PatchSiren

elixir-protobuf CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH elixir-protobuf CVE published 2026-09-17

CVE-2026-54451

CVE-2026-54451 is a high-severity vulnerability in Elixir protobuf, a pure Elixir implementation of Google Protobuf. The issue allows services that decode attacker-controlled protobuf bytes with Protobuf.Decoder to be taken offline when the schema contains a self-referential or cyclic message type. This can lead to substantial CPU and memory consumption, potentially pinning a BEAM scheduler and exhausting [truncated]