Threat reportVulnerabilityTL-2026-1039

CVE-2026-55407: Unbounded Heap Allocation DoS in Anthropic's Buffa Rust Protobuf Library (decode_unknown_field)

PATCHED

CVE-2026-55407 (TL-2026-1039), also tracked as GHSA-f9qc-qg88-7pq5, is a moderate-severity software vulnerability scored CVSS 6.3, first published 2026-07-01. It has no confirmed attribution, affects Anthropic buffa, references 1 CVE (CVE-2026-55407), maps to 10 MITRE ATT&CK techniques (T1046, T1190, T1499), and is covered by 9 detection rules and 16 indicators of compromise.

CVSS
6.3/10Moderate
CVEs
1Referenced vulnerabilities
Techniques
10MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
16Indicators of compromise

Key facts for TL-2026-1039

Threat ID
TL-2026-1039
Also known as
GHSA-f9qc-qg88-7pq5
Severity
MODERATE
CVSS
6.3 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N)
Status
PATCHED
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
NONE
Motivation
UNKNOWN
Target sectors
technology, software-development, cloud-services
Target regions
Global
Detection rules
9
Indicators of compromise
16

Malware and tooling in CVE-2026-55407

Malware and tooling: Endor Labs AI SAST engine

How CVE-2026-55407 works

Buffa, Anthropic's Rust protobuf implementation (and the related connectrpc library), contained an unbounded heap-allocation flaw in decode_unknown_field's handling of WireType::StartGroup, allowing a crafted 64 MiB payload of nested minimal varint fields to force ~1.4 GB of heap allocation (~22x amplification) and trigger an OOM crash. Discovered by Endor Labs' AI SAST engine and disclosed via Anthropic's bug bounty program; patched in buffa/connectrpc 0.8.0.

CVE-2026-55407 (GHSA-f9qc-qg88-7pq5) is an uncontrolled resource consumption vulnerability in decode_unknown_field, located in buffa/src/encoding.rs, reachable through the default public decode APIs Message::decode, Message::decode_from_slice, and MessageView::decode_view whenever generated code retains unknown fields (preserve_unknown_fields=true, the default).

Two distinct amplification vectors exist in the same function. The first, a flat WireType::LengthDelimited path (encoding.rs lines ~490-499), allocates a Vec<u8> sized directly from an attacker-controlled varint length prefix; a `buf.remaining()` check prevents out-of-bounds reads but places no independent cap on the size of the allocation itself, yielding roughly 2x amplification relative to wire size. The second and more severe vector abuses WireType::StartGroup (encoding.rs lines ~500-520): the decoder loops over nested fields until an EndGroup marker, pushing one UnknownField struct (~40 bytes on 64-bit targets) per iteration. Because a minimal field can be encoded in just 2 wire bytes (a 1-byte tag plus a 1-byte zero varint), an attacker can pack roughly 33.5 million such fields into a single group inside a 64 MiB message, producing about 1.41 GB of live heap - approximately 22x amplification. Recursion depth is bounded, but there is no limit on the number of fields processed per group or per message.

Endor Labs demonstrated the exploit with a wire payload of `0x0b` (StartGroup, field 1) followed by repeated `[0x08, 0x00]` two-byte varint pairs and a closing `0x0c` (EndGroup), decoded against the zero-field `google.protobuf.Empty` message type (exploitable purely via forward-compatible unknown-field retention, with no declared fields required). In a Docker container capped at 256 MiB, the 64 MiB payload reliably produced an OOM-kill (process exit code 137). Buffa's DecodeOptions::DEFAULT_MAX_MESSAGE_SIZE (~2 GiB) bounds the incoming wire size but does not constrain in-memory expansion from group-based unknown-field amplification.

The flaw was found by Endor Labs' AI-assisted static analysis (SAST) engine through data-flow tracing of attacker-controlled wire values into unbounded allocation sinks - a class of bug traditionally hard to automate against memory-safe languages that lack classic unsafe-pointer primitives. It was reported to Anthropic through its bug bounty program, validated by Anthropic, and resolved collaboratively; Anthropic paid a $600 bounty. Buffa and connectrpc 0.8.0 fix the issue by enforcing a configurable per-message limit on the number of retained unknown fields (default: 1,000,000 fields), capping worst-case unknown-field overhead at roughly 40 MB per message. Consumers who do not need unknown-field preservation can also mitigate by regenerating code with preserve_unknown_fields=false, which removes the vulnerable retention path entirely.

