CVE-2025-4565
16.06.2025, 15:15
Any project that uses Protobuf Pure-Python backendto parse untrusted Protocol Buffers data containing an arbitrary number of recursive groups, recursive messages or a series of SGROUPtags can be corrupted by exceeding the Python recursion limit. This can result in a Denial of service by crashing the application with a RecursionError. We recommend upgrading to version =>6.31.1 or beyond commit17838beda2943d08b8a9d4df5b68f5f04f26d901Enginsight
Vendor | Product | Version |
---|---|---|
protobuf-python | 𝑥 < 4.25.8 | |
protobuf-python | 5.26.0 ≤ 𝑥 < 5.29.5 | |
protobuf-python | 6.30.0 ≤ 𝑥 < 6.31.1 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Ubuntu Product | |||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
protobuf |
|
Common Weakness Enumeration