{
  "@id": "urn:uuid:afa8f208-ddbe-488f-8bb9-22370895ca3f",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 1,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-09-24T09:31:26.931840+00:00",
  "statements": [
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/protobuf@3.17.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/protobuf@3.17.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-4565 affects version 3.17.0.post1+tuxcare of protobuf.",
      "vulnerability": {
        "name": "CVE-2025-4565"
      },
      "action_statement": "Vulnerability CVE-2025-4565 affects version 3.17.0.post1+tuxcare of protobuf."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/protobuf@3.17.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/protobuf@3.17.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-0994 does not affect version 3.17.0.post1+tuxcare of protobuf. protobuf 3.17.0 has no recursion-depth limit to bypass. CVE-2026-0994 is a bypass of json_format's max_recursion_depth: _ConvertAnyMessage dispatched well-known types through methodcaller, skipping ConvertMessage and therefore the depth counter. On 3.17.0 there is no counter and no limit - the strings recursion_depth and max_recursion_depth do not occur anywhere in python/google/protobuf/json_format.py, ConvertMessage is declared (self, value, message) with no path argument, and the entry points expose no such parameter (3.17.0: ParseDict(js_dict, message, ignore_unknown_fields=False, descriptor_pool=None); 4.24.3: the same plus max_recursion_depth=100). Upstream's regression tests for this CVE call ParseDict(..., max_recursion_depth=5) and would raise TypeError here rather than exercise the fix. The guarded feature was introduced by a later upstream change, so the code this CVE concerns is not present. Stated separately so it is not lost: having no limit at all leaves 3.17.0 exposed to the unbounded-recursion issue that the limit was introduced to fix - a different vulnerability, not covered by this assessment.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-0994"
      },
      "impact_statement": "protobuf 3.17.0 has no recursion-depth limit to bypass. CVE-2026-0994 is a bypass of json_format's max_recursion_depth: _ConvertAnyMessage dispatched well-known types through methodcaller, skipping ConvertMessage and therefore the depth counter. On 3.17.0 there is no counter and no limit - the strings recursion_depth and max_recursion_depth do not occur anywhere in python/google/protobuf/json_format.py, ConvertMessage is declared (self, value, message) with no path argument, and the entry points expose no such parameter (3.17.0: ParseDict(js_dict, message, ignore_unknown_fields=False, descriptor_pool=None); 4.24.3: the same plus max_recursion_depth=100). Upstream's regression tests for this CVE call ParseDict(..., max_recursion_depth=5) and would raise TypeError here rather than exercise the fix. The guarded feature was introduced by a later upstream change, so the code this CVE concerns is not present. Stated separately so it is not lost: having no limit at all leaves 3.17.0 exposed to the unbounded-recursion issue that the limit was introduced to fix - a different vulnerability, not covered by this assessment."
    }
  ]
}
