Skip to content

[Aikido] Fix security issue in protobuf via minor version upgrade from 6.33.4 to 6.33.5#1

Open
aikido-autofix[bot] wants to merge 1 commit intomainfrom
fix/aikido-security-AIKIDO-718-AIKIDO-1426-update-packages-15077062-78pU
Open

[Aikido] Fix security issue in protobuf via minor version upgrade from 6.33.4 to 6.33.5#1
aikido-autofix[bot] wants to merge 1 commit intomainfrom
fix/aikido-security-AIKIDO-718-AIKIDO-1426-update-packages-15077062-78pU

Conversation

@aikido-autofix
Copy link

Upgrade protobuf to mitigate critical DoS vulnerability in JSON parsing that allows bypassing recursion depth limits and potential stack exhaustion.

✅ 1 CVE resolved by this upgrade

This PR will resolve the following CVEs:

Issue Severity           Description
CVE-2026-0994
HIGH
Protobuf JSON parsing vulnerability allows bypassing recursion depth limits via nested Any messages, potentially causing a Python RecursionError and enabling a denial-of-service attack by exhausting the recursion stack.
🔗 Related Tasks

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants