CVE-2025-53605: Stepancheg Protobuf

Medium severity, CVSS 5.9. EPSS: 0.5% chance of exploitation in the next 30 days.

The protobuf crate before 3.7.2 for Rust allows uncontrolled recursion in the protobuf::coded_input_stream::CodedInputStream::skip_group parsing of unknown fields in untrusted input.

Affected products

  • Stepancheg Protobuf: before 3.7.2 (fixed in 3.7.2)

Published 2025-07-05. Last modified 2026-06-17.