No in-the-wild exploitation has been reported; this was a coordinated, pre-emptive disclosure. Real-world severity is deployment dependent: services running multiple replicas behind supervision/auto-restart see graceful, low-impact degradation, while single-instance or unsupervised deployments - and high-concurrency gRPC services accepting the common 4 MiB default message-size limit - face a repeatable, unauthenticated crash-loop DoS with low attacker cost (small payload, no authentication required).

MITRE ATT&CK techniques used in TL-2026-1039

Discovery

T1046 Network Service Discovery; T1518 Software Discovery

Initial Access

T1190 Exploit Public-Facing Application

Impact

T1499 Endpoint Denial of Service

Resource Development

T1587 Develop Capabilities; T1588 Obtain Capabilities

Reconnaissance

T1592 Gather Victim Host Information; T1594 Search Victim-Owned Websites; T1595 Active Scanning; T1596 Search Open Technical Databases

Affected products and versions in CVE-2026-55407

  • Anthropic — buffa
    Vulnerable versions: < 0.8.0
    Fixed in: 0.8.0
  • Anthropic — connectrpc
    Vulnerable versions: < 0.8.0
    Fixed in: 0.8.0

Remediation for CVE-2026-55407

Patches

  • buffa 0.8.0 - configurable per-message unknown-field count limit (default 1,000,000 fields)
  • connectrpc 0.8.0 - inherits the buffa fix

Immediate actions

  • Upgrade buffa and connectrpc to version 0.8.0 or later
  • If upgrading is not immediately possible, regenerate protobuf code with preserve_unknown_fields=false to eliminate the unknown-field retention path
  • Apply strict message-size limits (well below the library default of ~2 GiB) at the transport/gRPC layer for any service decoding untrusted protobuf input
  • Run decoders in memory-cgroup-limited containers with automatic restart/supervision to bound the blast radius of any single OOM event

Workarounds

  • Regenerate protobuf bindings with preserve_unknown_fields=false
  • Enforce a small, application-appropriate max message size ahead of the default limit
  • Rate-limit and authenticate inbound gRPC/protobuf endpoints where feasible to reduce anonymous DoS exposure

Longer-term hardening

  • Deploy multiple replicas with health checks and auto-recovery for any service that parses untrusted protobuf/gRPC traffic
  • Add fuzzing/resource-exhaustion test coverage for protobuf decoders as part of CI, including nested-group and length-prefix amplification cases
  • Track and pin dependency versions for buffa/connectrpc via Cargo.lock and enable automated advisory scanning (cargo-audit / cargo-deny) in CI

CVEs associated with CVE-2026-55407

CVE-2026-55407

Weaknesses (CWE) in CVE-2026-55407

CWE-770, CWE-400

Timeline of CVE-2026-55407

  • buffa v0.8.0 published on GitHub Releases, bundling the unknown-field allocation-limit fix alongside unrelated feature work (pluggable owned types, lazy view decoding, UTF-8 validation).
  • Endor Labs published a technical writeup detailing the exploit chain, PoC construction, and Docker-based OOM-kill reproduction.
  • CVE-2026-55407 / GHSA-f9qc-qg88-7pq5 assigned and bounty of $600 paid to the reporting researchers.
  • Fix shipped in buffa and connectrpc version 0.8.0, adding a configurable per-message unknown-field count limit (default 1,000,000 fields).
  • Anthropic validated both the flat LengthDelimited and StartGroup-nested amplification vectors and collaborated on CVSS 4.0 scoring given deployment-dependent severity.
  • Vulnerability reported to Anthropic through its bug bounty program after being surfaced by Endor Labs' AI SAST engine via data-flow analysis of buffa's decode_unknown_field.
  • Cyberpress published a secondary technical summary of the vulnerability and patch.
  • Cyber Security News published coverage of the disclosure, first surfacing it to the harness's monitored feeds.

Sources cited for CVE-2026-55407

Detection coverage for TL-2026-1039

As of 2026-07-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1039 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
16 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats