CVE-2025-53605
The protobuf crate before 3.7.2 for Rust allows uncontrolled recursion in the protobuf::coded_input_stream::CodedInputStream::skip_group parsing of unknown fields in untrusted input.
02 / AFFECTED SOFTWARE
Affected packages
19 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
The protobuf crate before 3.7.2 for Rust allows uncontrolled recursion in the protobuf::coded_input_stream::CodedInputStream::skip_group parsing of unknown fields in untrusted input.
Affected version of this crate did not properly parse unknown fields when parsing a user-supplied input. This allows an attacker to cause a stack overflow when parsing the mssage on untrusted data.
Affected version of this crate did not properly parse unknown fields when parsing a user-supplied input. This allows an attacker to cause a stack overflow when parsing the message on untrusted data.
05 / REFERENCES
Further evidence
- https://crates.io/crates/protobuf
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/53xxx/CVE-2025-53605.json
- https://github.com/stepancheg/rust-protobuf/issues/749
- https://nvd.nist.gov/vuln/detail/CVE-2025-53605
- https://rustsec.org/advisories/RUSTSEC-2024-0437
- https://rustsec.org/advisories/RUSTSEC-2024-0437.html
- https://github.com/stepancheg/rust-protobuf
- https://github.com/stepancheg/rust-protobuf/commit/f06992f46771c0a092593b9ebf7afd48740b3ed6