VDB
DEBIAN-CVE-2025-4565
DEBIAN-CVE-2025-4565
PUBLISHED
CVSS 5.300000190734863 MEDIUM
Any project that uses Protobuf Pure-Python backend to parse untrusted Protocol Buffers data containing an arbitrary number of recursive groups, recursive messages or a series of SGROUP tags can be corrupted by exceeding the Python recursion limit. This can result in a Denial of service by crashing the application with a RecursionError. We recommend upgrading to version =>6.31.1 or beyond commit 17838beda2943d08b8a9d4df5b68f5f04f26d901
Risk Scores
CVSS 3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:13 | protobuf | 0, 3.21.12-11, 3.21.12-12 |
| Debian:12 | protobuf | 3.21.12-12, 0, 3.21.12-10 |
| Debian:14 | protobuf | 0, 0, 3.21.12-11 |
| Debian:11 | protobuf | 3.12.4-1, 3.14.0-1, 3.17.1-1 |
Exploit Intelligence
- sdk.py (github-poc)
- tmp_audit.json (github-poc)
- converter_test.go (github-poc)
- dependencies.py (github-poc)
Timeline
- Jun 16, 2025 CVE Published
- Apr 28, 2026 CVE Updated