CVE-2025-53605 Information
Jul 06, 2025
cve
Description
The protobuf crate before 3.7.2 for Rust allows uncontrolled recursion in the protobuf::coded_input_stream::CodedInputStream::skip_group parsing of unknown fields in untrusted input.
Reference
https://crates.io/crates/protobuf https://github.com/stepancheg/rust-protobuf/issues/749 https://rustsec.org/advisories/RUSTSEC-2024-0437
Related CNNVD
CNNVD-202507-520 (Published: 2025-07-04)
Share on: