CVE-2025-53605
published 2025-07-05CVE-2025-53605: The protobuf crate before 3.7.2 for Rust allows uncontrolled recursion in the protobuf::coded_input_stream::CodedInputStream::skip_group parsing of unknown…
PriorityP427medium5.9CVSS 3.1
AVNACHPRNUINSUCNINAH
EPSS
0.38%
30.1th percentile
The protobuf crate before 3.7.2 for Rust allows uncontrolled recursion in the protobuf::coded_input_stream::CodedInputStream::skip_group parsing of unknown fields in untrusted input.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | rust-protobuf | < rust-protobuf 3.7.2-1 (forky) | rust-protobuf 3.7.2-1 (forky) |
| protobuf | >= 0 < 3.7.2 | 3.7.2 | |
| protobuf | >= 0.0.0-0 < 3.7.2 | 3.7.2 | |
| msrc | azl3_kata-containers-cc_3.15.0.aks0-4_on_azure_linux_3.0 | — | — |
| msrc | azl3_kata-containers-cc_3.15.0.aks0-5_on_azure_linux_3.0 | — | — |
| msrc | azl3_kata-containers-cc_3.15.0.aks0-6_on_azure_linux_3.0 | — | — |
| msrc | azl3_kata-containers_3.18.0.kata0-3_on_azure_linux_3.0 | — | — |
| msrc | azl3_rust_1.75.0-17_on_azure_linux_3.0 | — | — |
| msrc | azl3_rust_1.86.0-4_on_azure_linux_3.0 | — | — |
| msrc | cbl2_kata-containers-cc_3.2.0.azl2-7_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_kata-containers-cc_3.2.0.azl2-8_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_kata-containers_3.2.0.azl2-6_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_kata-containers_3.2.0.azl2-7_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_rust_1.72.0-10_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_rust_1.72.0-11_on_cbl_mariner_2.0 | — | — |
| stepancheg | protobuf | < 3.7.2 | 3.7.2 |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_msrc5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2025-53605: The protobuf crate before 3
osv·2025-07-05·CVSS 5.9
CVE-2025-53605 [MEDIUM] CVE-2025-53605: The protobuf crate before 3
The protobuf crate before 3.7.2 for Rust allows uncontrolled recursion in the protobuf::coded_input_stream::CodedInputStream::skip_group parsing of unknown fields in untrusted input.
GHSA
Crash due to uncontrolled recursion in protobuf crate
ghsa·2025-03-07
CVE-2025-53605 [MEDIUM] CWE-20 Crash due to uncontrolled recursion in protobuf crate
Crash due to uncontrolled recursion in protobuf crate
Affected version of this crate did not properly parse unknown fields when parsing a user-supplied input.
This allows an attacker to cause a stack overflow when parsing the message on untrusted data.
OSV
Crash due to uncontrolled recursion in protobuf crate
osv·2025-03-07
CVE-2025-53605 [MEDIUM] Crash due to uncontrolled recursion in protobuf crate
Crash due to uncontrolled recursion in protobuf crate
Affected version of this crate did not properly parse unknown fields when parsing a user-supplied input.
This allows an attacker to cause a stack overflow when parsing the message on untrusted data.
OSV
Crash due to uncontrolled recursion in protobuf crate
osv·2024-12-12
CVE-2025-53605 Crash due to uncontrolled recursion in protobuf crate
Crash due to uncontrolled recursion in protobuf crate
Affected version of this crate did not properly parse unknown fields when parsing a user-supplied input.
This allows an attacker to cause a stack overflow when parsing the mssage on untrusted data.
Microsoft
The protobuf crate before 3.7.2 for Rust allows uncontrolled recursion in the protobuf::coded_input_stream::CodedInputStream::skip_group parsing of unknown fields in untrusted input.
vendor_msrc·2025-07-08·CVSS 5.9
CVE-2025-53605 [MEDIUM] CWE-674 The protobuf crate before 3.7.2 for Rust allows uncontrolled recursion in the protobuf::coded_input_stream::CodedInputStream::skip_group parsing of unknown fields in untrusted input.
The protobuf crate before 3.7.2 for Rust allows uncontrolled recursion in the protobuf::coded_input_stream::CodedInputStream::skip_group parsing of unknown fields in untrusted input.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect th
Red Hat
protobuf: Protobuf: Uncontrolled Recursion Vulnerability
vendor_redhat·2025-07-05·CVSS 5.9
CVE-2025-53605 [MEDIUM] CWE-674 protobuf: Protobuf: Uncontrolled Recursion Vulnerability
protobuf: Protobuf: Uncontrolled Recursion Vulnerability
The protobuf crate before 3.7.2 for Rust allows uncontrolled recursion in the protobuf::coded_input_stream::CodedInputStream::skip_group parsing of unknown fields in untrusted input.
A flaw was found in protobuf. The protobuf::coded_input_stream::CodedInputStream::skip_group function exhibits uncontrolled recursion when parsing unknown fields from untrusted input, potentially leading to excessive resource consumption. This flaw allows a network attacker to trigger this condition by providing a maliciously crafted Protocol Buffer (protobuf) file. This issue can result in an application-level denial of service due to resource exhaustion.
Mitigation: Mitigation for this issue is either not available or the currently available options
Debian
CVE-2025-53605: rust-protobuf - The protobuf crate before 3.7.2 for Rust allows uncontrolled recursion in the pr...
vendor_debian·2025·CVSS 5.9
CVE-2025-53605 [MEDIUM] CVE-2025-53605: rust-protobuf - The protobuf crate before 3.7.2 for Rust allows uncontrolled recursion in the pr...
The protobuf crate before 3.7.2 for Rust allows uncontrolled recursion in the protobuf::coded_input_stream::CodedInputStream::skip_group parsing of unknown fields in untrusted input.
Scope: local
bookworm: open
forky: resolved (fixed in 3.7.2-1)
sid: resolved (fixed in 3.7.2-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-07-05
Published