Endor Labs’ AI SAST Finds Zero Day Memory-Amplification DoS in Anthropic’s buffa library
Blog post from Endor Labs
Endor Labs' AI SAST engine identified a potential denial-of-service vulnerability in Anthropic's Rust protobuf library, buffa, specifically in its handling of unknown-field decoding, which could lead to excessive memory allocation from untrusted input. The vulnerability arises from an unbounded allocation linked to a length-delimited field, which could result in a memory blow-up of approximately 22 times the input size, potentially leading to out-of-memory (OOM) conditions. Despite buffa being a well-reviewed library from a reputable lab, the flaw persisted and was unearthed by AI SAST tracing the data flow without relying on pattern-matching. The issue was quickly addressed by Anthropic, who collaborated effectively with the researcher to understand the severity of the flaw across different deployment scenarios. This vulnerability, tracked as GHSA-f9qc-qg88-7pq5 / CVE-2026-55407, was patched in version 0.8.0 of buffa and connectrpc, offering a per-message unknown-field count limit to mitigate the risk. The incident underscores the importance of comprehensive security analysis tools capable of tracing data flows in identifying vulnerabilities in memory-safe languages like Rust.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.