PT-2025-25564 · Protobuf+6 · Protobuf+6
CVE-2025-4565
·
Publicado
2025-05-14
·
Atualizado
2026-07-09
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Protobuf versions prior to 6.31.1
Description
The issue affects projects that use the Protobuf Pure-Python backend to parse untrusted Protocol Buffers data. This data can contain an arbitrary number of recursive groups, recursive messages, or a series of SGROUP tags, which can cause the application to exceed the Python recursion limit. As a result, this can lead to a Denial of Service by crashing the application with a RecursionError.
Recommendations
For versions prior to 6.31.1, upgrade to version 6.31.1 or beyond commit 17838beda2943d08b8a9d4df5b68f5f04f26d901 to resolve the issue.
Exploit
Correção
DoS
Uncontrolled Recursion
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Astra Linux
Debian
Linuxmint
Protobuf
Red Os
Suse
Ubuntu