MEDIUM
GHSA-2gh3-rmm4-6rq5
Crash due to uncontrolled recursion in protobuf crate
Details
Affected version of this crate did not properly parse unknown fields when parsing a user-supplied input.
This allows an attacker to cause a stack overflow when parsing the message on untrusted data.
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/protobuf
Introduced in:
0Fixed in: 3.7.2Upgrade protobuf to 3.7.2 or newer (ecosystem crates.io).
References
- https://nvd.nist.gov/vuln/detail/CVE-2025-53605[ADVISORY]
- https://github.com/stepancheg/rust-protobuf/issues/749[WEB]
- https://github.com/stepancheg/rust-protobuf/commit/f06992f46771c0a092593b9ebf7afd48740b3ed6[WEB]
- https://github.com/stepancheg/rust-protobuf[PACKAGE]
- https://rustsec.org/advisories/RUSTSEC-2024-0437.html[WEB]