Threat reportVulnerabilityTL-2026-1039
CVE-2026-55407: Unbounded Heap Allocation DoS in Anthropic's Buffa Rust Protobuf Library (decode_unknown_field)
CVE-2026-55407 (TL-2026-1039), also tracked as GHSA-f9qc-qg88-7pq5, is a moderate-severity software vulnerability scored CVSS 6.3, first published 2026-07-01. It has no confirmed attribution, affects Anthropic buffa, references 1 CVE (CVE-2026-55407), maps to 10 MITRE ATT&CK techniques (T1046, T1190, T1499), and is covered by 9 detection rules and 16 indicators of compromise.
- CVSS
- 6.3/10Moderate
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 10MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 16Indicators of compromise
Key facts for TL-2026-1039
- Threat ID
- TL-2026-1039
- Also known as
- GHSA-f9qc-qg88-7pq5
- Severity
- MODERATE
- CVSS
- 6.3 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N)
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- UNKNOWN
- Target sectors
- technology, software-development, cloud-services
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 16
Malware and tooling in CVE-2026-55407
Malware and tooling: Endor Labs AI SAST engine
How CVE-2026-55407 works
Buffa, Anthropic's Rust protobuf implementation (and the related connectrpc library), contained an unbounded heap-allocation flaw in decode_unknown_field's handling of WireType::StartGroup, allowing a crafted 64 MiB payload of nested minimal varint fields to force ~1.4 GB of heap allocation (~22x amplification) and trigger an OOM crash. Discovered by Endor Labs' AI SAST engine and disclosed via Anthropic's bug bounty program; patched in buffa/connectrpc 0.8.0.
CVE-2026-55407 (GHSA-f9qc-qg88-7pq5) is an uncontrolled resource consumption vulnerability in decode_unknown_field, located in buffa/src/encoding.rs, reachable through the default public decode APIs Message::decode, Message::decode_from_slice, and MessageView::decode_view whenever generated code retains unknown fields (preserve_unknown_fields=true, the default).
Two distinct amplification vectors exist in the same function. The first, a flat WireType::LengthDelimited path (encoding.rs lines ~490-499), allocates a Vec<u8> sized directly from an attacker-controlled varint length prefix; a `buf.remaining()` check prevents out-of-bounds reads but places no independent cap on the size of the allocation itself, yielding roughly 2x amplification relative to wire size. The second and more severe vector abuses WireType::StartGroup (encoding.rs lines ~500-520): the decoder loops over nested fields until an EndGroup marker, pushing one UnknownField struct (~40 bytes on 64-bit targets) per iteration. Because a minimal field can be encoded in just 2 wire bytes (a 1-byte tag plus a 1-byte zero varint), an attacker can pack roughly 33.5 million such fields into a single group inside a 64 MiB message, producing about 1.41 GB of live heap - approximately 22x amplification. Recursion depth is bounded, but there is no limit on the number of fields processed per group or per message.
Endor Labs demonstrated the exploit with a wire payload of `0x0b` (StartGroup, field 1) followed by repeated `[0x08, 0x00]` two-byte varint pairs and a closing `0x0c` (EndGroup), decoded against the zero-field `google.protobuf.Empty` message type (exploitable purely via forward-compatible unknown-field retention, with no declared fields required). In a Docker container capped at 256 MiB, the 64 MiB payload reliably produced an OOM-kill (process exit code 137). Buffa's DecodeOptions::DEFAULT_MAX_MESSAGE_SIZE (~2 GiB) bounds the incoming wire size but does not constrain in-memory expansion from group-based unknown-field amplification.
The flaw was found by Endor Labs' AI-assisted static analysis (SAST) engine through data-flow tracing of attacker-controlled wire values into unbounded allocation sinks - a class of bug traditionally hard to automate against memory-safe languages that lack classic unsafe-pointer primitives. It was reported to Anthropic through its bug bounty program, validated by Anthropic, and resolved collaboratively; Anthropic paid a $600 bounty. Buffa and connectrpc 0.8.0 fix the issue by enforcing a configurable per-message limit on the number of retained unknown fields (default: 1,000,000 fields), capping worst-case unknown-field overhead at roughly 40 MB per message. Consumers who do not need unknown-field preservation can also mitigate by regenerating code with preserve_unknown_fields=false, which removes the vulnerable retention path entirely.
