Skip to content
This repository was archived by the owner on Feb 12, 2026. It is now read-only.

[Aikido] Fix security issue in protobuf via minor version upgrade from 6.33.4 to 6.33.5 in community#4

Open
aikido-autofix[bot] wants to merge 1 commit intomainfrom
fix/aikido-security-update-packages-15204927-oZJX
Open

[Aikido] Fix security issue in protobuf via minor version upgrade from 6.33.4 to 6.33.5 in community#4
aikido-autofix[bot] wants to merge 1 commit intomainfrom
fix/aikido-security-update-packages-15204927-oZJX

Conversation

@aikido-autofix
Copy link
Copy Markdown

@aikido-autofix aikido-autofix bot commented Feb 1, 2026

Upgrade protobuf to mitigate critical DoS vulnerability in JSON parsing that allows bypassing recursion depth limits and potential stack exhaustion.

✅ 1 CVE resolved by this upgrade

This PR will resolve the following CVEs:

Issue Severity           Description
CVE-2026-0994
HIGH
Protobuf JSON parsing vulnerability allows bypassing recursion depth limits via nested Any messages, potentially causing a Python RecursionError and enabling a denial-of-service attack by exhausting the recursion stack.

@coderabbitai
Copy link
Copy Markdown

coderabbitai bot commented Feb 1, 2026

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

  • 🔍 Trigger a full review

Comment @coderabbitai help to get the list of available commands and usage tips.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants