0rc3
5.28.1
5.28.2
5.28.3
5.29.0
5.29.0rc1
5.29.0rc2
5.29.0rc3
5.29.1
5.29.2
5.29.3
5.29.4
5.29.5
6.30.0
6.30.0rc1
6.30.0rc2
6.30.1
6.30.2
6.31.0
6.31.0rc1
6.31.0rc2
6.31.1
6.32.0
6.32.0rc1
6.32.0rc2
6.32.1
6.33.0
6.33.0rc1
6.33.0rc2
6.33.1
6.33.2
6.33.3
6.33.4
Fixed in
5.29.6
6.33.5
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-4565
PYSEC-2026-1806
GHSA-8qvm-5x2c-j2w7
Jul 07, 2026
protobuf-python has a potential Denial of Service issue
High
Network
Low
None
None
SummaryAny project that uses Protobuf pure-Python backend to parse untrusted Protocol Buffers data containing an arbitrary number of recursive groups, recursive messages or a series of Reporter: Alexis Challande, Trail of Bits Ecosystem Security Team ecosystem@trailofbits.com Affected versions: This issue only affects the pure-Python implementation of protobuf-python backend. This is the implementation when This is a Python variant of a previous issue affecting protobuf-java. SeverityThis is a potential Denial of Service. Parsing nested protobuf data creates unbounded recursions that can be abused by an attacker. Proof of ConceptFor reproduction details, please refer to the unit tests decoder_test.py and message_test Remediation and MitigationA mitigation is available now. Please update to the latest available versions of the following packages:
Affected versions
2.0.0beta
2.0.3
2.3.0
2.4.1
2.5.0
2.6.0
2.6.1
3.0.0
3.0.0a2
3.0.0a3
3.0.0b1
3.0.0b1.post1
+ 178 more Show less
3.0.0b1.post2
3.0.0b2
3.0.0b2.post1
3.0.0b2.post2
3.0.0b3
3.0.0b4
3.1.0
3.1.0.post1
3.10.0
3.10.0rc1
3.11.0
3.11.0rc1
3.11.0rc2
3.11.1
3.11.2
3.11.3
3.12.0
3.12.0rc1
3.12.0rc2
3.12.1
3.12.2
3.12.4
3.13.0
3.13.0rc3
3.14.0
3.14.0rc1
3.14.0rc2
3.14.0rc3
3.15.0
3.15.0rc1
3.15.0rc2
3.15.1
3.15.2
3.15.3
3.15.4
3.15.5
3.15.6
3.15.7
3.15.8
3.16.0
3.16.0rc1
3.16.0rc2
3.17.0
3.17.0rc1
3.17.0rc2
3.17.1
3.17.2
3.17.3
3.18.0
3.18.0rc1
3.18.0rc2
3.18.1
3.18.3
3.19.0
3.19.0rc1
3.19.0rc2
3.19.1
3.19.2
3.19.3
3.19.4
3.19.5
3.19.6
3.2.0
3.2.0rc1
3.2.0rc1.post1
3.2.0rc2
3.20.0
3.20.0rc1
3.20.0rc2
3.20.1
3.20.1rc1
3.20.2
3.20.3
3.3.0
3.4.0
3.5.0.post1
3.5.1
3.5.2
3.5.2.post1
3.6.0
3.6.1
3.7.0
3.7.0rc2
3.7.0rc3
3.7.1
3.8.0
3.8.0rc1
3.9.0
3.9.0rc1
3.9.1
3.9.2
4.0.0rc1
4.0.0rc2
4.21.0
4.21.0rc1
4.21.0rc2
4.21.1
4.21.10
4.21.11
4.21.12
4.21.2
4.21.3
4.21.4
4.21.5
4.21.6
4.21.7
4.21.8
4.21.9
4.22.0
4.22.0rc1
4.22.0rc2
4.22.0rc3
4.22.1
4.22.3
4.22.4
4.22.5
4.23.0
4.23.0rc2
4.23.0rc3
4.23.1
4.23.2
4.23.3
4.23.4
4.24.0
4.24.0rc1
4.24.0rc2
4.24.0rc3
4.24.1
4.24.2
4.24.3
4.24.4
4.25.0
4.25.0rc1
4.25.0rc2
4.25.1
4.25.2
4.25.3
4.25.4
4.25.5
4.25.6
4.25.7
5.26.0
5.26.0rc1
5.26.0rc2
5.26.0rc3
5.26.1
5.27.0
5.27.0rc1
5.27.0rc2
5.27.0rc3
5.27.1
5.27.2
5.27.3
5.27.4
5.27.5
5.28.0
5.28.0rc1
5.28.0rc2
5.28.0rc3
5.28.1
5.28.2
5.28.3
5.29.0
5.29.0rc1
5.29.0rc2
5.29.0rc3
5.29.1
5.29.2
5.29.3
5.29.4
6.30.0
6.30.0rc1
6.30.0rc2
6.30.1
6.30.2
6.31.0
6.31.0rc1
6.31.0rc2
Fixed in
4.25.8
5.29.5
6.31.1
References
Updated Jul 07, 2026 · Source: OSV.dev |
4.25.7
patch
|
|
6.31.0rc1
pre
2 CVEs
CVE-2026-0994
PYSEC-2026-1805
GHSA-7gcm-g887-7qv7
Jul 07, 2026
protobuf affected by a JSON recursion depth bypass
High
Network
Low
None
None
A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages. Due to missing recursion depth accounting inside the internal Any-handling logic, an attacker can supply deeply nested Any structures that bypass the intended recursion limit, eventually exhausting Python’s recursion stack and causing a RecursionError. Affected versions
2.0.0beta
2.0.3
2.3.0
2.4.1
2.5.0
2.6.0
2.6.1
3.0.0
3.0.0a2
3.0.0a3
3.0.0b1
3.0.0b1.post1
+ 193 more Show less
3.0.0b1.post2
3.0.0b2
3.0.0b2.post1
3.0.0b2.post2
3.0.0b3
3.0.0b4
3.1.0
3.1.0.post1
3.10.0
3.10.0rc1
3.11.0
3.11.0rc1
3.11.0rc2
3.11.1
3.11.2
3.11.3
3.12.0
3.12.0rc1
3.12.0rc2
3.12.1
3.12.2
3.12.4
3.13.0
3.13.0rc3
3.14.0
3.14.0rc1
3.14.0rc2
3.14.0rc3
3.15.0
3.15.0rc1
3.15.0rc2
3.15.1
3.15.2
3.15.3
3.15.4
3.15.5
3.15.6
3.15.7
3.15.8
3.16.0
3.16.0rc1
3.16.0rc2
3.17.0
3.17.0rc1
3.17.0rc2
3.17.1
3.17.2
3.17.3
3.18.0
3.18.0rc1
3.18.0rc2
3.18.1
3.18.3
3.19.0
3.19.0rc1
3.19.0rc2
3.19.1
3.19.2
3.19.3
3.19.4
3.19.5
3.19.6
3.2.0
3.2.0rc1
3.2.0rc1.post1
3.2.0rc2
3.20.0
3.20.0rc1
3.20.0rc2
3.20.1
3.20.1rc1
3.20.2
3.20.3
3.3.0
3.4.0
3.5.0.post1
3.5.1
3.5.2
3.5.2.post1
3.6.0
3.6.1
3.7.0
3.7.0rc2
3.7.0rc3
3.7.1
3.8.0
3.8.0rc1
3.9.0
3.9.0rc1
3.9.1
3.9.2
4.0.0rc1
4.0.0rc2
4.21.0
4.21.0rc1
4.21.0rc2
4.21.1
4.21.10
4.21.11
4.21.12
4.21.2
4.21.3
4.21.4
4.21.5
4.21.6
4.21.7
4.21.8
4.21.9
4.22.0
4.22.0rc1
4.22.0rc2
4.22.0rc3
4.22.1
4.22.3
4.22.4
4.22.5
4.23.0
4.23.0rc2
4.23.0rc3
4.23.1
4.23.2
4.23.3
4.23.4
4.24.0
4.24.0rc1
4.24.0rc2
4.24.0rc3
4.24.1
4.24.2
4.24.3
4.24.4
4.25.0
4.25.0rc1
4.25.0rc2
4.25.1
4.25.2
4.25.3
4.25.4
4.25.5
4.25.6
4.25.7
4.25.8
4.25.9
5.26.0
5.26.0rc1
5.26.0rc2
5.26.0rc3
5.26.1
5.27.0
5.27.0rc1
5.27.0rc2
5.27.0rc3
5.27.1
5.27.2
5.27.3
5.27.4
5.27.5
5.28.0
5.28.0rc1
5.28.0rc2
5.28.0rc3
5.28.1
5.28.2
5.28.3
5.29.0
5.29.0rc1
5.29.0rc2
5.29.0rc3
5.29.1
5.29.2
5.29.3
5.29.4
5.29.5
6.30.0
6.30.0rc1
6.30.0rc2
6.30.1
6.30.2
6.31.0
6.31.0rc1
6.31.0rc2
6.31.1
6.32.0
6.32.0rc1
6.32.0rc2
6.32.1
6.33.0
6.33.0rc1
6.33.0rc2
6.33.1
6.33.2
6.33.3
6.33.4
Fixed in
5.29.6
6.33.5
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-4565
PYSEC-2026-1806
GHSA-8qvm-5x2c-j2w7
Jul 07, 2026
protobuf-python has a potential Denial of Service issue
High
Network
Low
None
None
SummaryAny project that uses Protobuf pure-Python backend to parse untrusted Protocol Buffers data containing an arbitrary number of recursive groups, recursive messages or a series of Reporter: Alexis Challande, Trail of Bits Ecosystem Security Team ecosystem@trailofbits.com Affected versions: This issue only affects the pure-Python implementation of protobuf-python backend. This is the implementation when This is a Python variant of a previous issue affecting protobuf-java. SeverityThis is a potential Denial of Service. Parsing nested protobuf data creates unbounded recursions that can be abused by an attacker. Proof of ConceptFor reproduction details, please refer to the unit tests decoder_test.py and message_test Remediation and MitigationA mitigation is available now. Please update to the latest available versions of the following packages:
Affected versions
2.0.0beta
2.0.3
2.3.0
2.4.1
2.5.0
2.6.0
2.6.1
3.0.0
3.0.0a2
3.0.0a3
3.0.0b1
3.0.0b1.post1
+ 178 more Show less
3.0.0b1.post2
3.0.0b2
3.0.0b2.post1
3.0.0b2.post2
3.0.0b3
3.0.0b4
3.1.0
3.1.0.post1
3.10.0
3.10.0rc1
3.11.0
3.11.0rc1
3.11.0rc2
3.11.1
3.11.2
3.11.3
3.12.0
3.12.0rc1
3.12.0rc2
3.12.1
3.12.2
3.12.4
3.13.0
3.13.0rc3
3.14.0
3.14.0rc1
3.14.0rc2
3.14.0rc3
3.15.0
3.15.0rc1
3.15.0rc2
3.15.1
3.15.2
3.15.3
3.15.4
3.15.5
3.15.6
3.15.7
3.15.8
3.16.0
3.16.0rc1
3.16.0rc2
3.17.0
3.17.0rc1
3.17.0rc2
3.17.1
3.17.2
3.17.3
3.18.0
3.18.0rc1
3.18.0rc2
3.18.1
3.18.3
3.19.0
3.19.0rc1
3.19.0rc2
3.19.1
3.19.2
3.19.3
3.19.4
3.19.5
3.19.6
3.2.0
3.2.0rc1
3.2.0rc1.post1
3.2.0rc2
3.20.0
3.20.0rc1
3.20.0rc2
3.20.1
3.20.1rc1
3.20.2
3.20.3
3.3.0
3.4.0
3.5.0.post1
3.5.1
3.5.2
3.5.2.post1
3.6.0
3.6.1
3.7.0
3.7.0rc2
3.7.0rc3
3.7.1
3.8.0
3.8.0rc1
3.9.0
3.9.0rc1
3.9.1
3.9.2
4.0.0rc1
4.0.0rc2
4.21.0
4.21.0rc1
4.21.0rc2
4.21.1
4.21.10
4.21.11
4.21.12
4.21.2
4.21.3
4.21.4
4.21.5
4.21.6
4.21.7
4.21.8
4.21.9
4.22.0
4.22.0rc1
4.22.0rc2
4.22.0rc3
4.22.1
4.22.3
4.22.4
4.22.5
4.23.0
4.23.0rc2
4.23.0rc3
4.23.1
4.23.2
4.23.3
4.23.4
4.24.0
4.24.0rc1
4.24.0rc2
4.24.0rc3
4.24.1
4.24.2
4.24.3
4.24.4
4.25.0
4.25.0rc1
4.25.0rc2
4.25.1
4.25.2
4.25.3
4.25.4
4.25.5
4.25.6
4.25.7
5.26.0
5.26.0rc1
5.26.0rc2
5.26.0rc3
5.26.1
5.27.0
5.27.0rc1
5.27.0rc2
5.27.0rc3
5.27.1
5.27.2
5.27.3
5.27.4
5.27.5
5.28.0
5.28.0rc1
5.28.0rc2
5.28.0rc3
5.28.1
5.28.2
5.28.3
5.29.0
5.29.0rc1
5.29.0rc2
5.29.0rc3
5.29.1
5.29.2
5.29.3
5.29.4
6.30.0
6.30.0rc1
6.30.0rc2
6.30.1
6.30.2
6.31.0
6.31.0rc1
6.31.0rc2
Fixed in
4.25.8
5.29.5
6.31.1
References
Updated Jul 07, 2026 · Source: OSV.dev |
6.31.0rc1
pre
|
|
6.30.2
patch
2 CVEs
CVE-2026-0994
PYSEC-2026-1805
GHSA-7gcm-g887-7qv7
Jul 07, 2026
protobuf affected by a JSON recursion depth bypass
High
Network
Low
None
None
A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages. Due to missing recursion depth accounting inside the internal Any-handling logic, an attacker can supply deeply nested Any structures that bypass the intended recursion limit, eventually exhausting Python’s recursion stack and causing a RecursionError. Affected versions
2.0.0beta
2.0.3
2.3.0
2.4.1
2.5.0
2.6.0
2.6.1
3.0.0
3.0.0a2
3.0.0a3
3.0.0b1
3.0.0b1.post1
+ 193 more Show less
3.0.0b1.post2
3.0.0b2
3.0.0b2.post1
3.0.0b2.post2
3.0.0b3
3.0.0b4
3.1.0
3.1.0.post1
3.10.0
3.10.0rc1
3.11.0
3.11.0rc1
3.11.0rc2
3.11.1
3.11.2
3.11.3
3.12.0
3.12.0rc1
3.12.0rc2
3.12.1
3.12.2
3.12.4
3.13.0
3.13.0rc3
3.14.0
3.14.0rc1
3.14.0rc2
3.14.0rc3
3.15.0
3.15.0rc1
3.15.0rc2
3.15.1
3.15.2
3.15.3
3.15.4
3.15.5
3.15.6
3.15.7
3.15.8
3.16.0
3.16.0rc1
3.16.0rc2
3.17.0
3.17.0rc1
3.17.0rc2
3.17.1
3.17.2
3.17.3
3.18.0
3.18.0rc1
3.18.0rc2
3.18.1
3.18.3
3.19.0
3.19.0rc1
3.19.0rc2
3.19.1
3.19.2
3.19.3
3.19.4
3.19.5
3.19.6
3.2.0
3.2.0rc1
3.2.0rc1.post1
3.2.0rc2
3.20.0
3.20.0rc1
3.20.0rc2
3.20.1
3.20.1rc1
3.20.2
3.20.3
3.3.0
3.4.0
3.5.0.post1
3.5.1
3.5.2
3.5.2.post1
3.6.0
3.6.1
3.7.0
3.7.0rc2
3.7.0rc3
3.7.1
3.8.0
3.8.0rc1
3.9.0
3.9.0rc1
3.9.1
3.9.2
4.0.0rc1
4.0.0rc2
4.21.0
4.21.0rc1
4.21.0rc2
4.21.1
4.21.10
4.21.11
4.21.12
4.21.2
4.21.3
4.21.4
4.21.5
4.21.6
4.21.7
4.21.8
4.21.9
4.22.0
4.22.0rc1
4.22.0rc2
4.22.0rc3
4.22.1
4.22.3
4.22.4
4.22.5
4.23.0
4.23.0rc2
4.23.0rc3
4.23.1
4.23.2
4.23.3
4.23.4
4.24.0
4.24.0rc1
4.24.0rc2
4.24.0rc3
4.24.1
4.24.2
4.24.3
4.24.4
4.25.0
4.25.0rc1
4.25.0rc2
4.25.1
4.25.2
4.25.3
4.25.4
4.25.5
4.25.6
4.25.7
4.25.8
4.25.9
5.26.0
5.26.0rc1
5.26.0rc2
5.26.0rc3
5.26.1
5.27.0
5.27.0rc1
5.27.0rc2
5.27.0rc3
5.27.1
5.27.2
5.27.3
5.27.4
5.27.5
5.28.0
5.28.0rc1
5.28.0rc2
5.28.0rc3
5.28.1
5.28.2
5.28.3
5.29.0
5.29.0rc1
5.29.0rc2
5.29.0rc3
5.29.1
5.29.2
5.29.3
5.29.4
5.29.5
6.30.0
6.30.0rc1
6.30.0rc2
6.30.1
6.30.2
6.31.0
6.31.0rc1
6.31.0rc2
6.31.1
6.32.0
6.32.0rc1
6.32.0rc2
6.32.1
6.33.0
6.33.0rc1
6.33.0rc2
6.33.1
6.33.2
6.33.3
6.33.4
Fixed in
5.29.6
6.33.5
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-4565
PYSEC-2026-1806
GHSA-8qvm-5x2c-j2w7
Jul 07, 2026
protobuf-python has a potential Denial of Service issue
High
Network
Low
None
None
SummaryAny project that uses Protobuf pure-Python backend to parse untrusted Protocol Buffers data containing an arbitrary number of recursive groups, recursive messages or a series of Reporter: Alexis Challande, Trail of Bits Ecosystem Security Team ecosystem@trailofbits.com Affected versions: This issue only affects the pure-Python implementation of protobuf-python backend. This is the implementation when This is a Python variant of a previous issue affecting protobuf-java. SeverityThis is a potential Denial of Service. Parsing nested protobuf data creates unbounded recursions that can be abused by an attacker. Proof of ConceptFor reproduction details, please refer to the unit tests decoder_test.py and message_test Remediation and MitigationA mitigation is available now. Please update to the latest available versions of the following packages:
Affected versions
2.0.0beta
2.0.3
2.3.0
2.4.1
2.5.0
2.6.0
2.6.1
3.0.0
3.0.0a2
3.0.0a3
3.0.0b1
3.0.0b1.post1
+ 178 more Show less
3.0.0b1.post2
3.0.0b2
3.0.0b2.post1
3.0.0b2.post2
3.0.0b3
3.0.0b4
3.1.0
3.1.0.post1
3.10.0
3.10.0rc1
3.11.0
3.11.0rc1
3.11.0rc2
3.11.1
3.11.2
3.11.3
3.12.0
3.12.0rc1
3.12.0rc2
3.12.1
3.12.2
3.12.4
3.13.0
3.13.0rc3
3.14.0
3.14.0rc1
3.14.0rc2
3.14.0rc3
3.15.0
3.15.0rc1
3.15.0rc2
3.15.1
3.15.2
3.15.3
3.15.4
3.15.5
3.15.6
3.15.7
3.15.8
3.16.0
3.16.0rc1
3.16.0rc2
3.17.0
3.17.0rc1
3.17.0rc2
3.17.1
3.17.2
3.17.3
3.18.0
3.18.0rc1
3.18.0rc2
3.18.1
3.18.3
3.19.0
3.19.0rc1
3.19.0rc2
3.19.1
3.19.2
3.19.3
3.19.4
3.19.5
3.19.6
3.2.0
3.2.0rc1
3.2.0rc1.post1
3.2.0rc2
3.20.0
3.20.0rc1
3.20.0rc2
3.20.1
3.20.1rc1
3.20.2
3.20.3
3.3.0
3.4.0
3.5.0.post1
3.5.1
3.5.2
3.5.2.post1
3.6.0
3.6.1
3.7.0
3.7.0rc2
3.7.0rc3
3.7.1
3.8.0
3.8.0rc1
3.9.0
3.9.0rc1
3.9.1
3.9.2
4.0.0rc1
4.0.0rc2
4.21.0
4.21.0rc1
4.21.0rc2
4.21.1
4.21.10
4.21.11
4.21.12
4.21.2
4.21.3
4.21.4
4.21.5
4.21.6
4.21.7
4.21.8
4.21.9
4.22.0
4.22.0rc1
4.22.0rc2
4.22.0rc3
4.22.1
4.22.3
4.22.4
4.22.5
4.23.0
4.23.0rc2
4.23.0rc3
4.23.1
4.23.2
4.23.3
4.23.4
4.24.0
4.24.0rc1
4.24.0rc2
4.24.0rc3
4.24.1
4.24.2
4.24.3
4.24.4
4.25.0
4.25.0rc1
4.25.0rc2
4.25.1
4.25.2
4.25.3
4.25.4
4.25.5
4.25.6
4.25.7
5.26.0
5.26.0rc1
5.26.0rc2
5.26.0rc3
5.26.1
5.27.0
5.27.0rc1
5.27.0rc2
5.27.0rc3
5.27.1
5.27.2
5.27.3
5.27.4
5.27.5
5.28.0
5.28.0rc1
5.28.0rc2
5.28.0rc3
5.28.1
5.28.2
5.28.3
5.29.0
5.29.0rc1
5.29.0rc2
5.29.0rc3
5.29.1
5.29.2
5.29.3
5.29.4
6.30.0
6.30.0rc1
6.30.0rc2
6.30.1
6.30.2
6.31.0
6.31.0rc1
6.31.0rc2
Fixed in
4.25.8
5.29.5
6.31.1
References
Updated Jul 07, 2026 · Source: OSV.dev |
6.30.2
patch
|
|
5.29.4
patch
2 CVEs
CVE-2026-0994
PYSEC-2026-1805
GHSA-7gcm-g887-7qv7
Jul 07, 2026
protobuf affected by a JSON recursion depth bypass
High
Network
Low
None
None
A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages. Due to missing recursion depth accounting inside the internal Any-handling logic, an attacker can supply deeply nested Any structures that bypass the intended recursion limit, eventually exhausting Python’s recursion stack and causing a RecursionError. Affected versions
2.0.0beta
2.0.3
2.3.0
2.4.1
2.5.0
2.6.0
2.6.1
3.0.0
3.0.0a2
3.0.0a3
3.0.0b1
3.0.0b1.post1
+ 193 more Show less
3.0.0b1.post2
3.0.0b2
3.0.0b2.post1
3.0.0b2.post2
3.0.0b3
3.0.0b4
3.1.0
3.1.0.post1
3.10.0
3.10.0rc1
3.11.0
3.11.0rc1
3.11.0rc2
3.11.1
3.11.2
3.11.3
3.12.0
3.12.0rc1
3.12.0rc2
3.12.1
3.12.2
3.12.4
3.13.0
3.13.0rc3
3.14.0
3.14.0rc1
3.14.0rc2
3.14.0rc3
3.15.0
3.15.0rc1
3.15.0rc2
3.15.1
3.15.2
3.15.3
3.15.4
3.15.5
3.15.6
3.15.7
3.15.8
3.16.0
3.16.0rc1
3.16.0rc2
3.17.0
3.17.0rc1
3.17.0rc2
3.17.1
3.17.2
3.17.3
3.18.0
3.18.0rc1
3.18.0rc2
3.18.1
3.18.3
3.19.0
3.19.0rc1
3.19.0rc2
3.19.1
3.19.2
3.19.3
3.19.4
3.19.5
3.19.6
3.2.0
3.2.0rc1
3.2.0rc1.post1
3.2.0rc2
3.20.0
3.20.0rc1
3.20.0rc2
3.20.1
3.20.1rc1
3.20.2
3.20.3
3.3.0
3.4.0
3.5.0.post1
3.5.1
3.5.2
3.5.2.post1
3.6.0
3.6.1
3.7.0
3.7.0rc2
3.7.0rc3
3.7.1
3.8.0
3.8.0rc1
3.9.0
3.9.0rc1
3.9.1
3.9.2
4.0.0rc1
4.0.0rc2
4.21.0
4.21.0rc1
4.21.0rc2
4.21.1
4.21.10
4.21.11
4.21.12
4.21.2
4.21.3
4.21.4
4.21.5
4.21.6
4.21.7
4.21.8
4.21.9
4.22.0
4.22.0rc1
4.22.0rc2
4.22.0rc3
4.22.1
4.22.3
4.22.4
4.22.5
4.23.0
4.23.0rc2
4.23.0rc3
4.23.1
4.23.2
4.23.3
4.23.4
4.24.0
4.24.0rc1
4.24.0rc2
4.24.0rc3
4.24.1
4.24.2
4.24.3
4.24.4
4.25.0
4.25.0rc1
4.25.0rc2
4.25.1
4.25.2
4.25.3
4.25.4
4.25.5
4.25.6
4.25.7
4.25.8
4.25.9
5.26.0
5.26.0rc1
5.26.0rc2
5.26.0rc3
5.26.1
5.27.0
5.27.0rc1
5.27.0rc2
5.27.0rc3
5.27.1
5.27.2
5.27.3
5.27.4
5.27.5
5.28.0
5.28.0rc1
5.28.0rc2
5.28.0rc3
5.28.1
5.28.2
5.28.3
5.29.0
5.29.0rc1
5.29.0rc2
5.29.0rc3
5.29.1
5.29.2
5.29.3
5.29.4
5.29.5
6.30.0
6.30.0rc1
6.30.0rc2
6.30.1
6.30.2
6.31.0
6.31.0rc1
6.31.0rc2
6.31.1
6.32.0
6.32.0rc1
6.32.0rc2
6.32.1
6.33.0
6.33.0rc1
6.33.0rc2
6.33.1
6.33.2
6.33.3
6.33.4
Fixed in
5.29.6
6.33.5
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-4565
PYSEC-2026-1806
GHSA-8qvm-5x2c-j2w7
Jul 07, 2026
protobuf-python has a potential Denial of Service issue
High
Network
Low
None
None
SummaryAny project that uses Protobuf pure-Python backend to parse untrusted Protocol Buffers data containing an arbitrary number of recursive groups, recursive messages or a series of Reporter: Alexis Challande, Trail of Bits Ecosystem Security Team ecosystem@trailofbits.com Affected versions: This issue only affects the pure-Python implementation of protobuf-python backend. This is the implementation when This is a Python variant of a previous issue affecting protobuf-java. SeverityThis is a potential Denial of Service. Parsing nested protobuf data creates unbounded recursions that can be abused by an attacker. Proof of ConceptFor reproduction details, please refer to the unit tests decoder_test.py and message_test Remediation and MitigationA mitigation is available now. Please update to the latest available versions of the following packages:
Affected versions
2.0.0beta
2.0.3
2.3.0
2.4.1
2.5.0
2.6.0
2.6.1
3.0.0
3.0.0a2
3.0.0a3
3.0.0b1
3.0.0b1.post1
+ 178 more Show less
3.0.0b1.post2
3.0.0b2
3.0.0b2.post1
3.0.0b2.post2
3.0.0b3
3.0.0b4
3.1.0
3.1.0.post1
3.10.0
3.10.0rc1
3.11.0
3.11.0rc1
3.11.0rc2
3.11.1
3.11.2
3.11.3
3.12.0
3.12.0rc1
3.12.0rc2
3.12.1
3.12.2
3.12.4
3.13.0
3.13.0rc3
3.14.0
3.14.0rc1
3.14.0rc2
3.14.0rc3
3.15.0
3.15.0rc1
3.15.0rc2
3.15.1
3.15.2
3.15.3
3.15.4
3.15.5
3.15.6
3.15.7
3.15.8
3.16.0
3.16.0rc1
3.16.0rc2
3.17.0
3.17.0rc1
3.17.0rc2
3.17.1
3.17.2
3.17.3
3.18.0
3.18.0rc1
3.18.0rc2
3.18.1
3.18.3
3.19.0
3.19.0rc1
3.19.0rc2
3.19.1
3.19.2
3.19.3
3.19.4
3.19.5
3.19.6
3.2.0
3.2.0rc1
3.2.0rc1.post1
3.2.0rc2
3.20.0
3.20.0rc1
3.20.0rc2
3.20.1
3.20.1rc1
3.20.2
3.20.3
3.3.0
3.4.0
3.5.0.post1
3.5.1
3.5.2
3.5.2.post1
3.6.0
3.6.1
3.7.0
3.7.0rc2
3.7.0rc3
3.7.1
3.8.0
3.8.0rc1
3.9.0
3.9.0rc1
3.9.1
3.9.2
4.0.0rc1
4.0.0rc2
4.21.0
4.21.0rc1
4.21.0rc2
4.21.1
4.21.10
4.21.11
4.21.12
4.21.2
4.21.3
4.21.4
4.21.5
4.21.6
4.21.7
4.21.8
4.21.9
4.22.0
4.22.0rc1
4.22.0rc2
4.22.0rc3
4.22.1
4.22.3
4.22.4
4.22.5
4.23.0
4.23.0rc2
4.23.0rc3
4.23.1
4.23.2
4.23.3
4.23.4
4.24.0
4.24.0rc1
4.24.0rc2
4.24.0rc3
4.24.1
4.24.2
4.24.3
4.24.4
4.25.0
4.25.0rc1
4.25.0rc2
4.25.1
4.25.2
4.25.3
4.25.4
4.25.5
4.25.6
4.25.7
5.26.0
5.26.0rc1
5.26.0rc2
5.26.0rc3
5.26.1
5.27.0
5.27.0rc1
5.27.0rc2
5.27.0rc3
5.27.1
5.27.2
5.27.3
5.27.4
5.27.5
5.28.0
5.28.0rc1
5.28.0rc2
5.28.0rc3
5.28.1
5.28.2
5.28.3
5.29.0
5.29.0rc1
5.29.0rc2
5.29.0rc3
5.29.1
5.29.2
5.29.3
5.29.4
6.30.0
6.30.0rc1
6.30.0rc2
6.30.1
6.30.2
6.31.0
6.31.0rc1
6.31.0rc2
Fixed in
4.25.8
5.29.5
6.31.1
References
Updated Jul 07, 2026 · Source: OSV.dev |
5.29.4
patch
|
|
6.30.1
patch
2 CVEs
CVE-2026-0994
PYSEC-2026-1805
GHSA-7gcm-g887-7qv7
Jul 07, 2026
protobuf affected by a JSON recursion depth bypass
High
Network
Low
None
None
A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages. Due to missing recursion depth accounting inside the internal Any-handling logic, an attacker can supply deeply nested Any structures that bypass the intended recursion limit, eventually exhausting Python’s recursion stack and causing a RecursionError. Affected versions
2.0.0beta
2.0.3
2.3.0
2.4.1
2.5.0
2.6.0
2.6.1
3.0.0
3.0.0a2
3.0.0a3
3.0.0b1
3.0.0b1.post1
+ 193 more Show less
3.0.0b1.post2
3.0.0b2
3.0.0b2.post1
3.0.0b2.post2
3.0.0b3
3.0.0b4
3.1.0
3.1.0.post1
3.10.0
3.10.0rc1
3.11.0
3.11.0rc1
3.11.0rc2
3.11.1
3.11.2
3.11.3
3.12.0
3.12.0rc1
3.12.0rc2
3.12.1
3.12.2
3.12.4
3.13.0
3.13.0rc3
3.14.0
3.14.0rc1
3.14.0rc2
3.14.0rc3
3.15.0
3.15.0rc1
3.15.0rc2
3.15.1
3.15.2
3.15.3
3.15.4
3.15.5
3.15.6
3.15.7
3.15.8
3.16.0
3.16.0rc1
3.16.0rc2
3.17.0
3.17.0rc1
3.17.0rc2
3.17.1
3.17.2
3.17.3
3.18.0
3.18.0rc1
3.18.0rc2
3.18.1
3.18.3
3.19.0
3.19.0rc1
3.19.0rc2
3.19.1
3.19.2
3.19.3
3.19.4
3.19.5
3.19.6
3.2.0
3.2.0rc1
3.2.0rc1.post1
3.2.0rc2
3.20.0
3.20.0rc1
3.20.0rc2
3.20.1
3.20.1rc1
3.20.2
3.20.3
3.3.0
3.4.0
3.5.0.post1
3.5.1
3.5.2
3.5.2.post1
3.6.0
3.6.1
3.7.0
3.7.0rc2
3.7.0rc3
3.7.1
3.8.0
3.8.0rc1
3.9.0
3.9.0rc1
3.9.1
3.9.2
4.0.0rc1
4.0.0rc2
4.21.0
4.21.0rc1
4.21.0rc2
4.21.1
4.21.10
4.21.11
4.21.12
4.21.2
4.21.3
4.21.4
4.21.5
4.21.6
4.21.7
4.21.8
4.21.9
4.22.0
4.22.0rc1
4.22.0rc2
4.22.0rc3
4.22.1
4.22.3
4.22.4
4.22.5
4.23.0
4.23.0rc2
4.23.0rc3
4.23.1
4.23.2
4.23.3
4.23.4
4.24.0
4.24.0rc1
4.24.0rc2
4.24.0rc3
4.24.1
4.24.2
4.24.3
4.24.4
4.25.0
4.25.0rc1
4.25.0rc2
4.25.1
4.25.2
4.25.3
4.25.4
4.25.5
4.25.6
4.25.7
4.25.8
4.25.9
5.26.0
5.26.0rc1
5.26.0rc2
5.26.0rc3
5.26.1
5.27.0
5.27.0rc1
5.27.0rc2
5.27.0rc3
5.27.1
5.27.2
5.27.3
5.27.4
5.27.5
5.28.0
5.28.0rc1
5.28.0rc2
5.28.0rc3
5.28.1
5.28.2
5.28.3
5.29.0
5.29.0rc1
5.29.0rc2
5.29.0rc3
5.29.1
5.29.2
5.29.3
5.29.4
5.29.5
6.30.0
6.30.0rc1
6.30.0rc2
6.30.1
6.30.2
6.31.0
6.31.0rc1
6.31.0rc2
6.31.1
6.32.0
6.32.0rc1
6.32.0rc2
6.32.1
6.33.0
6.33.0rc1
6.33.0rc2
6.33.1
6.33.2
6.33.3
6.33.4
Fixed in
5.29.6
6.33.5
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-4565
PYSEC-2026-1806
GHSA-8qvm-5x2c-j2w7
Jul 07, 2026
protobuf-python has a potential Denial of Service issue
High
Network
Low
None
None
SummaryAny project that uses Protobuf pure-Python backend to parse untrusted Protocol Buffers data containing an arbitrary number of recursive groups, recursive messages or a series of Reporter: Alexis Challande, Trail of Bits Ecosystem Security Team ecosystem@trailofbits.com Affected versions: This issue only affects the pure-Python implementation of protobuf-python backend. This is the implementation when This is a Python variant of a previous issue affecting protobuf-java. SeverityThis is a potential Denial of Service. Parsing nested protobuf data creates unbounded recursions that can be abused by an attacker. Proof of ConceptFor reproduction details, please refer to the unit tests decoder_test.py and message_test Remediation and MitigationA mitigation is available now. Please update to the latest available versions of the following packages:
Affected versions
2.0.0beta
2.0.3
2.3.0
2.4.1
2.5.0
2.6.0
2.6.1
3.0.0
3.0.0a2
3.0.0a3
3.0.0b1
3.0.0b1.post1
+ 178 more Show less
3.0.0b1.post2
3.0.0b2
3.0.0b2.post1
3.0.0b2.post2
3.0.0b3
3.0.0b4
3.1.0
3.1.0.post1
3.10.0
3.10.0rc1
3.11.0
3.11.0rc1
3.11.0rc2
3.11.1
3.11.2
3.11.3
3.12.0
3.12.0rc1
3.12.0rc2
3.12.1
3.12.2
3.12.4
3.13.0
3.13.0rc3
3.14.0
3.14.0rc1
3.14.0rc2
3.14.0rc3
3.15.0
3.15.0rc1
3.15.0rc2
3.15.1
3.15.2
3.15.3
3.15.4
3.15.5
3.15.6
3.15.7
3.15.8
3.16.0
3.16.0rc1
3.16.0rc2
3.17.0
3.17.0rc1
3.17.0rc2
3.17.1
3.17.2
3.17.3
3.18.0
3.18.0rc1
3.18.0rc2
3.18.1
3.18.3
3.19.0
3.19.0rc1
3.19.0rc2
3.19.1
3.19.2
3.19.3
3.19.4
3.19.5
3.19.6
3.2.0
3.2.0rc1
3.2.0rc1.post1
3.2.0rc2
3.20.0
3.20.0rc1
3.20.0rc2
3.20.1
3.20.1rc1
3.20.2
3.20.3
3.3.0
3.4.0
3.5.0.post1
3.5.1
3.5.2
3.5.2.post1
3.6.0
3.6.1
3.7.0
3.7.0rc2
3.7.0rc3
3.7.1
3.8.0
3.8.0rc1
3.9.0
3.9.0rc1
3.9.1
3.9.2
4.0.0rc1
4.0.0rc2
4.21.0
4.21.0rc1
4.21.0rc2
4.21.1
4.21.10
4.21.11
4.21.12
4.21.2
4.21.3
4.21.4
4.21.5
4.21.6
4.21.7
4.21.8
4.21.9
4.22.0
4.22.0rc1
4.22.0rc2
4.22.0rc3
4.22.1
4.22.3
4.22.4
4.22.5
4.23.0
4.23.0rc2
4.23.0rc3
4.23.1
4.23.2
4.23.3
4.23.4
4.24.0
4.24.0rc1
4.24.0rc2
4.24.0rc3
4.24.1
4.24.2
4.24.3
4.24.4
4.25.0
4.25.0rc1
4.25.0rc2
4.25.1
4.25.2
4.25.3
4.25.4
4.25.5
4.25.6
4.25.7
5.26.0
5.26.0rc1
5.26.0rc2
5.26.0rc3
5.26.1
5.27.0
5.27.0rc1
5.27.0rc2
5.27.0rc3
5.27.1
5.27.2
5.27.3
5.27.4
5.27.5
5.28.0
5.28.0rc1
5.28.0rc2
5.28.0rc3
5.28.1
5.28.2
5.28.3
5.29.0
5.29.0rc1
5.29.0rc2
5.29.0rc3
5.29.1
5.29.2
5.29.3
5.29.4
6.30.0
6.30.0rc1
6.30.0rc2
6.30.1
6.30.2
6.31.0
6.31.0rc1
6.31.0rc2
Fixed in
4.25.8
5.29.5
6.31.1
References
Updated Jul 07, 2026 · Source: OSV.dev |
6.30.1
patch
|
|
6.30.0
major
2 CVEs
CVE-2026-0994
PYSEC-2026-1805
GHSA-7gcm-g887-7qv7
Jul 07, 2026
protobuf affected by a JSON recursion depth bypass
High
Network
Low
None
None
A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages. Due to missing recursion depth accounting inside the internal Any-handling logic, an attacker can supply deeply nested Any structures that bypass the intended recursion limit, eventually exhausting Python’s recursion stack and causing a RecursionError. Affected versions
2.0.0beta
2.0.3
2.3.0
2.4.1
2.5.0
2.6.0
2.6.1
3.0.0
3.0.0a2
3.0.0a3
3.0.0b1
3.0.0b1.post1
+ 193 more Show less
3.0.0b1.post2
3.0.0b2
3.0.0b2.post1
3.0.0b2.post2
3.0.0b3
3.0.0b4
3.1.0
3.1.0.post1
3.10.0
3.10.0rc1
3.11.0
3.11.0rc1
3.11.0rc2
3.11.1
3.11.2
3.11.3
3.12.0
3.12.0rc1
3.12.0rc2
3.12.1
3.12.2
3.12.4
3.13.0
3.13.0rc3
3.14.0
3.14.0rc1
3.14.0rc2
3.14.0rc3
3.15.0
3.15.0rc1
3.15.0rc2
3.15.1
3.15.2
3.15.3
3.15.4
3.15.5
3.15.6
3.15.7
3.15.8
3.16.0
3.16.0rc1
3.16.0rc2
3.17.0
3.17.0rc1
3.17.0rc2
3.17.1
3.17.2
3.17.3
3.18.0
3.18.0rc1
3.18.0rc2
3.18.1
3.18.3
3.19.0
3.19.0rc1
3.19.0rc2
3.19.1
3.19.2
3.19.3
3.19.4
3.19.5
3.19.6
3.2.0
3.2.0rc1
3.2.0rc1.post1
3.2.0rc2
3.20.0
3.20.0rc1
3.20.0rc2
3.20.1
3.20.1rc1
3.20.2
3.20.3
3.3.0
3.4.0
3.5.0.post1
3.5.1
3.5.2
3.5.2.post1
3.6.0
3.6.1
3.7.0
3.7.0rc2
3.7.0rc3
3.7.1
3.8.0
3.8.0rc1
3.9.0
3.9.0rc1
3.9.1
3.9.2
4.0.0rc1
4.0.0rc2
4.21.0
4.21.0rc1
4.21.0rc2
4.21.1
4.21.10
4.21.11
4.21.12
4.21.2
4.21.3
4.21.4
4.21.5
4.21.6
4.21.7
4.21.8
4.21.9
4.22.0
4.22.0rc1
4.22.0rc2
4.22.0rc3
4.22.1
4.22.3
4.22.4
4.22.5
4.23.0
4.23.0rc2
4.23.0rc3
4.23.1
4.23.2
4.23.3
4.23.4
4.24.0
4.24.0rc1
4.24.0rc2
4.24.0rc3
4.24.1
4.24.2
4.24.3
4.24.4
4.25.0
4.25.0rc1
4.25.0rc2
4.25.1
4.25.2
4.25.3
4.25.4
4.25.5
4.25.6
4.25.7
4.25.8
4.25.9
5.26.0
5.26.0rc1
5.26.0rc2
5.26.0rc3
5.26.1
5.27.0
5.27.0rc1
5.27.0rc2
5.27.0rc3
5.27.1
5.27.2
5.27.3
5.27.4
5.27.5
5.28.0
5.28.0rc1
5.28.0rc2
5.28.0rc3
5.28.1
5.28.2
5.28.3
5.29.0
5.29.0rc1
5.29.0rc2
5.29.0rc3
5.29.1
5.29.2
5.29.3
5.29.4
5.29.5
6.30.0
6.30.0rc1
6.30.0rc2
6.30.1
6.30.2
6.31.0
6.31.0rc1
6.31.0rc2
6.31.1
6.32.0
6.32.0rc1
6.32.0rc2
6.32.1
6.33.0
6.33.0rc1
6.33.0rc2
6.33.1
6.33.2
6.33.3
6.33.4
Fixed in
5.29.6
6.33.5
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-4565
PYSEC-2026-1806
GHSA-8qvm-5x2c-j2w7
Jul 07, 2026
protobuf-python has a potential Denial of Service issue
High
Network
Low
None
None
SummaryAny project that uses Protobuf pure-Python backend to parse untrusted Protocol Buffers data containing an arbitrary number of recursive groups, recursive messages or a series of Reporter: Alexis Challande, Trail of Bits Ecosystem Security Team ecosystem@trailofbits.com Affected versions: This issue only affects the pure-Python implementation of protobuf-python backend. This is the implementation when This is a Python variant of a previous issue affecting protobuf-java. SeverityThis is a potential Denial of Service. Parsing nested protobuf data creates unbounded recursions that can be abused by an attacker. Proof of ConceptFor reproduction details, please refer to the unit tests decoder_test.py and message_test Remediation and MitigationA mitigation is available now. Please update to the latest available versions of the following packages:
Affected versions
2.0.0beta
2.0.3
2.3.0
2.4.1
2.5.0
2.6.0
2.6.1
3.0.0
3.0.0a2
3.0.0a3
3.0.0b1
3.0.0b1.post1
+ 178 more Show less
3.0.0b1.post2
3.0.0b2
3.0.0b2.post1
3.0.0b2.post2
3.0.0b3
3.0.0b4
3.1.0
3.1.0.post1
3.10.0
3.10.0rc1
3.11.0
3.11.0rc1
3.11.0rc2
3.11.1
3.11.2
3.11.3
3.12.0
3.12.0rc1
3.12.0rc2
3.12.1
3.12.2
3.12.4
3.13.0
3.13.0rc3
3.14.0
3.14.0rc1
3.14.0rc2
3.14.0rc3
3.15.0
3.15.0rc1
3.15.0rc2
3.15.1
3.15.2
3.15.3
3.15.4
3.15.5
3.15.6
3.15.7
3.15.8
3.16.0
3.16.0rc1
3.16.0rc2
3.17.0
3.17.0rc1
3.17.0rc2
3.17.1
3.17.2
3.17.3
3.18.0
3.18.0rc1
3.18.0rc2
3.18.1
3.18.3
3.19.0
3.19.0rc1
3.19.0rc2
3.19.1
3.19.2
3.19.3
3.19.4
3.19.5
3.19.6
3.2.0
3.2.0rc1
3.2.0rc1.post1
3.2.0rc2
3.20.0
3.20.0rc1
3.20.0rc2
3.20.1
3.20.1rc1
3.20.2
3.20.3
3.3.0
3.4.0
3.5.0.post1
3.5.1
3.5.2
3.5.2.post1
3.6.0
3.6.1
3.7.0
3.7.0rc2
3.7.0rc3
3.7.1
3.8.0
3.8.0rc1
3.9.0
3.9.0rc1
3.9.1
3.9.2
4.0.0rc1
4.0.0rc2
4.21.0
4.21.0rc1
4.21.0rc2
4.21.1
4.21.10
4.21.11
4.21.12
4.21.2
4.21.3
4.21.4
4.21.5
4.21.6
4.21.7
4.21.8
4.21.9
4.22.0
4.22.0rc1
4.22.0rc2
4.22.0rc3
4.22.1
4.22.3
4.22.4
4.22.5
4.23.0
4.23.0rc2
4.23.0rc3
4.23.1
4.23.2
4.23.3
4.23.4
4.24.0
4.24.0rc1
4.24.0rc2
4.24.0rc3
4.24.1
4.24.2
4.24.3
4.24.4
4.25.0
4.25.0rc1
4.25.0rc2
4.25.1
4.25.2
4.25.3
4.25.4
4.25.5
4.25.6
4.25.7
5.26.0
5.26.0rc1
5.26.0rc2
5.26.0rc3
5.26.1
5.27.0
5.27.0rc1
5.27.0rc2
5.27.0rc3
5.27.1
5.27.2
5.27.3
5.27.4
5.27.5
5.28.0
5.28.0rc1
5.28.0rc2
5.28.0rc3
5.28.1
5.28.2
5.28.3
5.29.0
5.29.0rc1
5.29.0rc2
5.29.0rc3
5.29.1
5.29.2
5.29.3
5.29.4
6.30.0
6.30.0rc1
6.30.0rc2
6.30.1
6.30.2
6.31.0
6.31.0rc1
6.31.0rc2
Fixed in
4.25.8
5.29.5
6.31.1
References
Updated Jul 07, 2026 · Source: OSV.dev |
6.30.0
major
|
|
6.30.0rc2
pre
2 CVEs
CVE-2026-0994
PYSEC-2026-1805
GHSA-7gcm-g887-7qv7
Jul 07, 2026
protobuf affected by a JSON recursion depth bypass
High
Network
Low
None
None
A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages. Due to missing recursion depth accounting inside the internal Any-handling logic, an attacker can supply deeply nested Any structures that bypass the intended recursion limit, eventually exhausting Python’s recursion stack and causing a RecursionError. Affected versions
2.0.0beta
2.0.3
2.3.0
2.4.1
2.5.0
2.6.0
2.6.1
3.0.0
3.0.0a2
3.0.0a3
3.0.0b1
3.0.0b1.post1
+ 193 more Show less
3.0.0b1.post2
3.0.0b2
3.0.0b2.post1
3.0.0b2.post2
3.0.0b3
3.0.0b4
3.1.0
3.1.0.post1
3.10.0
3.10.0rc1
3.11.0
3.11.0rc1
3.11.0rc2
3.11.1
3.11.2
3.11.3
3.12.0
3.12.0rc1
3.12.0rc2
3.12.1
3.12.2
3.12.4
3.13.0
3.13.0rc3
3.14.0
3.14.0rc1
3.14.0rc2
3.14.0rc3
3.15.0
3.15.0rc1
3.15.0rc2
3.15.1
3.15.2
3.15.3
3.15.4
3.15.5
3.15.6
3.15.7
3.15.8
3.16.0
3.16.0rc1
3.16.0rc2
3.17.0
3.17.0rc1
3.17.0rc2
3.17.1
3.17.2
3.17.3
3.18.0
3.18.0rc1
3.18.0rc2
3.18.1
3.18.3
3.19.0
3.19.0rc1
3.19.0rc2
3.19.1
3.19.2
3.19.3
3.19.4
3.19.5
3.19.6
3.2.0
3.2.0rc1
3.2.0rc1.post1
3.2.0rc2
3.20.0
3.20.0rc1
3.20.0rc2
3.20.1
3.20.1rc1
3.20.2
3.20.3
3.3.0
3.4.0
3.5.0.post1
3.5.1
3.5.2
3.5.2.post1
3.6.0
3.6.1
3.7.0
3.7.0rc2
3.7.0rc3
3.7.1
3.8.0
3.8.0rc1
3.9.0
3.9.0rc1
3.9.1
3.9.2
4.0.0rc1
4.0.0rc2
4.21.0
4.21.0rc1
4.21.0rc2
4.21.1
4.21.10
4.21.11
4.21.12
4.21.2
4.21.3
4.21.4
4.21.5
4.21.6
4.21.7
4.21.8
4.21.9
4.22.0
4.22.0rc1
4.22.0rc2
4.22.0rc3
4.22.1
4.22.3
4.22.4
4.22.5
4.23.0
4.23.0rc2
4.23.0rc3
4.23.1
4.23.2
4.23.3
4.23.4
4.24.0
4.24.0rc1
4.24.0rc2
4.24.0rc3
4.24.1
4.24.2
4.24.3
4.24.4
4.25.0
4.25.0rc1
4.25.0rc2
4.25.1
4.25.2
4.25.3
4.25.4
4.25.5
4.25.6
4.25.7
4.25.8
4.25.9
5.26.0
5.26.0rc1
5.26.0rc2
5.26.0rc3
5.26.1
5.27.0
5.27.0rc1
5.27.0rc2
5.27.0rc3
5.27.1
5.27.2
5.27.3
5.27.4
5.27.5
5.28.0
5.28.0rc1
5.28.0rc2
5.28.0rc3
5.28.1
5.28.2
5.28.3
5.29.0
5.29.0rc1
5.29.0rc2
5.29.0rc3
5.29.1
5.29.2
5.29.3
5.29.4
5.29.5
6.30.0
6.30.0rc1
6.30.0rc2
6.30.1
6.30.2
6.31.0
6.31.0rc1
6.31.0rc2
6.31.1
6.32.0
6.32.0rc1
6.32.0rc2
6.32.1
6.33.0
6.33.0rc1
6.33.0rc2
6.33.1
6.33.2
6.33.3
6.33.4
Fixed in
5.29.6
6.33.5
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-4565
PYSEC-2026-1806
GHSA-8qvm-5x2c-j2w7
Jul 07, 2026
protobuf-python has a potential Denial of Service issue
High
Network
Low
None
None
SummaryAny project that uses Protobuf pure-Python backend to parse untrusted Protocol Buffers data containing an arbitrary number of recursive groups, recursive messages or a series of Reporter: Alexis Challande, Trail of Bits Ecosystem Security Team ecosystem@trailofbits.com Affected versions: This issue only affects the pure-Python implementation of protobuf-python backend. This is the implementation when This is a Python variant of a previous issue affecting protobuf-java. SeverityThis is a potential Denial of Service. Parsing nested protobuf data creates unbounded recursions that can be abused by an attacker. Proof of ConceptFor reproduction details, please refer to the unit tests decoder_test.py and message_test Remediation and MitigationA mitigation is available now. Please update to the latest available versions of the following packages:
Affected versions
2.0.0beta
2.0.3
2.3.0
2.4.1
2.5.0
2.6.0
2.6.1
3.0.0
3.0.0a2
3.0.0a3
3.0.0b1
3.0.0b1.post1
+ 178 more Show less
3.0.0b1.post2
3.0.0b2
3.0.0b2.post1
3.0.0b2.post2
3.0.0b3
3.0.0b4
3.1.0
3.1.0.post1
3.10.0
3.10.0rc1
3.11.0
3.11.0rc1
3.11.0rc2
3.11.1
3.11.2
3.11.3
3.12.0
3.12.0rc1
3.12.0rc2
3.12.1
3.12.2
3.12.4
3.13.0
3.13.0rc3
3.14.0
3.14.0rc1
3.14.0rc2
3.14.0rc3
3.15.0
3.15.0rc1
3.15.0rc2
3.15.1
3.15.2
3.15.3
3.15.4
3.15.5
3.15.6
3.15.7
3.15.8
3.16.0
3.16.0rc1
3.16.0rc2
3.17.0
3.17.0rc1
3.17.0rc2
3.17.1
3.17.2
3.17.3
3.18.0
3.18.0rc1
3.18.0rc2
3.18.1
3.18.3
3.19.0
3.19.0rc1
3.19.0rc2
3.19.1
3.19.2
3.19.3
3.19.4
3.19.5
3.19.6
3.2.0
3.2.0rc1
3.2.0rc1.post1
3.2.0rc2
3.20.0
3.20.0rc1
3.20.0rc2
3.20.1
3.20.1rc1
3.20.2
3.20.3
3.3.0
3.4.0
3.5.0.post1
3.5.1
3.5.2
3.5.2.post1
3.6.0
3.6.1
3.7.0
3.7.0rc2
3.7.0rc3
3.7.1
3.8.0
3.8.0rc1
3.9.0
3.9.0rc1
3.9.1
3.9.2
4.0.0rc1
4.0.0rc2
4.21.0
4.21.0rc1
4.21.0rc2
4.21.1
4.21.10
4.21.11
4.21.12
4.21.2
4.21.3
4.21.4
4.21.5
4.21.6
4.21.7
4.21.8
4.21.9
4.22.0
4.22.0rc1
4.22.0rc2
4.22.0rc3
4.22.1
4.22.3
4.22.4
4.22.5
4.23.0
4.23.0rc2
4.23.0rc3
4.23.1
4.23.2
4.23.3
4.23.4
4.24.0
4.24.0rc1
4.24.0rc2
4.24.0rc3
4.24.1
4.24.2
4.24.3
4.24.4
4.25.0
4.25.0rc1
4.25.0rc2
4.25.1
4.25.2
4.25.3
4.25.4
4.25.5
4.25.6
4.25.7
5.26.0
5.26.0rc1
5.26.0rc2
5.26.0rc3
5.26.1
5.27.0
5.27.0rc1
5.27.0rc2
5.27.0rc3
5.27.1
5.27.2
5.27.3
5.27.4
5.27.5
5.28.0
5.28.0rc1
5.28.0rc2
5.28.0rc3
5.28.1
5.28.2
5.28.3
5.29.0
5.29.0rc1
5.29.0rc2
5.29.0rc3
5.29.1
5.29.2
5.29.3
5.29.4
6.30.0
6.30.0rc1
6.30.0rc2
6.30.1
6.30.2
6.31.0
6.31.0rc1
6.31.0rc2
Fixed in
4.25.8
5.29.5
6.31.1
References
Updated Jul 07, 2026 · Source: OSV.dev |
6.30.0rc2
pre
|
|
6.30.0rc1
pre
2 CVEs
CVE-2026-0994
PYSEC-2026-1805
GHSA-7gcm-g887-7qv7
Jul 07, 2026
protobuf affected by a JSON recursion depth bypass
High
Network
Low
None
None
A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages. Due to missing recursion depth accounting inside the internal Any-handling logic, an attacker can supply deeply nested Any structures that bypass the intended recursion limit, eventually exhausting Python’s recursion stack and causing a RecursionError. Affected versions
2.0.0beta
2.0.3
2.3.0
2.4.1
2.5.0
2.6.0
2.6.1
3.0.0
3.0.0a2
3.0.0a3
3.0.0b1
3.0.0b1.post1
+ 193 more Show less
3.0.0b1.post2
3.0.0b2
3.0.0b2.post1
3.0.0b2.post2
3.0.0b3
3.0.0b4
3.1.0
3.1.0.post1
3.10.0
3.10.0rc1
3.11.0
3.11.0rc1
3.11.0rc2
3.11.1
3.11.2
3.11.3
3.12.0
3.12.0rc1
3.12.0rc2
3.12.1
3.12.2
3.12.4
3.13.0
3.13.0rc3
3.14.0
3.14.0rc1
3.14.0rc2
3.14.0rc3
3.15.0
3.15.0rc1
3.15.0rc2
3.15.1
3.15.2
3.15.3
3.15.4
3.15.5
3.15.6
3.15.7
3.15.8
3.16.0
3.16.0rc1
3.16.0rc2
3.17.0
3.17.0rc1
3.17.0rc2
3.17.1
3.17.2
3.17.3
3.18.0
3.18.0rc1
3.18.0rc2
3.18.1
3.18.3
3.19.0
3.19.0rc1
3.19.0rc2
3.19.1
3.19.2
3.19.3
3.19.4
3.19.5
3.19.6
3.2.0
3.2.0rc1
3.2.0rc1.post1
3.2.0rc2
3.20.0
3.20.0rc1
3.20.0rc2
3.20.1
3.20.1rc1
3.20.2
3.20.3
3.3.0
3.4.0
3.5.0.post1
3.5.1
3.5.2
3.5.2.post1
3.6.0
3.6.1
3.7.0
3.7.0rc2
3.7.0rc3
3.7.1
3.8.0
3.8.0rc1
3.9.0
3.9.0rc1
3.9.1
3.9.2
4.0.0rc1
4.0.0rc2
4.21.0
4.21.0rc1
4.21.0rc2
4.21.1
4.21.10
4.21.11
4.21.12
4.21.2
4.21.3
4.21.4
4.21.5
4.21.6
4.21.7
4.21.8
4.21.9
4.22.0
4.22.0rc1
4.22.0rc2
4.22.0rc3
4.22.1
4.22.3
4.22.4
4.22.5
4.23.0
4.23.0rc2
4.23.0rc3
4.23.1
4.23.2
4.23.3
4.23.4
4.24.0
4.24.0rc1
4.24.0rc2
4.24.0rc3
4.24.1
4.24.2
4.24.3
4.24.4
4.25.0
4.25.0rc1
4.25.0rc2
4.25.1
4.25.2
4.25.3
4.25.4
4.25.5
4.25.6
4.25.7
4.25.8
4.25.9
5.26.0
5.26.0rc1
5.26.0rc2
5.26.0rc3
5.26.1
5.27.0
5.27.0rc1
5.27.0rc2
5.27.0rc3
5.27.1
5.27.2
5.27.3
5.27.4
5.27.5
5.28.0
5.28.0rc1
5.28.0rc2
5.28.0rc3
5.28.1
5.28.2
5.28.3
5.29.0
5.29.0rc1
5.29.0rc2
5.29.0rc3
5.29.1
5.29.2
5.29.3
5.29.4
5.29.5
6.30.0
6.30.0rc1
6.30.0rc2
6.30.1
6.30.2
6.31.0
6.31.0rc1
6.31.0rc2
6.31.1
6.32.0
6.32.0rc1
6.32.0rc2
6.32.1
6.33.0
6.33.0rc1
6.33.0rc2
6.33.1
6.33.2
6.33.3
6.33.4
Fixed in
5.29.6
6.33.5
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-4565
PYSEC-2026-1806
GHSA-8qvm-5x2c-j2w7
Jul 07, 2026
protobuf-python has a potential Denial of Service issue
High
Network
Low
None
None
SummaryAny project that uses Protobuf pure-Python backend to parse untrusted Protocol Buffers data containing an arbitrary number of recursive groups, recursive messages or a series of Reporter: Alexis Challande, Trail of Bits Ecosystem Security Team ecosystem@trailofbits.com Affected versions: This issue only affects the pure-Python implementation of protobuf-python backend. This is the implementation when This is a Python variant of a previous issue affecting protobuf-java. SeverityThis is a potential Denial of Service. Parsing nested protobuf data creates unbounded recursions that can be abused by an attacker. Proof of ConceptFor reproduction details, please refer to the unit tests decoder_test.py and message_test Remediation and MitigationA mitigation is available now. Please update to the latest available versions of the following packages:
Affected versions
2.0.0beta
2.0.3
2.3.0
2.4.1
2.5.0
2.6.0
2.6.1
3.0.0
3.0.0a2
3.0.0a3
3.0.0b1
3.0.0b1.post1
+ 178 more Show less
3.0.0b1.post2
3.0.0b2
3.0.0b2.post1
3.0.0b2.post2
3.0.0b3
3.0.0b4
3.1.0
3.1.0.post1
3.10.0
3.10.0rc1
3.11.0
3.11.0rc1
3.11.0rc2
3.11.1
3.11.2
3.11.3
3.12.0
3.12.0rc1
3.12.0rc2
3.12.1
3.12.2
3.12.4
3.13.0
3.13.0rc3
3.14.0
3.14.0rc1
3.14.0rc2
3.14.0rc3
3.15.0
3.15.0rc1
3.15.0rc2
3.15.1
3.15.2
3.15.3
3.15.4
3.15.5
3.15.6
3.15.7
3.15.8
3.16.0
3.16.0rc1
3.16.0rc2
3.17.0
3.17.0rc1
3.17.0rc2
3.17.1
3.17.2
3.17.3
3.18.0
3.18.0rc1
3.18.0rc2
3.18.1
3.18.3
3.19.0
3.19.0rc1
3.19.0rc2
3.19.1
3.19.2
3.19.3
3.19.4
3.19.5
3.19.6
3.2.0
3.2.0rc1
3.2.0rc1.post1
3.2.0rc2
3.20.0
3.20.0rc1
3.20.0rc2
3.20.1
3.20.1rc1
3.20.2
3.20.3
3.3.0
3.4.0
3.5.0.post1
3.5.1
3.5.2
3.5.2.post1
3.6.0
3.6.1
3.7.0
3.7.0rc2
3.7.0rc3
3.7.1
3.8.0
3.8.0rc1
3.9.0
3.9.0rc1
3.9.1
3.9.2
4.0.0rc1
4.0.0rc2
4.21.0
4.21.0rc1
4.21.0rc2
4.21.1
4.21.10
4.21.11
4.21.12
4.21.2
4.21.3
4.21.4
4.21.5
4.21.6
4.21.7
4.21.8
4.21.9
4.22.0
4.22.0rc1
4.22.0rc2
4.22.0rc3
4.22.1
4.22.3
4.22.4
4.22.5
4.23.0
4.23.0rc2
4.23.0rc3
4.23.1
4.23.2
4.23.3
4.23.4
4.24.0
4.24.0rc1
4.24.0rc2
4.24.0rc3
4.24.1
4.24.2
4.24.3
4.24.4
4.25.0
4.25.0rc1
4.25.0rc2
4.25.1
4.25.2
4.25.3
4.25.4
4.25.5
4.25.6
4.25.7
5.26.0
5.26.0rc1
5.26.0rc2
5.26.0rc3
5.26.1
5.27.0
5.27.0rc1
5.27.0rc2
5.27.0rc3
5.27.1
5.27.2
5.27.3
5.27.4
5.27.5
5.28.0
5.28.0rc1
5.28.0rc2
5.28.0rc3
5.28.1
5.28.2
5.28.3
5.29.0
5.29.0rc1
5.29.0rc2
5.29.0rc3
5.29.1
5.29.2
5.29.3
5.29.4
6.30.0
6.30.0rc1
6.30.0rc2
6.30.1
6.30.2
6.31.0
6.31.0rc1
6.31.0rc2
Fixed in
4.25.8
5.29.5
6.31.1
References
Updated Jul 07, 2026 · Source: OSV.dev |
6.30.0rc1
pre
|
|
4.25.6
patch
2 CVEs
CVE-2026-0994
PYSEC-2026-1805
GHSA-7gcm-g887-7qv7
Jul 07, 2026
protobuf affected by a JSON recursion depth bypass
High
Network
Low
None
None
A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages. Due to missing recursion depth accounting inside the internal Any-handling logic, an attacker can supply deeply nested Any structures that bypass the intended recursion limit, eventually exhausting Python’s recursion stack and causing a RecursionError. Affected versions
2.0.0beta
2.0.3
2.3.0
2.4.1
2.5.0
2.6.0
2.6.1
3.0.0
3.0.0a2
3.0.0a3
3.0.0b1
3.0.0b1.post1
+ 193 more Show less
3.0.0b1.post2
3.0.0b2
3.0.0b2.post1
3.0.0b2.post2
3.0.0b3
3.0.0b4
3.1.0
3.1.0.post1
3.10.0
3.10.0rc1
3.11.0
3.11.0rc1
3.11.0rc2
3.11.1
3.11.2
3.11.3
3.12.0
3.12.0rc1
3.12.0rc2
3.12.1
3.12.2
3.12.4
3.13.0
3.13.0rc3
3.14.0
3.14.0rc1
3.14.0rc2
3.14.0rc3
3.15.0
3.15.0rc1
3.15.0rc2
3.15.1
3.15.2
3.15.3
3.15.4
3.15.5
3.15.6
3.15.7
3.15.8
3.16.0
3.16.0rc1
3.16.0rc2
3.17.0
3.17.0rc1
3.17.0rc2
3.17.1
3.17.2
3.17.3
3.18.0
3.18.0rc1
3.18.0rc2
3.18.1
3.18.3
3.19.0
3.19.0rc1
3.19.0rc2
3.19.1
3.19.2
3.19.3
3.19.4
3.19.5
3.19.6
3.2.0
3.2.0rc1
3.2.0rc1.post1
3.2.0rc2
3.20.0
3.20.0rc1
3.20.0rc2
3.20.1
3.20.1rc1
3.20.2
3.20.3
3.3.0
3.4.0
3.5.0.post1
3.5.1
3.5.2
3.5.2.post1
3.6.0
3.6.1
3.7.0
3.7.0rc2
3.7.0rc3
3.7.1
3.8.0
3.8.0rc1
3.9.0
3.9.0rc1
3.9.1
3.9.2
4.0.0rc1
4.0.0rc2
4.21.0
4.21.0rc1
4.21.0rc2
4.21.1
4.21.10
4.21.11
4.21.12
4.21.2
4.21.3
4.21.4
4.21.5
4.21.6
4.21.7
4.21.8
4.21.9
4.22.0
4.22.0rc1
4.22.0rc2
4.22.0rc3
4.22.1
4.22.3
4.22.4
4.22.5
4.23.0
4.23.0rc2
4.23.0rc3
4.23.1
4.23.2
4.23.3
4.23.4
4.24.0
4.24.0rc1
4.24.0rc2
4.24.0rc3
4.24.1
4.24.2
4.24.3
4.24.4
4.25.0
4.25.0rc1
4.25.0rc2
4.25.1
4.25.2
4.25.3
4.25.4
4.25.5
4.25.6
4.25.7
4.25.8
4.25.9
5.26.0
5.26.0rc1
5.26.0rc2
5.26.0rc3
5.26.1
5.27.0
5.27.0rc1
5.27.0rc2
5.27.0rc3
5.27.1
5.27.2
5.27.3
5.27.4
5.27.5
5.28.0
5.28.0rc1
5.28.0rc2
5.28.0rc3
5.28.1
5.28.2
5.28.3
5.29.0
5.29.0rc1
5.29.0rc2
5.29.0rc3
5.29.1
5.29.2
5.29.3
5.29.4
5.29.5
6.30.0
6.30.0rc1
6.30.0rc2
6.30.1
6.30.2
6.31.0
6.31.0rc1
6.31.0rc2
6.31.1
6.32.0
6.32.0rc1
6.32.0rc2
6.32.1
6.33.0
6.33.0rc1
6.33.0rc2
6.33.1
6.33.2
6.33.3
6.33.4
Fixed in
5.29.6
6.33.5
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-4565
PYSEC-2026-1806
GHSA-8qvm-5x2c-j2w7
Jul 07, 2026
protobuf-python has a potential Denial of Service issue
High
Network
Low
None
None
SummaryAny project that uses Protobuf pure-Python backend to parse untrusted Protocol Buffers data containing an arbitrary number of recursive groups, recursive messages or a series of Reporter: Alexis Challande, Trail of Bits Ecosystem Security Team ecosystem@trailofbits.com Affected versions: This issue only affects the pure-Python implementation of protobuf-python backend. This is the implementation when This is a Python variant of a previous issue affecting protobuf-java. SeverityThis is a potential Denial of Service. Parsing nested protobuf data creates unbounded recursions that can be abused by an attacker. Proof of ConceptFor reproduction details, please refer to the unit tests decoder_test.py and message_test Remediation and MitigationA mitigation is available now. Please update to the latest available versions of the following packages:
Affected versions
2.0.0beta
2.0.3
2.3.0
2.4.1
2.5.0
2.6.0
2.6.1
3.0.0
3.0.0a2
3.0.0a3
3.0.0b1
3.0.0b1.post1
+ 178 more Show less
3.0.0b1.post2
3.0.0b2
3.0.0b2.post1
