CVE-2025-4565
16.06.2025, 15:15
Any project that uses Protobuf Pure-Python backendto parse untrusted Protocol Buffers data containing an arbitrary number of recursive groups, recursive messages or a series of SGROUPtags can be corrupted by exceeding the Python recursion limit. This can result in a Denial of service by crashing the application with a RecursionError. We recommend upgrading to version =>6.31.1 or beyond commit17838beda2943d08b8a9d4df5b68f5f04f26d901Enginsight
| Vendor | Product | Version |
|---|---|---|
| protobuf-python | 𝑥 < 4.25.8 | |
| protobuf-python | 5.26.0 ≤ 𝑥 < 5.29.5 | |
| protobuf-python | 6.30.0 ≤ 𝑥 < 6.31.1 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Ubuntu Product | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| protobuf |
|
Common Weakness Enumeration