No in-the-wild exploitation has been reported; this was a coordinated, pre-emptive disclosure. Real-world severity is deployment dependent: services running multiple replicas behind supervision/auto-restart see graceful, low-impact degradation, while single-instance or unsupervised deployments - and high-concurrency gRPC services accepting the common 4 MiB default message-size limit - face a repeatable, unauthenticated crash-loop DoS with low attacker cost (small payload, no authentication required).
MITRE ATT&CK techniques used in TL-2026-1039
Discovery
T1046 Network Service Discovery; T1518 Software Discovery
Initial Access
T1190 Exploit Public-Facing Application
Impact
T1499 Endpoint Denial of Service
Resource Development
T1587 Develop Capabilities; T1588 Obtain Capabilities
Reconnaissance
T1592 Gather Victim Host Information; T1594 Search Victim-Owned Websites; T1595 Active Scanning; T1596 Search Open Technical Databases
Affected products and versions in CVE-2026-55407
- Anthropic — buffa
Vulnerable versions: < 0.8.0
Fixed in: 0.8.0 - Anthropic — connectrpc
Vulnerable versions: < 0.8.0
Fixed in: 0.8.0
Remediation for CVE-2026-55407
Patches
- buffa 0.8.0 - configurable per-message unknown-field count limit (default 1,000,000 fields)
- connectrpc 0.8.0 - inherits the buffa fix
Immediate actions
- Upgrade buffa and connectrpc to version 0.8.0 or later
- If upgrading is not immediately possible, regenerate protobuf code with preserve_unknown_fields=false to eliminate the unknown-field retention path
- Apply strict message-size limits (well below the library default of ~2 GiB) at the transport/gRPC layer for any service decoding untrusted protobuf input
- Run decoders in memory-cgroup-limited containers with automatic restart/supervision to bound the blast radius of any single OOM event
Workarounds
- Regenerate protobuf bindings with preserve_unknown_fields=false
- Enforce a small, application-appropriate max message size ahead of the default limit
- Rate-limit and authenticate inbound gRPC/protobuf endpoints where feasible to reduce anonymous DoS exposure
Longer-term hardening
- Deploy multiple replicas with health checks and auto-recovery for any service that parses untrusted protobuf/gRPC traffic
- Add fuzzing/resource-exhaustion test coverage for protobuf decoders as part of CI, including nested-group and length-prefix amplification cases
- Track and pin dependency versions for buffa/connectrpc via Cargo.lock and enable automated advisory scanning (cargo-audit / cargo-deny) in CI
CVEs associated with CVE-2026-55407
Weaknesses (CWE) in CVE-2026-55407
Timeline of CVE-2026-55407
- buffa v0.8.0 published on GitHub Releases, bundling the unknown-field allocation-limit fix alongside unrelated feature work (pluggable owned types, lazy view decoding, UTF-8 validation).
- Endor Labs published a technical writeup detailing the exploit chain, PoC construction, and Docker-based OOM-kill reproduction.
- CVE-2026-55407 / GHSA-f9qc-qg88-7pq5 assigned and bounty of $600 paid to the reporting researchers.
- Fix shipped in buffa and connectrpc version 0.8.0, adding a configurable per-message unknown-field count limit (default 1,000,000 fields).
- Anthropic validated both the flat LengthDelimited and StartGroup-nested amplification vectors and collaborated on CVSS 4.0 scoring given deployment-dependent severity.
- Vulnerability reported to Anthropic through its bug bounty program after being surfaced by Endor Labs' AI SAST engine via data-flow analysis of buffa's decode_unknown_field.
- Cyberpress published a secondary technical summary of the vulnerability and patch.
- Cyber Security News published coverage of the disclosure, first surfacing it to the harness's monitored feeds.
Sources cited for CVE-2026-55407
- Anthropic's Buffa Rust Library 0-Day Vulnerability Enables DoS Attack
- Endor Labs' AI SAST Finds Zero Day Memory-Amplification DoS in Anthropic's buffa library
- Anthropic buffa Library Hit by Zero-Day DoS Flaw in Rust Protobuf Decoder
- GHSA-f9qc-qg88-7pq5
- anthropics/buffa - Rust implementation of protobuf
- buffa Releases (v0.8.0)
Detection coverage for TL-2026-1039
As of 2026-07-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1039 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.