3.0.0b2.post2
3.0.0b3
3.0.0b4
3.1.0
3.1.0.post1
3.10.0
3.10.0rc1
3.11.0
3.11.0rc1
3.11.0rc2
3.11.1
3.11.2
3.11.3
3.12.0
3.12.0rc1
3.12.0rc2
3.12.1
3.12.2
3.12.4
3.13.0
3.13.0rc3
3.14.0
3.14.0rc1
3.14.0rc2
3.14.0rc3
3.15.0
3.15.0rc1
3.15.0rc2
3.15.1
3.15.2
3.15.3
3.15.4
3.15.5
3.15.6
3.15.7
3.15.8
3.16.0
3.16.0rc1
3.16.0rc2
3.17.0
3.17.0rc1
3.17.0rc2
3.17.1
3.17.2
3.17.3
3.18.0
3.18.0rc1
3.18.0rc2
3.18.1
3.18.3
3.19.0
3.19.0rc1
3.19.0rc2
3.19.1
3.19.2
3.19.3
3.19.4
3.19.5
3.19.6
3.2.0
3.2.0rc1
3.2.0rc1.post1
3.2.0rc2
3.20.0
3.20.0rc1
3.20.0rc2
3.20.1
3.20.1rc1
3.20.2
3.20.3
3.3.0
3.4.0
3.5.0.post1
3.5.1
3.5.2
3.5.2.post1
3.6.0
3.6.1
3.7.0
3.7.0rc2
3.7.0rc3
3.7.1
3.8.0
3.8.0rc1
3.9.0
3.9.0rc1
3.9.1
3.9.2
4.0.0rc1
4.0.0rc2
4.21.0
4.21.0rc1
4.21.0rc2
4.21.1
4.21.10
4.21.11
4.21.12
4.21.2
4.21.3
4.21.4
4.21.5
4.21.6
4.21.7
4.21.8
4.21.9
4.22.0
4.22.0rc1
4.22.0rc2
4.22.0rc3
4.22.1
4.22.3
4.22.4
4.22.5
4.23.0
4.23.0rc2
4.23.0rc3
4.23.1
4.23.2
4.23.3
4.23.4
4.24.0
4.24.0rc1
4.24.0rc2
4.24.0rc3
4.24.1
4.24.2
4.24.3
4.24.4
4.25.0
4.25.0rc1
4.25.0rc2
4.25.1
4.25.2
4.25.3
4.25.4
4.25.5
4.25.6
4.25.7
5.26.0
5.26.0rc1
5.26.0rc2
5.26.0rc3
5.26.1
5.27.0
5.27.0rc1
5.27.0rc2
5.27.0rc3
5.27.1
5.27.2
5.27.3
5.27.4
5.27.5
5.28.0
5.28.0rc1
5.28.0rc2
5.28.0rc3
5.28.1
5.28.2
5.28.3
5.29.0
5.29.0rc1
5.29.0rc2
5.29.0rc3
5.29.1
5.29.2
5.29.3
5.29.4
6.30.0
6.30.0rc1
6.30.0rc2
6.30.1
6.30.2
6.31.0
6.31.0rc1
6.31.0rc2
Fixed in
4.25.8
5.29.5
6.31.1
References
Updated Jul 07, 2026 · Source: OSV.dev |
4.25.6
patch
|
|
5.29.3
patch
2 CVEs
CVE-2026-0994
PYSEC-2026-1805
GHSA-7gcm-g887-7qv7
Jul 07, 2026
protobuf affected by a JSON recursion depth bypass
High
Network
Low
None
None
A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages. Due to missing recursion depth accounting inside the internal Any-handling logic, an attacker can supply deeply nested Any structures that bypass the intended recursion limit, eventually exhausting Python’s recursion stack and causing a RecursionError. Affected versions
2.0.0beta
2.0.3
2.3.0
2.4.1
2.5.0
2.6.0
2.6.1
3.0.0
3.0.0a2
3.0.0a3
3.0.0b1
3.0.0b1.post1
+ 193 more Show less
3.0.0b1.post2
3.0.0b2
3.0.0b2.post1
3.0.0b2.post2
3.0.0b3
3.0.0b4
3.1.0
3.1.0.post1
3.10.0
3.10.0rc1
3.11.0
3.11.0rc1
3.11.0rc2
3.11.1
3.11.2
3.11.3
3.12.0
3.12.0rc1
3.12.0rc2
3.12.1
3.12.2
3.12.4
3.13.0
3.13.0rc3
3.14.0
3.14.0rc1
3.14.0rc2
3.14.0rc3
3.15.0
3.15.0rc1
3.15.0rc2
3.15.1
3.15.2
3.15.3
3.15.4
3.15.5
3.15.6
3.15.7
3.15.8
3.16.0
3.16.0rc1
3.16.0rc2
3.17.0
3.17.0rc1
3.17.0rc2
3.17.1
3.17.2
3.17.3
3.18.0
3.18.0rc1
3.18.0rc2
3.18.1
3.18.3
3.19.0
3.19.0rc1
3.19.0rc2
3.19.1
3.19.2
3.19.3
3.19.4
3.19.5
3.19.6
3.2.0
3.2.0rc1
3.2.0rc1.post1
3.2.0rc2
3.20.0
3.20.0rc1
3.20.0rc2
3.20.1
3.20.1rc1
3.20.2
3.20.3
3.3.0
3.4.0
3.5.0.post1
3.5.1
3.5.2
3.5.2.post1
3.6.0
3.6.1
3.7.0
3.7.0rc2
3.7.0rc3
3.7.1
3.8.0
3.8.0rc1
3.9.0
3.9.0rc1
3.9.1
3.9.2
4.0.0rc1
4.0.0rc2
4.21.0
4.21.0rc1
4.21.0rc2
4.21.1
4.21.10
4.21.11
4.21.12
4.21.2
4.21.3
4.21.4
4.21.5
4.21.6
4.21.7
4.21.8
4.21.9
4.22.0
4.22.0rc1
4.22.0rc2
4.22.0rc3
4.22.1
4.22.3
4.22.4
4.22.5
4.23.0
4.23.0rc2
4.23.0rc3
4.23.1
4.23.2
4.23.3
4.23.4
4.24.0
4.24.0rc1
4.24.0rc2
4.24.0rc3
4.24.1
4.24.2
4.24.3
4.24.4
4.25.0
4.25.0rc1
4.25.0rc2
4.25.1
4.25.2
4.25.3
4.25.4
4.25.5
4.25.6
4.25.7
4.25.8
4.25.9
5.26.0
5.26.0rc1
5.26.0rc2
5.26.0rc3
5.26.1
5.27.0
5.27.0rc1
5.27.0rc2
5.27.0rc3
5.27.1
5.27.2
5.27.3
5.27.4
5.27.5
5.28.0
5.28.0rc1
5.28.0rc2
5.28.0rc3
5.28.1
5.28.2
5.28.3
5.29.0
5.29.0rc1
5.29.0rc2
5.29.0rc3
5.29.1
5.29.2
5.29.3
5.29.4
5.29.5
6.30.0
6.30.0rc1
6.30.0rc2
6.30.1
6.30.2
6.31.0
6.31.0rc1
6.31.0rc2
6.31.1
6.32.0
6.32.0rc1
6.32.0rc2
6.32.1
6.33.0
6.33.0rc1
6.33.0rc2
6.33.1
6.33.2
6.33.3
6.33.4
Fixed in
5.29.6
6.33.5
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-4565
PYSEC-2026-1806
GHSA-8qvm-5x2c-j2w7
Jul 07, 2026
protobuf-python has a potential Denial of Service issue
High
Network
Low
None
None
SummaryAny project that uses Protobuf pure-Python backend to parse untrusted Protocol Buffers data containing an arbitrary number of recursive groups, recursive messages or a series of Reporter: Alexis Challande, Trail of Bits Ecosystem Security Team ecosystem@trailofbits.com Affected versions: This issue only affects the pure-Python implementation of protobuf-python backend. This is the implementation when This is a Python variant of a previous issue affecting protobuf-java. SeverityThis is a potential Denial of Service. Parsing nested protobuf data creates unbounded recursions that can be abused by an attacker. Proof of ConceptFor reproduction details, please refer to the unit tests decoder_test.py and message_test Remediation and MitigationA mitigation is available now. Please update to the latest available versions of the following packages:
Affected versions
2.0.0beta
2.0.3
2.3.0
2.4.1
2.5.0
2.6.0
2.6.1
3.0.0
3.0.0a2
3.0.0a3
3.0.0b1
3.0.0b1.post1
+ 178 more Show less
3.0.0b1.post2
3.0.0b2
3.0.0b2.post1
3.0.0b2.post2
3.0.0b3
3.0.0b4
3.1.0
3.1.0.post1
3.10.0
3.10.0rc1
3.11.0
3.11.0rc1
3.11.0rc2
3.11.1
3.11.2
3.11.3
3.12.0
3.12.0rc1
3.12.0rc2
3.12.1
3.12.2
3.12.4
3.13.0
3.13.0rc3
3.14.0
3.14.0rc1
3.14.0rc2
3.14.0rc3
3.15.0
3.15.0rc1
3.15.0rc2
3.15.1
3.15.2
3.15.3
3.15.4
3.15.5
3.15.6
3.15.7
3.15.8
3.16.0
3.16.0rc1
3.16.0rc2
3.17.0
3.17.0rc1
3.17.0rc2
3.17.1
3.17.2
3.17.3
3.18.0
3.18.0rc1
3.18.0rc2
3.18.1
3.18.3
3.19.0
3.19.0rc1
3.19.0rc2
3.19.1
3.19.2
3.19.3
3.19.4
3.19.5
3.19.6
3.2.0
3.2.0rc1
3.2.0rc1.post1
3.2.0rc2
3.20.0
3.20.0rc1
3.20.0rc2
3.20.1
3.20.1rc1
3.20.2
3.20.3
3.3.0
3.4.0
3.5.0.post1
3.5.1
3.5.2
3.5.2.post1
3.6.0
3.6.1
3.7.0
3.7.0rc2
3.7.0rc3
3.7.1
3.8.0
3.8.0rc1
3.9.0
3.9.0rc1
3.9.1
3.9.2
4.0.0rc1
4.0.0rc2
4.21.0
4.21.0rc1
4.21.0rc2
4.21.1
4.21.10
4.21.11
4.21.12
4.21.2
4.21.3
4.21.4
4.21.5
4.21.6
4.21.7
4.21.8
4.21.9
4.22.0
4.22.0rc1
4.22.0rc2
4.22.0rc3
4.22.1
4.22.3
4.22.4
4.22.5
4.23.0
4.23.0rc2
4.23.0rc3
4.23.1
4.23.2
4.23.3
4.23.4
4.24.0
4.24.0rc1
4.24.0rc2
4.24.0rc3
4.24.1
4.24.2
4.24.3
4.24.4
4.25.0
4.25.0rc1
4.25.0rc2
4.25.1
4.25.2
4.25.3
4.25.4
4.25.5
4.25.6
4.25.7
5.26.0
5.26.0rc1
5.26.0rc2
5.26.0rc3
5.26.1
5.27.0
5.27.0rc1
5.27.0rc2
5.27.0rc3
5.27.1
5.27.2
5.27.3
5.27.4
5.27.5
5.28.0
5.28.0rc1
5.28.0rc2
5.28.0rc3
5.28.1
5.28.2
5.28.3
5.29.0
5.29.0rc1
5.29.0rc2
5.29.0rc3
5.29.1
5.29.2
5.29.3
5.29.4
6.30.0
6.30.0rc1
6.30.0rc2
6.30.1
6.30.2
6.31.0
6.31.0rc1
6.31.0rc2
Fixed in
4.25.8
5.29.5
6.31.1
References
Updated Jul 07, 2026 · Source: OSV.dev |
5.29.3
patch
|
|
5.29.2
patch
2 CVEs
CVE-2026-0994
PYSEC-2026-1805
GHSA-7gcm-g887-7qv7
Jul 07, 2026
protobuf affected by a JSON recursion depth bypass
High
Network
Low
None
None
A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages. Due to missing recursion depth accounting inside the internal Any-handling logic, an attacker can supply deeply nested Any structures that bypass the intended recursion limit, eventually exhausting Python’s recursion stack and causing a RecursionError. Affected versions
2.0.0beta
2.0.3
2.3.0
2.4.1
2.5.0
2.6.0
2.6.1
3.0.0
3.0.0a2
3.0.0a3
3.0.0b1
3.0.0b1.post1
+ 193 more Show less
3.0.0b1.post2
3.0.0b2
3.0.0b2.post1
3.0.0b2.post2
3.0.0b3
3.0.0b4
3.1.0
3.1.0.post1
3.10.0
3.10.0rc1
3.11.0
3.11.0rc1
3.11.0rc2
3.11.1
3.11.2
3.11.3
3.12.0
3.12.0rc1
3.12.0rc2
3.12.1
3.12.2
3.12.4
3.13.0
3.13.0rc3
3.14.0
3.14.0rc1
3.14.0rc2
3.14.0rc3
3.15.0
3.15.0rc1
3.15.0rc2
3.15.1
3.15.2
3.15.3
3.15.4
3.15.5
3.15.6
3.15.7
3.15.8
3.16.0
3.16.0rc1
3.16.0rc2
3.17.0
3.17.0rc1
3.17.0rc2
3.17.1
3.17.2
3.17.3
3.18.0
3.18.0rc1
3.18.0rc2
3.18.1
3.18.3
3.19.0
3.19.0rc1
3.19.0rc2
3.19.1
3.19.2
3.19.3
3.19.4
3.19.5
3.19.6
3.2.0
3.2.0rc1
3.2.0rc1.post1
3.2.0rc2
3.20.0
3.20.0rc1
3.20.0rc2
3.20.1
3.20.1rc1
3.20.2
3.20.3
3.3.0
3.4.0
3.5.0.post1
3.5.1
3.5.2
3.5.2.post1
3.6.0
3.6.1
3.7.0
3.7.0rc2
3.7.0rc3
3.7.1
3.8.0
3.8.0rc1
3.9.0
3.9.0rc1
3.9.1
3.9.2
4.0.0rc1
4.0.0rc2
4.21.0
4.21.0rc1
4.21.0rc2
4.21.1
4.21.10
4.21.11
4.21.12
4.21.2
4.21.3
4.21.4
4.21.5
4.21.6
4.21.7
4.21.8
4.21.9
4.22.0
4.22.0rc1
4.22.0rc2
4.22.0rc3
4.22.1
4.22.3
4.22.4
4.22.5
4.23.0
4.23.0rc2
4.23.0rc3
4.23.1
4.23.2
4.23.3
4.23.4
4.24.0
4.24.0rc1
4.24.0rc2
4.24.0rc3
4.24.1
4.24.2
4.24.3
4.24.4
4.25.0
4.25.0rc1
4.25.0rc2
4.25.1
4.25.2
4.25.3
4.25.4
4.25.5
4.25.6
4.25.7
4.25.8
4.25.9
5.26.0
5.26.0rc1
5.26.0rc2
5.26.0rc3
5.26.1
5.27.0
5.27.0rc1
5.27.0rc2
5.27.0rc3
5.27.1
5.27.2
5.27.3
5.27.4
5.27.5
5.28.0
5.28.0rc1
5.28.0rc2
5.28.0rc3
5.28.1
5.28.2
5.28.3
5.29.0
5.29.0rc1
5.29.0rc2
5.29.0rc3
5.29.1
5.29.2
5.29.3
5.29.4
5.29.5
6.30.0
6.30.0rc1
6.30.0rc2
6.30.1
6.30.2
6.31.0
6.31.0rc1
6.31.0rc2
6.31.1
6.32.0
6.32.0rc1
6.32.0rc2
6.32.1
6.33.0
6.33.0rc1
6.33.0rc2
6.33.1
6.33.2
6.33.3
6.33.4
Fixed in
5.29.6
6.33.5
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-4565
PYSEC-2026-1806
GHSA-8qvm-5x2c-j2w7
Jul 07, 2026
protobuf-python has a potential Denial of Service issue
High
Network
Low
None
None
SummaryAny project that uses Protobuf pure-Python backend to parse untrusted Protocol Buffers data containing an arbitrary number of recursive groups, recursive messages or a series of Reporter: Alexis Challande, Trail of Bits Ecosystem Security Team ecosystem@trailofbits.com Affected versions: This issue only affects the pure-Python implementation of protobuf-python backend. This is the implementation when This is a Python variant of a previous issue affecting protobuf-java. SeverityThis is a potential Denial of Service. Parsing nested protobuf data creates unbounded recursions that can be abused by an attacker. Proof of ConceptFor reproduction details, please refer to the unit tests decoder_test.py and message_test Remediation and MitigationA mitigation is available now. Please update to the latest available versions of the following packages:
Affected versions
2.0.0beta
2.0.3
2.3.0
2.4.1
2.5.0
2.6.0
2.6.1
3.0.0
3.0.0a2
3.0.0a3
3.0.0b1
3.0.0b1.post1
+ 178 more Show less
3.0.0b1.post2
3.0.0b2
3.0.0b2.post1
3.0.0b2.post2
3.0.0b3
3.0.0b4
3.1.0
3.1.0.post1
3.10.0
3.10.0rc1
3.11.0
3.11.0rc1
3.11.0rc2
3.11.1
3.11.2
3.11.3
3.12.0
3.12.0rc1
3.12.0rc2
3.12.1
3.12.2
3.12.4
3.13.0
3.13.0rc3
3.14.0
3.14.0rc1
3.14.0rc2
3.14.0rc3
3.15.0
3.15.0rc1
3.15.0rc2
3.15.1
3.15.2
3.15.3
3.15.4
3.15.5
3.15.6
3.15.7
3.15.8
3.16.0
3.16.0rc1
3.16.0rc2
3.17.0
3.17.0rc1
3.17.0rc2
3.17.1
3.17.2
3.17.3
3.18.0
