CVE-2025-53605: Stepancheg Protobuf
Medium severity, CVSS 5.9. EPSS: 0.5% chance of exploitation in the next 30 days.
The protobuf crate before 3.7.2 for Rust allows uncontrolled recursion in the protobuf::coded_input_stream::CodedInputStream::skip_group parsing of unknown fields in untrusted input.
Affected products
- Stepancheg Protobuf: before 3.7.2 (fixed in 3.7.2)
Published 2025-07-05. Last modified 2026-06-17.