3.18.0rc1
3.18.0rc2
3.18.1
3.18.3
3.19.0
3.19.0rc1
3.19.0rc2
3.19.1
3.19.2
3.19.3
3.19.4
3.19.5
3.19.6
3.2.0
3.2.0rc1
3.2.0rc1.post1
3.2.0rc2
3.20.0
3.20.0rc1
3.20.0rc2
3.20.1
3.20.1rc1
3.20.2
3.20.3
3.3.0
3.4.0
3.5.0.post1
3.5.1
3.5.2
3.5.2.post1
3.6.0
3.6.1
3.7.0
3.7.0rc2
3.7.0rc3
3.7.1
3.8.0
3.8.0rc1
3.9.0
3.9.0rc1
3.9.1
3.9.2
4.0.0rc1
4.0.0rc2
4.21.0
4.21.0rc1
4.21.0rc2
4.21.1
4.21.10
4.21.11
4.21.12
4.21.2
4.21.3
4.21.4
4.21.5
4.21.6
4.21.7
4.21.8
4.21.9
4.22.0
4.22.0rc1
4.22.0rc2
4.22.0rc3
4.22.1
4.22.3
4.22.4
4.22.5
4.23.0
4.23.0rc2
4.23.0rc3
4.23.1
4.23.2
4.23.3
4.23.4
4.24.0
4.24.0rc1
4.24.0rc2
4.24.0rc3
4.24.1
4.24.2
4.24.3
4.24.4
4.25.0
4.25.0rc1
4.25.0rc2
4.25.1
4.25.2
4.25.3
4.25.4
4.25.5
4.25.6
4.25.7
5.26.0
5.26.0rc1
5.26.0rc2
5.26.0rc3
5.26.1
5.27.0
5.27.0rc1
5.27.0rc2
5.27.0rc3
5.27.1
5.27.2
5.27.3
5.27.4
5.27.5
5.28.0
5.28.0rc1
5.28.0rc2
5.28.0rc3
5.28.1
5.28.2
5.28.3
5.29.0
5.29.0rc1
5.29.0rc2
5.29.0rc3
5.29.1
5.29.2
5.29.3
5.29.4
6.30.0
6.30.0rc1
6.30.0rc2
6.30.1
6.30.2
6.31.0
6.31.0rc1
6.31.0rc2
Fixed in
4.25.8
5.29.5
6.31.1
References
Updated Jul 07, 2026 · Source: OSV.dev |
5.29.2
patch
|
|
5.29.1
patch
2 CVEs
CVE-2026-0994
PYSEC-2026-1805
GHSA-7gcm-g887-7qv7
Jul 07, 2026
protobuf affected by a JSON recursion depth bypass
High
Network
Low
None
None
A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages. Due to missing recursion depth accounting inside the internal Any-handling logic, an attacker can supply deeply nested Any structures that bypass the intended recursion limit, eventually exhausting Python’s recursion stack and causing a RecursionError. Affected versions
2.0.0beta
2.0.3
2.3.0
2.4.1
2.5.0
2.6.0
2.6.1
3.0.0
3.0.0a2
3.0.0a3
3.0.0b1
3.0.0b1.post1
+ 193 more Show less
3.0.0b1.post2
3.0.0b2
3.0.0b2.post1
3.0.0b2.post2
3.0.0b3
3.0.0b4
3.1.0
3.1.0.post1
3.10.0
3.10.0rc1
3.11.0
3.11.0rc1
3.11.0rc2
3.11.1
3.11.2
3.11.3
3.12.0
3.12.0rc1
3.12.0rc2
3.12.1
3.12.2
3.12.4
3.13.0
3.13.0rc3
3.14.0
3.14.0rc1
3.14.0rc2
3.14.0rc3
3.15.0
3.15.0rc1
3.15.0rc2
3.15.1
3.15.2
3.15.3
3.15.4
3.15.5
3.15.6
3.15.7
3.15.8
3.16.0
3.16.0rc1
3.16.0rc2
3.17.0
3.17.0rc1
3.17.0rc2
3.17.1
3.17.2
3.17.3
3.18.0
3.18.0rc1
3.18.0rc2
3.18.1
3.18.3
3.19.0
3.19.0rc1
3.19.0rc2
3.19.1
3.19.2
3.19.3
3.19.4
3.19.5
3.19.6
3.2.0
3.2.0rc1
3.2.0rc1.post1
3.2.0rc2
3.20.0
3.20.0rc1
3.20.0rc2
3.20.1
3.20.1rc1
3.20.2
3.20.3
3.3.0
3.4.0
3.5.0.post1
3.5.1
3.5.2
3.5.2.post1
3.6.0
3.6.1
3.7.0
3.7.0rc2
3.7.0rc3
3.7.1
3.8.0
3.8.0rc1
3.9.0
3.9.0rc1
3.9.1
3.9.2
4.0.0rc1
4.0.0rc2
4.21.0
4.21.0rc1
4.21.0rc2
4.21.1
4.21.10
4.21.11
4.21.12
4.21.2
4.21.3
4.21.4
4.21.5
4.21.6
4.21.7
4.21.8
4.21.9
4.22.0
4.22.0rc1
4.22.0rc2
4.22.0rc3
4.22.1
4.22.3
4.22.4
4.22.5
4.23.0
4.23.0rc2
4.23.0rc3
4.23.1
4.23.2
4.23.3
4.23.4
4.24.0
4.24.0rc1
4.24.0rc2
4.24.0rc3
4.24.1
4.24.2
4.24.3
4.24.4
4.25.0
4.25.0rc1
4.25.0rc2
4.25.1
4.25.2
4.25.3
4.25.4
4.25.5
4.25.6
4.25.7
4.25.8
4.25.9
5.26.0
5.26.0rc1
5.26.0rc2
5.26.0rc3
5.26.1
5.27.0
5.27.0rc1
5.27.0rc2
5.27.0rc3
5.27.1
5.27.2
5.27.3
5.27.4
5.27.5
5.28.0
5.28.0rc1
5.28.0rc2
5.28.0rc3
5.28.1
5.28.2
5.28.3
5.29.0
5.29.0rc1
5.29.0rc2
5.29.0rc3
5.29.1
5.29.2
5.29.3
5.29.4
5.29.5
6.30.0
6.30.0rc1
6.30.0rc2
6.30.1
6.30.2
6.31.0
6.31.0rc1
6.31.0rc2
6.31.1
6.32.0
6.32.0rc1
6.32.0rc2
6.32.1
6.33.0
6.33.0rc1
6.33.0rc2
6.33.1
6.33.2
6.33.3
6.33.4
Fixed in
5.29.6
6.33.5
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-4565
PYSEC-2026-1806
GHSA-8qvm-5x2c-j2w7
Jul 07, 2026
protobuf-python has a potential Denial of Service issue
High
Network
Low
None
None
SummaryAny project that uses Protobuf pure-Python backend to parse untrusted Protocol Buffers data containing an arbitrary number of recursive groups, recursive messages or a series of Reporter: Alexis Challande, Trail of Bits Ecosystem Security Team ecosystem@trailofbits.com Affected versions: This issue only affects the pure-Python implementation of protobuf-python backend. This is the implementation when This is a Python variant of a previous issue affecting protobuf-java. SeverityThis is a potential Denial of Service. Parsing nested protobuf data creates unbounded recursions that can be abused by an attacker. Proof of ConceptFor reproduction details, please refer to the unit tests decoder_test.py and message_test Remediation and MitigationA mitigation is available now. Please update to the latest available versions of the following packages:
Affected versions
2.0.0beta
2.0.3
2.3.0
2.4.1
2.5.0
2.6.0
2.6.1
3.0.0
3.0.0a2
3.0.0a3
3.0.0b1
3.0.0b1.post1
+ 178 more Show less
3.0.0b1.post2
3.0.0b2
3.0.0b2.post1
3.0.0b2.post2
3.0.0b3
3.0.0b4
3.1.0
3.1.0.post1
3.10.0
3.10.0rc1
3.11.0
3.11.0rc1
3.11.0rc2
3.11.1
3.11.2
3.11.3
3.12.0
3.12.0rc1
3.12.0rc2
3.12.1
3.12.2
3.12.4
3.13.0
3.13.0rc3
3.14.0
3.14.0rc1
3.14.0rc2
3.14.0rc3
3.15.0
3.15.0rc1
3.15.0rc2
3.15.1
3.15.2
3.15.3
3.15.4
3.15.5
3.15.6
3.15.7
3.15.8
3.16.0
3.16.0rc1
3.16.0rc2
3.17.0
3.17.0rc1
3.17.0rc2
3.17.1
3.17.2
3.17.3
3.18.0
3.18.0rc1
3.18.0rc2
3.18.1
3.18.3
3.19.0
3.19.0rc1
3.19.0rc2
3.19.1
3.19.2
3.19.3
3.19.4
3.19.5
3.19.6
3.2.0
3.2.0rc1
3.2.0rc1.post1
3.2.0rc2
3.20.0
3.20.0rc1
3.20.0rc2
3.20.1
3.20.1rc1
3.20.2
3.20.3
3.3.0
3.4.0
3.5.0.post1
3.5.1
3.5.2
3.5.2.post1
3.6.0
3.6.1
3.7.0
3.7.0rc2
3.7.0rc3
3.7.1
3.8.0
3.8.0rc1
3.9.0
3.9.0rc1
3.9.1
3.9.2
4.0.0rc1
4.0.0rc2
4.21.0
4.21.0rc1
4.21.0rc2
4.21.1
4.21.10
4.21.11
4.21.12
4.21.2
4.21.3
4.21.4
4.21.5
4.21.6
4.21.7
4.21.8
4.21.9
4.22.0
4.22.0rc1
4.22.0rc2
4.22.0rc3
4.22.1
4.22.3
4.22.4
4.22.5
4.23.0
4.23.0rc2
4.23.0rc3
4.23.1
4.23.2
4.23.3
4.23.4
4.24.0
4.24.0rc1
4.24.0rc2
4.24.0rc3
4.24.1
4.24.2
4.24.3
4.24.4
4.25.0
4.25.0rc1
4.25.0rc2
4.25.1
4.25.2
4.25.3
4.25.4
4.25.5
4.25.6
4.25.7
5.26.0
5.26.0rc1
5.26.0rc2
5.26.0rc3
5.26.1
5.27.0
5.27.0rc1
5.27.0rc2
5.27.0rc3
5.27.1
5.27.2
5.27.3
5.27.4
5.27.5
5.28.0
5.28.0rc1
5.28.0rc2
5.28.0rc3
5.28.1
5.28.2
5.28.3
5.29.0
5.29.0rc1
5.29.0rc2
5.29.0rc3
5.29.1
5.29.2
5.29.3
5.29.4
6.30.0
6.30.0rc1
6.30.0rc2
6.30.1
6.30.2
6.31.0
6.31.0rc1
6.31.0rc2
Fixed in
4.25.8
5.29.5
6.31.1
References
Updated Jul 07, 2026 · Source: OSV.dev |
5.29.1
patch
|
|
5.29.0
minor
2 CVEs
CVE-2026-0994
PYSEC-2026-1805
GHSA-7gcm-g887-7qv7
Jul 07, 2026
protobuf affected by a JSON recursion depth bypass
High
Network
Low
None
None
A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages. Due to missing recursion depth accounting inside the internal Any-handling logic, an attacker can supply deeply nested Any structures that bypass the intended recursion limit, eventually exhausting Python’s recursion stack and causing a RecursionError. Affected versions
2.0.0beta
2.0.3
2.3.0
2.4.1
2.5.0
2.6.0
2.6.1
3.0.0
3.0.0a2
3.0.0a3
3.0.0b1
3.0.0b1.post1
+ 193 more Show less
3.0.0b1.post2
3.0.0b2
3.0.0b2.post1
3.0.0b2.post2
3.0.0b3
3.0.0b4
3.1.0
3.1.0.post1
3.10.0
3.10.0rc1
3.11.0
3.11.0rc1
3.11.0rc2
3.11.1
3.11.2
3.11.3
3.12.0
3.12.0rc1
3.12.0rc2
3.12.1
3.12.2
3.12.4
3.13.0
3.13.0rc3
3.14.0
3.14.0rc1
3.14.0rc2
3.14.0rc3
3.15.0
3.15.0rc1
3.15.0rc2
3.15.1
3.15.2
3.15.3
3.15.4
3.15.5
3.15.6
3.15.7
3.15.8
3.16.0
3.16.0rc1
3.16.0rc2
3.17.0
3.17.0rc1
3.17.0rc2
3.17.1
3.17.2
3.17.3
3.18.0
3.18.0rc1
3.18.0rc2
3.18.1
3.18.3
3.19.0
3.19.0rc1
3.19.0rc2
3.19.1
3.19.2
3.19.3
3.19.4
3.19.5
3.19.6
3.2.0
3.2.0rc1
3.2.0rc1.post1
3.2.0rc2
3.20.0
3.20.0rc1
3.20.0rc2
3.20.1
3.20.1rc1
3.20.2
3.20.3
3.3.0
3.4.0
3.5.0.post1
3.5.1
3.5.2
3.5.2.post1
3.6.0
3.6.1
3.7.0
3.7.0rc2
3.7.0rc3
3.7.1
3.8.0
3.8.0rc1
3.9.0
3.9.0rc1
3.9.1
3.9.2
4.0.0rc1
4.0.0rc2
4.21.0
4.21.0rc1
4.21.0rc2
4.21.1
4.21.10
4.21.11
4.21.12
4.21.2
4.21.3
4.21.4
4.21.5
4.21.6
4.21.7
4.21.8
4.21.9
4.22.0
4.22.0rc1
4.22.0rc2
4.22.0rc3
4.22.1
4.22.3
4.22.4
4.22.5
4.23.0
4.23.0rc2
4.23.0rc3
4.23.1
4.23.2
4.23.3
4.23.4
4.24.0
4.24.0rc1
4.24.0rc2
4.24.0rc3
4.24.1
4.24.2
4.24.3
4.24.4
4.25.0
4.25.0rc1
4.25.0rc2
4.25.1
4.25.2
4.25.3
4.25.4
4.25.5
4.25.6
4.25.7
4.25.8
4.25.9
5.26.0
5.26.0rc1
5.26.0rc2
5.26.0rc3
5.26.1
5.27.0
5.27.0rc1
5.27.0rc2
5.27.0rc3
5.27.1
5.27.2
5.27.3
5.27.4
5.27.5
5.28.0
5.28.0rc1
5.28.0rc2
5.28.0rc3
5.28.1
5.28.2
5.28.3
5.29.0
5.29.0rc1
5.29.0rc2
5.29.0rc3
5.29.1
5.29.2
5.29.3
5.29.4
5.29.5
6.30.0
6.30.0rc1
6.30.0rc2
6.30.1
6.30.2
6.31.0
6.31.0rc1
6.31.0rc2
6.31.1
6.32.0
6.32.0rc1
6.32.0rc2
6.32.1
6.33.0
6.33.0rc1
6.33.0rc2
6.33.1
6.33.2
6.33.3
6.33.4
Fixed in
5.29.6
6.33.5
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-4565
PYSEC-2026-1806
GHSA-8qvm-5x2c-j2w7
Jul 07, 2026
protobuf-python has a potential Denial of Service issue
High
Network
Low
None
None
SummaryAny project that uses Protobuf pure-Python backend to parse untrusted Protocol Buffers data containing an arbitrary number of recursive groups, recursive messages or a series of Reporter: Alexis Challande, Trail of Bits Ecosystem Security Team ecosystem@trailofbits.com Affected versions: This issue only affects the pure-Python implementation of protobuf-python backend. This is the implementation when This is a Python variant of a previous issue affecting protobuf-java. SeverityThis is a potential Denial of Service. Parsing nested protobuf data creates unbounded recursions that can be abused by an attacker. Proof of ConceptFor reproduction details, please refer to the unit tests decoder_test.py and message_test Remediation and MitigationA mitigation is available now. Please update to the latest available versions of the following packages:
Affected versions
2.0.0beta
2.0.3
2.3.0
2.4.1
2.5.0
2.6.0
2.6.1
3.0.0
3.0.0a2
3.0.0a3
3.0.0b1
3.0.0b1.post1
+ 178 more Show less
3.0.0b1.post2
3.0.0b2
3.0.0b2.post1
3.0.0b2.post2
3.0.0b3
3.0.0b4
3.1.0
3.1.0.post1
3.10.0
3.10.0rc1
3.11.0
3.11.0rc1
3.11.0rc2
3.11.1
3.11.2
3.11.3
3.12.0
3.12.0rc1
3.12.0rc2
3.12.1
3.12.2
3.12.4
3.13.0
3.13.0rc3
3.14.0
3.14.0rc1
3.14.0rc2
3.14.0rc3
3.15.0
3.15.0rc1
3.15.0rc2
3.15.1
3.15.2
3.15.3
3.15.4
3.15.5
3.15.6
3.15.7
3.15.8
3.16.0
3.16.0rc1
3.16.0rc2
3.17.0
3.17.0rc1
3.17.0rc2
3.17.1
3.17.2
3.17.3
3.18.0
3.18.0rc1
3.18.0rc2
3.18.1
3.18.3
3.19.0
3.19.0rc1
3.19.0rc2
3.19.1
3.19.2
3.19.3
3.19.4
3.19.5
3.19.6
3.2.0
3.2.0rc1
3.2.0rc1.post1
3.2.0rc2
3.20.0
3.20.0rc1
3.20.0rc2
3.20.1
3.20.1rc1
3.20.2
3.20.3
3.3.0
3.4.0
3.5.0.post1
3.5.1
3.5.2
3.5.2.post1
3.6.0
3.6.1
3.7.0
3.7.0rc2
3.7.0rc3
3.7.1
3.8.0
3.8.0rc1
3.9.0
3.9.0rc1
3.9.1
3.9.2
4.0.0rc1
4.0.0rc2
4.21.0
4.21.0rc1
4.21.0rc2
4.21.1
4.21.10
4.21.11
4.21.12
4.21.2
4.21.3
4.21.4
4.21.5
4.21.6
4.21.7
4.21.8
4.21.9
4.22.0
4.22.0rc1
4.22.0rc2
4.22.0rc3
4.22.1
4.22.3
4.22.4
4.22.5
4.23.0
4.23.0rc2
4.23.0rc3
4.23.1
4.23.2
4.23.3
4.23.4
4.24.0
4.24.0rc1
4.24.0rc2
4.24.0rc3
4.24.1
4.24.2
4.24.3
4.24.4
4.25.0
4.25.0rc1
4.25.0rc2
4.25.1
4.25.2
4.25.3
4.25.4
4.25.5
4.25.6
4.25.7
5.26.0
5.26.0rc1
5.26.0rc2
5.26.0rc3
5.26.1
5.27.0
5.27.0rc1
5.27.0rc2
5.27.0rc3
5.27.1
5.27.2
5.27.3
5.27.4
5.27.5
5.28.0
5.28.0rc1
5.28.0rc2
5.28.0rc3
5.28.1
5.28.2
5.28.3
5.29.0
5.29.0rc1
5.29.0rc2
5.29.0rc3
5.29.1
5.29.2
5.29.3
5.29.4
6.30.0
6.30.0rc1
6.30.0rc2
6.30.1
6.30.2
6.31.0
6.31.0rc1
6.31.0rc2
Fixed in
4.25.8
5.29.5
6.31.1
References
Updated Jul 07, 2026 · Source: OSV.dev |
5.29.0
minor
|
|
5.29.0rc3
pre
2 CVEs
CVE-2026-0994
PYSEC-2026-1805
GHSA-7gcm-g887-7qv7
Jul 07, 2026
protobuf affected by a JSON recursion depth bypass
High
Network
Low
None
None
A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages. Due to missing recursion depth accounting inside the internal Any-handling logic, an attacker can supply deeply nested Any structures that bypass the intended recursion limit, eventually exhausting Python’s recursion stack and causing a RecursionError. Affected versions
2.0.0beta
2.0.3
2.3.0
2.4.1
2.5.0
2.6.0
2.6.1
3.0.0
3.0.0a2
3.0.0a3
3.0.0b1
3.0.0b1.post1
+ 193 more Show less
3.0.0b1.post2
3.0.0b2
3.0.0b2.post1
3.0.0b2.post2
3.0.0b3
3.0.0b4
3.1.0
3.1.0.post1
3.10.0
3.10.0rc1
3.11.0
3.11.0rc1
3.11.0rc2
3.11.1
3.11.2
3.11.3
3.12.0
3.12.0rc1
3.12.0rc2
3.12.1
3.12.2
3.12.4
3.13.0
3.13.0rc3
3.14.0
3.14.0rc1
3.14.0rc2
3.14.0rc3
3.15.0
3.15.0rc1
3.15.0rc2
3.15.1
3.15.2
3.15.3
3.15.4
3.15.5
3.15.6
3.15.7
3.15.8
3.16.0
3.16.0rc1
3.16.0rc2
3.17.0
3.17.0rc1
3.17.0rc2
3.17.1
3.17.2
3.17.3
3.18.0
3.18.0rc1
3.18.0rc2
3.18.1
3.18.3
3.19.0
3.19.0rc1
3.19.0rc2
3.19.1
3.19.2
3.19.3
3.19.4
3.19.5
3.19.6
3.2.0
3.2.0rc1
3.2.0rc1.post1
3.2.0rc2
3.20.0
3.20.0rc1
3.20.0rc2
3.20.1
3.20.1rc1
3.20.2
3.20.3
3.3.0
3.4.0
3.5.0.post1
3.5.1
3.5.2
3.5.2.post1
3.6.0
3.6.1
3.7.0
3.7.0rc2
3.7.0rc3
3.7.1
3.8.0
3.8.0rc1
3.9.0
3.9.0rc1
3.9.1
3.9.2
4.0.0rc1
4.0.0rc2
4.21.0
4.21.0rc1
4.21.0rc2
4.21.1
4.21.10
4.21.11
4.21.12
4.21.2
4.21.3
4.21.4
4.21.5
4.21.6
4.21.7
4.21.8
4.21.9
4.22.0
4.22.0rc1
4.22.0rc2
4.22.0rc3
4.22.1
4.22.3
4.22.4
4.22.5
4.23.0
4.23.0rc2
4.23.0rc3
4.23.1
4.23.2
4.23.3
4.23.4
4.24.0
4.24.0rc1
4.24.0rc2
4.24.0rc3
4.24.1
4.24.2
4.24.3
4.24.4
4.25.0
4.25.0rc1
4.25.0rc2
4.25.1
4.25.2
4.25.3
4.25.4
4.25.5
4.25.6
4.25.7
4.25.8
4.25.9
5.26.0
5.26.0rc1
5.26.0rc2
5.26.0rc3
5.26.1
5.27.0
5.27.0rc1
5.27.0rc2
5.27.0rc3
5.27.1
5.27.2
5.27.3
5.27.4
5.27.5
5.28.0
5.28.0rc1
5.28.0rc2
5.28.0rc3
5.28.1
5.28.2
5.28.3
5.29.0
5.29.0rc1
5.29.0rc2
5.29.0rc3
5.29.1
5.29.2
5.29.3
5.29.4
5.29.5
6.30.0
6.30.0rc1
6.30.0rc2
6.30.1
6.30.2
6.31.0
6.31.0rc1
6.31.0rc2
6.31.1
6.32.0
6.32.0rc1
6.32.0rc2
6.32.1
6.33.0
6.33.0rc1
6.33.0rc2
6.33.1
6.33.2
6.33.3
6.33.4
Fixed in
5.29.6
6.33.5
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-4565
PYSEC-2026-1806
GHSA-8qvm-5x2c-j2w7
Jul 07, 2026
protobuf-python has a potential Denial of Service issue
High
Network
Low
None
None
SummaryAny project that uses Protobuf pure-Python backend to parse untrusted Protocol Buffers data containing an arbitrary number of recursive groups, recursive messages or a series of Reporter: Alexis Challande, Trail of Bits Ecosystem Security Team ecosystem@trailofbits.com Affected versions: This issue only affects the pure-Python implementation of protobuf-python backend. This is the implementation when This is a Python variant of a previous issue affecting protobuf-java. SeverityThis is a potential Denial of Service. Parsing nested protobuf data creates unbounded recursions that can be abused by an attacker. Proof of ConceptFor reproduction details, please refer to the unit tests decoder_test.py and message_test Remediation and MitigationA mitigation is available now. Please update to the latest available versions of the following packages:
Affected versions
2.0.0beta
2.0.3
2.3.0
2.4.1
2.5.0
2.6.0
2.6.1
3.0.0
3.0.0a2
3.0.0a3
3.0.0b1
3.0.0b1.post1
+ 178 more Show less
3.0.0b1.post2
3.0.0b2
3.0.0b2.post1
3.0.0b2.post2
3.0.0b3
3.0.0b4
3.1.0
3.1.0.post1
3.10.0
3.10.0rc1
3.11.0
3.11.0rc1
3.11.0rc2
3.11.1
3.11.2
3.11.3
3.12.0
3.12.0rc1
3.12.0rc2
3.12.1
3.12.2
3.12.4
3.13.0
3.13.0rc3
3.14.0
3.14.0rc1
3.14.0rc2
3.14.0rc3
3.15.0
3.15.0rc1
3.15.0rc2
3.15.1
3.15.2
3.15.3
3.15.4
3.15.5
3.15.6
3.15.7
3.15.8
3.16.0
3.16.0rc1
3.16.0rc2
3.17.0
3.17.0rc1
3.17.0rc2
3.17.1
3.17.2
3.17.3
3.18.0
3.18.0rc1
3.18.0rc2
3.18.1
3.18.3
3.19.0
3.19.0rc1
3.19.0rc2
3.19.1
3.19.2
3.19.3
3.19.4
3.19.5
3.19.6
3.2.0
3.2.0rc1
3.2.0rc1.post1
3.2.0rc2
3.20.0
3.20.0rc1
3.20.0rc2
3.20.1
3.20.1rc1
3.20.2
3.20.3
3.3.0
3.4.0
3.5.0.post1
3.5.1
3.5.2
3.5.2.post1
3.6.0
3.6.1
3.7.0
3.7.0rc2
3.7.0rc3
3.7.1
3.8.0
3.8.0rc1
3.9.0
3.9.0rc1
3.9.1
3.9.2
4.0.0rc1
4.0.0rc2
4.21.0
4.21.0rc1
4.21.0rc2
4.21.1
4.21.10
4.21.11
4.21.12
4.21.2
4.21.3
4.21.4
4.21.5
4.21.6
4.21.7
4.21.8
4.21.9
4.22.0
4.22.0rc1
4.22.0rc2
4.22.0rc3
4.22.1
4.22.3
4.22.4
4.22.5
4.23.0
4.23.0rc2
4.23.0rc3
4.23.1
4.23.2
4.23.3
4.23.4
4.24.0
4.24.0rc1
4.24.0rc2
4.24.0rc3
4.24.1
4.24.2
4.24.3
4.24.4
4.25.0
4.25.0rc1
4.25.0rc2
4.25.1
4.25.2
4.25.3
4.25.4
4.25.5
4.25.6
4.25.7
5.26.0
5.26.0rc1
5.26.0rc2
5.26.0rc3
5.26.1
5.27.0
5.27.0rc1
5.27.0rc2
5.27.0rc3
5.27.1
5.27.2
5.27.3
5.27.4
5.27.5
5.28.0
5.28.0rc1
5.28.0rc2
5.28.0rc3
5.28.1
5.28.2
5.28.3
5.29.0
5.29.0rc1
5.29.0rc2
5.29.0rc3
5.29.1
5.29.2
5.29.3
5.29.4
6.30.0
6.30.0rc1
6.30.0rc2
6.30.1
6.30.2
6.31.0
6.31.0rc1
6.31.0rc2
Fixed in
4.25.8
5.29.5
6.31.1
References
Updated Jul 07, 2026 · Source: OSV.dev |
5.29.0rc3
pre
|
|
5.29.0rc2
pre
2 CVEs
CVE-2026-0994
PYSEC-2026-1805
GHSA-7gcm-g887-7qv7
Jul 07, 2026
protobuf affected by a JSON recursion depth bypass
High
Network
Low
None
None
A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages. Due to missing recursion depth accounting inside the internal Any-handling logic, an attacker can supply deeply nested Any structures that bypass the intended recursion limit, eventually exhausting Python’s recursion stack and causing a RecursionError. Affected versions
2.0.0beta
2.0.3
2.3.0
2.4.1
2.5.0
2.6.0
2.6.1
3.0.0
3.0.0a2
3.0.0a3
3.0.0b1
3.0.0b1.post1
+ 193 more Show less
3.0.0b1.post2
3.0.0b2
3.0.0b2.post1
3.0.0b2.post2
3.0.0b3
3.0.0b4
3.1.0
3.1.0.post1
3.10.0
3.10.0rc1
3.11.0
3.11.0rc1
3.11.0rc2
3.11.1
3.11.2
3.11.3
3.12.0
3.12.0rc1
3.12.0rc2
3.12.1
3.12.2
3.12.4
3.13.0
3.13.0rc3
3.14.0
3.14.0rc1
3.14.0rc2
3.14.0rc3
3.15.0
3.15.0rc1
3.15.0rc2
3.15.1
3.15.2
3.15.3
3.15.4
3.15.5
3.15.6
3.15.7
3.15.8
3.16.0
3.16.0rc1
3.16.0rc2
3.17.0
3.17.0rc1
3.17.0rc2
3.17.1
3.17.2
3.17.3
3.18.0
3.18.0rc1
3.18.0rc2
3.18.1
3.18.3
3.19.0
3.19.0rc1
3.19.0rc2
3.19.1
3.19.2
3.19.3
3.19.4
3.19.5
3.19.6
3.2.0
3.2.0rc1
3.2.0rc1.post1
3.2.0rc2
3.20.0
3.20.0rc1
3.20.0rc2
3.20.1
3.20.1rc1
3.20.2
3.20.3
3.3.0
3.4.0
3.5.0.post1
3.5.1
3.5.2
3.5.2.post1
3.6.0
3.6.1
3.7.0
3.7.0rc2
3.7.0rc3
3.7.1
3.8.0
3.8.0rc1
3.9.0
3.9.0rc1
3.9.1
3.9.2
4.0.0rc1
4.0.0rc2
4.21.0
4.21.0rc1
4.21.0rc2
4.21.1
4.21.10
4.21.11
4.21.12
4.21.2
4.21.3
4.21.4
4.21.5
4.21.6
4.21.7
4.21.8
4.21.9
4.22.0
4.22.0rc1
4.22.0rc2
4.22.0rc3
4.22.1
4.22.3
4.22.4
4.22.5
4.23.0
4.23.0rc2
4.23.0rc3
4.23.1
4.23.2
4.23.3
4.23.4
4.24.0
4.24.0rc1
4.24.0rc2
4.24.0rc3
4.24.1
4.24.2
4.24.3
4.24.4
4.25.0
4.25.0rc1
4.25.0rc2
4.25.1
4.25.2
4.25.3
4.25.4
4.25.5
4.25.6
4.25.7
4.25.8
4.25.9
5.26.0
5.26.0rc1
5.26.0rc2
5.26.0rc3
5.26.1
5.27.0
5.27.0rc1
5.27.0rc2
5.27.0rc3
5.27.1
5.27.2
5.27.3
5.27.4
5.27.5
5.28.0
5.28.0rc1
5.28.0rc2
5.28.0rc3
5.28.1
5.28.2
5.28.3
5.29.0
5.29.0rc1
5.29.0rc2
5.29.0rc3
5.29.1
5.29.2
5.29.3
5.29.4
5.29.5
6.30.0
6.30.0rc1
6.30.0rc2
6.30.1
6.30.2
6.31.0
6.31.0rc1
6.31.0rc2
6.31.1
6.32.0
6.32.0rc1
6.32.0rc2
6.32.1
6.33.0
6.33.0rc1
6.33.0rc2
6.33.1
6.33.2
6.33.3
6.33.4
Fixed in
5.29.6
6.33.5
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-4565
PYSEC-2026-1806
GHSA-8qvm-5x2c-j2w7
Jul 07, 2026
protobuf-python has a potential Denial of Service issue
High
Network
Low
None
None
SummaryAny project that uses Protobuf pure-Python backend to parse untrusted Protocol Buffers data containing an arbitrary number of recursive groups, recursive messages or a series of Reporter: Alexis Challande, Trail of Bits Ecosystem Security Team ecosystem@trailofbits.com Affected versions: This issue only affects the pure-Python implementation of protobuf-python backend. This is the implementation when This is a Python variant of a previous issue affecting protobuf-java. SeverityThis is a potential Denial of Service. Parsing nested protobuf data creates unbounded recursions that can be abused by an attacker. Proof of ConceptFor reproduction details, please refer to the unit tests decoder_test.py and message_test Remediation and MitigationA mitigation is available now. Please update to the latest available versions of the following packages:
Affected versions
2.0.0beta
2.0.3
2.3.0
2.4.1
2.5.0
2.6.0
2.6.1
3.0.0
3.0.0a2
3.0.0a3
3.0.0b1
3.0.0b1.post1
+ 178 more Show less
3.0.0b1.post2
3.0.0b2
3.0.0b2.post1
3.0.0b2.post2
3.0.0b3
3.0.0b4
3.1.0
3.1.0.post1
3.10.0
3.10.0rc1
3.11.0
3.11.0rc1
3.11.0rc2
3.11.1
3.11.2
3.11.3
3.12.0
3.12.0rc1
3.12.0rc2
3.12.1
3.12.2
3.12.4
3.13.0
3.13.0rc3
3.14.0
3.14.0rc1
3.14.0rc2
3.14.0rc3
3.15.0
3.15.0rc1
3.15.0rc2
3.15.1
3.15.2
3.15.3
3.15.4
3.15.5
3.15.6
3.15.7
3.15.8
3.16.0
3.16.0rc1
3.16.0rc2
3.17.0
3.17.0rc1
3.17.0rc2
3.17.1
3.17.2
3.17.3
3.18.0
3.18.0rc1
3.18.0rc2
3.18.1
3.18.3
3.19.0
3.19.0rc1
3.19.0rc2
3.19.1
3.19.2
3.19.3
3.19.4
3.19.5
3.19.6
3.2.0
3.2.0rc1
3.2.0rc1.post1
3.2.0rc2
3.20.0
3.20.0rc1
3.20.0rc2
3.20.1
3.20.1rc1
3.20.2
3.20.3
3.3.0
3.4.0
3.5.0.post1
3.5.1
3.5.2
3.5.2.post1
3.6.0
3.6.1
3.7.0
3.7.0rc2
3.7.0rc3
3.7.1
3.8.0
3.8.0rc1
3.9.0
3.9.0rc1
3.9.1
3.9.2
4.0.0rc1
4.0.0rc2
4.21.0
4.21.0rc1
4.21.0rc2
4.21.1
4.21.10
4.21.11
4.21.12
4.21.2
4.21.3
4.21.4
4.21.5
4.21.6
4.21.7
4.21.8
4.21.9
4.22.0
4.22.0rc1
4.22.0rc2
4.22.0rc3
4.22.1
4.22.3
4.22.4
4.22.5
4.23.0
4.23.0rc2
4.23.0rc3
4.23.1
4.23.2
4.23.3
4.23.4
4.24.0
4.24.0rc1
4.24.0rc2
4.24.0rc3
4.24.1
4.24.2
4.24.3
4.24.4
4.25.0
4.25.0rc1
4.25.0rc2
4.25.1
4.25.2
4.25.3
4.25.4
4.25.5
4.25.6
4.25.7
5.26.0
5.26.0rc1
5.26.0rc2
5.26.0rc3
5.26.1
5.27.0
5.27.0rc1
5.27.0rc2
5.27.0rc3
5.27.1
5.27.2
5.27.3
5.27.4
5.27.5
5.28.0
5.28.0rc1
5.28.0rc2
5.28.0rc3
5.28.1
5.28.2
5.28.3
5.29.0
5.29.0rc1
5.29.0rc2
5.29.0rc3
5.29.1
5.29.2
5.29.3
5.29.4
6.30.0
6.30.0rc1
6.30.0rc2
6.30.1
6.30.2
6.31.0
6.31.0rc1
6.31.0rc2
Fixed in
4.25.8
5.29.5
6.31.1
References
Updated Jul 07, 2026 · Source: OSV.dev |
5.29.0rc2
pre
|
|
5.28.3
patch
2 CVEs
CVE-2026-0994
PYSEC-2026-1805
GHSA-7gcm-g887-7qv7
Jul 07, 2026
protobuf affected by a JSON recursion depth bypass
High
Network
Low
None
None
A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages. Due to missing recursion depth accounting inside the internal Any-handling logic, an attacker can supply deeply nested Any structures that bypass the intended recursion limit, eventually exhausting Python’s recursion stack and causing a RecursionError. Affected versions
2.0.0beta
2.0.3
2.3.0
2.4.1
2.5.0
2.6.0
2.6.1
3.0.0
3.0.0a2
3.0.0a3
3.0.0b1
3.0.0b1.post1
+ 193 more Show less
3.0.0b1.post2
3.0.0b2
3.0.0b2.post1
3.0.0b2.post2
3.0.0b3
3.0.0b4
3.1.0
3.1.0.post1
3.10.0
3.10.0rc1
3.11.0
3.11.0rc1
3.11.0rc2
3.11.1
3.11.2
3.11.3
3.12.0
3.12.0rc1
3.12.0rc2
3.12.1
3.12.2
3.12.4
3.13.0
3.13.0rc3
3.14.0
3.14.0rc1
3.14.0rc2
3.14.0rc3
3.15.0
3.15.0rc1
3.15.0rc2
3.15.1
3.15.2
3.15.3
3.15.4
3.15.5
3.15.6
3.15.7
3.15.8
3.16.0
3.16.0rc1
3.16.0rc2
3.17.0
3.17.0rc1
3.17.0rc2
3.17.1
3.17.2
3.17.3
3.18.0
3.18.0rc1
3.18.0rc2
3.18.1
3.18.3
3.19.0
3.19.0rc1
3.19.0rc2
3.19.1
3.19.2
3.19.3
3.19.4
3.19.5
3.19.6
3.2.0
3.2.0rc1
3.2.0rc1.post1
3.2.0rc2
3.20.0
3.20.0rc1
3.20.0rc2
3.20.1
3.20.1rc1
3.20.2
3.20.3
3.3.0
3.4.0
3.5.0.post1
3.5.1
3.5.2
3.5.2.post1
3.6.0
3.6.1
3.7.0
3.7.0rc2
3.7.0rc3
3.7.1
3.8.0
3.8.0rc1
3.9.0
3.9.0rc1
3.9.1
3.9.2
4.0.0rc1
4.0.0rc2
4.21.0
4.21.0rc1
4.21.0rc2
4.21.1
4.21.10
4.21.11
4.21.12
4.21.2
4.21.3
4.21.4
4.21.5
4.21.6
4.21.7
4.21.8
4.21.9
4.22.0
4.22.0rc1
4.22.0rc2
4.22.0rc3
4.22.1
4.22.3
4.22.4
4.22.5
4.23.0
4.23.0rc2
4.23.0rc3
4.23.1
4.23.2
4.23.3
4.23.4
4.24.0
4.24.0rc1
4.24.0rc2
4.24.0rc3
4.24.1
4.24.2
4.24.3
4.24.4
4.25.0
4.25.0rc1
4.25.0rc2
4.25.1
4.25.2
4.25.3
4.25.4
4.25.5
4.25.6
4.25.7
4.25.8
4.25.9
5.26.0
5.26.0rc1
5.26.0rc2
5.26.0rc3
5.26.1
5.27.0
5.27.0rc1
5.27.0rc2
5.27.0rc3
5.27.1
5.27.2
5.27.3
5.27.4
5.27.5
5.28.0
5.28.0rc1
5.28.0rc2
5.28.0rc3
5.28.1
5.28.2
5.28.3
5.29.0
5.29.0rc1
5.29.0rc2
5.29.0rc3
5.29.1
5.29.2
5.29.3
5.29.4
5.29.5
6.30.0
6.30.0rc1
6.30.0rc2
6.30.1
6.30.2
6.31.0
6.31.0rc1
6.31.0rc2
6.31.1
6.32.0
6.32.0rc1
6.32.0rc2
6.32.1
6.33.0
6.33.0rc1
6.33.0rc2
6.33.1
6.33.2
6.33.3
6.33.4
Fixed in
5.29.6
6.33.5
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-4565
PYSEC-2026-1806
GHSA-8qvm-5x2c-j2w7
Jul 07, 2026
protobuf-python has a potential Denial of Service issue
High
Network
Low
None
None
SummaryAny project that uses Protobuf pure-Python backend to parse untrusted Protocol Buffers data containing an arbitrary number of recursive groups, recursive messages or a series of Reporter: Alexis Challande, Trail of Bits Ecosystem Security Team ecosystem@trailofbits.com Affected versions: This issue only affects the pure-Python implementation of protobuf-python backend. This is the implementation when This is a Python variant of a previous issue affecting protobuf-java. SeverityThis is a potential Denial of Service. Parsing nested protobuf data creates unbounded recursions that can be abused by an attacker. Proof of ConceptFor reproduction details, please refer to the unit tests decoder_test.py and message_test Remediation and MitigationA mitigation is available now. Please update to the latest available versions of the following packages:
Affected versions
2.0.0beta
2.0.3
2.3.0
2.4.1
2.5.0
2.6.0
2.6.1
3.0.0
3.0.0a2
3.0.0a3
3.0.0b1
3.0.0b1.post1
+ 178 more Show less
3.0.0b1.post2
3.0.0b2
3.0.0b2.post1
3.0.0b2.post2
3.0.0b3
3.0.0b4
3.1.0
3.1.0.post1
3.10.0
3.10.0rc1
3.11.0
3.11.0rc1
3.11.0rc2
3.11.1
3.11.2
3.11.3
3.12.0
3.12.0rc1
3.12.0rc2
3.12.1
3.12.2
3.12.4
3.13.0
3.13.0rc3
3.14.0
3.14.0rc1
3.14.0rc2
3.14.0rc3
3.15.0
3.15.0rc1
3.15.0rc2
3.15.1
3.15.2
3.15.3
3.15.4
3.15.5
3.15.6
3.15.7
3.15.8
3.16.0
3.16.0rc1
3.16.0rc2
3.17.0
3.17.0rc1
3.17.0rc2
3.17.1
3.17.2
3.17.3
3.18.0
3.18.0rc1
3.18.0rc2
3.18.1
3.18.3
3.19.0
3.19.0rc1
3.19.0rc2
3.19.1
3.19.2
3.19.3
3.19.4
3.19.5
3.19.6
3.2.0
3.2.0rc1
3.2.0rc1.post1
3.2.0rc2
3.20.0
3.20.0rc1
3.20.0rc2
3.20.1
3.20.1rc1
3.20.2
3.20.3
3.3.0
3.4.0
3.5.0.post1
3.5.1
3.5.2
3.5.2.post1
3.6.0
3.6.1
3.7.0
3.7.0rc2
3.7.0rc3
3.7.1
3.8.0
3.8.0rc1
3.9.0
3.9.0rc1
3.9.1
3.9.2
4.0.0rc1
4.0.0rc2
4.21.0
4.21.0rc1
4.21.0rc2
4.21.1
4.21.10
4.21.11
4.21.12
4.21.2
4.21.3
4.21.4
4.21.5
4.21.6
4.21.7
4.21.8
4.21.9
4.22.0
4.22.0rc1
4.22.0rc2
4.22.0rc3
4.22.1
4.22.3
4.22.4
4.22.5
4.23.0
4.23.0rc2
4.23.0rc3
4.23.1
4.23.2
4.23.3
4.23.4
4.24.0
4.24.0rc1
4.24.0rc2
4.24.0rc3
4.24.1
4.24.2
4.24.3
4.24.4
4.25.0
4.25.0rc1
4.25.0rc2
4.25.1
4.25.2
4.25.3
4.25.4
4.25.5
4.25.6
4.25.7
5.26.0
5.26.0rc1
5.26.0rc2
5.26.0rc3
5.26.1
5.27.0
5.27.0rc1
5.27.0rc2
5.27.0rc3
5.27.1
5.27.2
5.27.3
5.27.4
5.27.5
5.28.0
5.28.0rc1
5.28.0rc2
5.28.0rc3
5.28.1
5.28.2
5.28.3
5.29.0
5.29.0rc1
5.29.0rc2
5.29.0rc3
5.29.1
5.29.2
5.29.3
5.29.4
6.30.0
6.30.0rc1
6.30.0rc2
6.30.1
6.30.2
6.31.0
6.31.0rc1
6.31.0rc2
Fixed in
4.25.8
5.29.5
6.31.1
References
Updated Jul 07, 2026 · Source: OSV.dev |
5.28.3
patch
|
|
5.29.0rc1
pre
2 CVEs
CVE-2026-0994
PYSEC-2026-1805
GHSA-7gcm-g887-7qv7
Jul 07, 2026
protobuf affected by a JSON recursion depth bypass
High
Network
Low
None
None
A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages. Due to missing recursion depth accounting inside the internal Any-handling logic, an attacker can supply deeply nested Any structures that bypass the intended recursion limit, eventually exhausting Python’s recursion stack and causing a RecursionError. Affected versions
2.0.0beta
2.0.3
2.3.0
2.4.1
2.5.0
2.6.0
2.6.1
3.0.0
3.0.0a2
3.0.0a3
3.0.0b1
3.0.0b1.post1
+ 193 more Show less
3.0.0b1.post2
3.0.0b2
3.0.0b2.post1
3.0.0b2.post2
3.0.0b3
3.0.0b4
3.1.0
3.1.0.post1
3.10.0
3.10.0rc1
3.11.0
3.11.0rc1
3.11.0rc2
3.11.1
3.11.2
3.11.3
3.12.0
3.12.0rc1
3.12.0rc2
3.12.1
3.12.2
3.12.4
3.13.0
3.13.0rc3
3.14.0
3.14.0rc1
3.14.0rc2
3.14.0rc3
3.15.0
3.15.0rc1
3.15.0rc2
3.15.1
3.15.2
3.15.3
3.15.4
3.15.5
3.15.6
3.15.7
3.15.8
3.16.0
3.16.0rc1
3.16.0rc2
3.17.0
3.17.0rc1
3.17.0rc2
3.17.1
3.17.2
3.17.3
3.18.0
3.18.0rc1
3.18.0rc2
3.18.1
3.18.3
3.19.0
3.19.0rc1
3.19.0rc2
3.19.1
3.19.2
3.19.3
3.19.4
3.19.5
3.19.6
3.2.0
3.2.0rc1
3.2.0rc1.post1
3.2.0rc2
3.20.0
3.20.0rc1
3.20.0rc2
3.20.1
3.20.1rc1
3.20.2
3.20.3
3.3.0
3.4.0
3.5.0.post1
3.5.1
3.5.2
3.5.2.post1
3.6.0
3.6.1
3.7.0
3.7.0rc2
3.7.0rc3
3.7.1
3.8.0
3.8.0rc1
3.9.0
3.9.0rc1
3.9.1
3.9.2
4.0.0rc1
4.0.0rc2
4.21.0
4.21.0rc1
4.21.0rc2
4.21.1
4.21.10
4.21.11
4.21.12
4.21.2
4.21.3
4.21.4
4.21.5
4.21.6
4.21.7
4.21.8
4.21.9
4.22.0
4.22.0rc1
4.22.0rc2
4.22.0rc3
4.22.1
4.22.3
4.22.4
4.22.5
4.23.0
4.23.0rc2
4.23.0rc3
4.23.1
4.23.2
4.23.3
4.23.4
4.24.0
4.24.0rc1
4.24.0rc2
4.24.0rc3
4.24.1
4.24.2
4.24.3
4.24.4
4.25.0
4.25.0rc1
4.25.0rc2
4.25.1
4.25.2
4.25.3
4.25.4
4.25.5
4.25.6
4.25.7
4.25.8
4.25.9
5.26.0
5.26.0rc1
5.26.0rc2
5.26.0rc3
5.26.1
5.27.0
5.27.0rc1
5.27.0rc2
5.27.0rc3
5.27.1
5.27.2
5.27.3
5.27.4
5.27.5
5.28.0
5.28.0rc1
5.28.0rc2
5.28.0rc3
5.28.1
5.28.2
5.28.3
5.29.0
5.29.0rc1
5.29.0rc2
5.29.0rc3
5.29.1
5.29.2
5.29.3
5.29.4
5.29.5
6.30.0
6.30.0rc1
6.30.0rc2
6.30.1
6.30.2
6.31.0
6.31.0rc1
6.31.0rc2
6.31.1
6.32.0
6.32.0rc1
6.32.0rc2
6.32.1
6.33.0
6.33.0rc1
6.33.0rc2
6.33.1
6.33.2
6.33.3
6.33.4
Fixed in
5.29.6
6.33.5
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-4565
PYSEC-2026-1806
GHSA-8qvm-5x2c-j2w7
Jul 07, 2026
protobuf-python has a potential Denial of Service issue
High
Network
Low
None
None
SummaryAny project that uses Protobuf pure-Python backend to parse untrusted Protocol Buffers data containing an arbitrary number of recursive groups, recursive messages or a series of Reporter: Alexis Challande, Trail of Bits Ecosystem Security Team ecosystem@trailofbits.com Affected versions: This issue only affects the pure-Python implementation of protobuf-python backend. This is the implementation when This is a Python variant of a previous issue affecting protobuf-java. SeverityThis is a potential Denial of Service. Parsing nested protobuf data creates unbounded recursions that can be abused by an attacker. Proof of ConceptFor reproduction details, please refer to the unit tests decoder_test.py and message_test Remediation and MitigationA mitigation is available now. Please update to the latest available versions of the following packages:
Affected versions
2.0.0beta
2.0.3
2.3.0
2.4.1
2.5.0
2.6.0
2.6.1
3.0.0
3.0.0a2
3.0.0a3
3.0.0b1
3.0.0b1.post1
+ 178 more Show less
3.0.0b1.post2
3.0.0b2
3.0.0b2.post1
3.0.0b2.post2
3.0.0b3
3.0.0b4
3.1.0
3.1.0.post1
3.10.0
3.10.0rc1
3.11.0
3.11.0rc1
3.11.0rc2
3.11.1
3.11.2
3.11.3
3.12.0
3.12.0rc1
3.12.0rc2
3.12.1
3.12.2
3.12.4
3.13.0
3.13.0rc3
3.14.0
3.14.0rc1
3.14.0rc2
3.14.0rc3
3.15.0
3.15.0rc1
3.15.0rc2
3.15.1
3.15.2
3.15.3
3.15.4
3.15.5
3.15.6
3.15.7
3.15.8
3.16.0
3.16.0rc1
3.16.0rc2
3.17.0
3.17.0rc1
3.17.0rc2
3.17.1
3.17.2
3.17.3
3.18.0
3.18.0rc1
3.18.0rc2
3.18.1
3.18.3
3.19.0
3.19.0rc1
3.19.0rc2
3.19.1
3.19.2
3.19.3
3.19.4
3.19.5
3.19.6
3.2.0
3.2.0rc1
3.2.0rc1.post1
3.2.0rc2
3.20.0
3.20.0rc1
3.20.0rc2
3.20.1
3.20.1rc1
3.20.2
3.20.3
3.3.0
3.4.0
3.5.0.post1
3.5.1
3.5.2
3.5.2.post1
3.6.0
3.6.1
3.7.0
3.7.0rc2
3.7.0rc3
3.7.1
3.8.0
3.8.0rc1
3.9.0
3.9.0rc1
3.9.1
3.9.2
4.0.0rc1
4.0.0rc2
4.21.0
4.21.0rc1
4.21.0rc2
4.21.1
4.21.10
4.21.11
4.21.12
4.21.2
4.21.3
4.21.4
4.21.5
4.21.6
4.21.7
4.21.8
4.21.9
4.22.0
4.22.0rc1
4.22.0rc2
4.22.0rc3
4.22.1
4.22.3
4.22.4
4.22.5
4.23.0
4.23.0rc2
4.23.0rc3
4.23.1
4.23.2
4.23.3
4.23.4
4.24.0
4.24.0rc1
4.24.0rc2
4.24.0rc3
4.24.1
4.24.2
4.24.3
4.24.4
4.25.0
4.25.0rc1
4.25.0rc2
4.25.1
4.25.2
4.25.3
4.25.4
4.25.5
4.25.6
4.25.7
5.26.0
5.26.0rc1
5.26.0rc2
5.26.0rc3
5.26.1
5.27.0
5.27.0rc1
5.27.0rc2
5.27.0rc3
5.27.1
5.27.2
5.27.3
5.27.4
5.27.5
5.28.0
5.28.0rc1
5.28.0rc2
5.28.0rc3
5.28.1
5.28.2
5.28.3
5.29.0
5.29.0rc1
5.29.0rc2
5.29.0rc3
5.29.1
5.29.2
5.29.3
5.29.4
6.30.0
6.30.0rc1
6.30.0rc2
6.30.1
6.30.2
6.31.0
6.31.0rc1
6.31.0rc2
Fixed in
4.25.8
5.29.5
6.31.1
References
Updated Jul 07, 2026 · Source: OSV.dev |
5.29.0rc1
pre
|