Any project that uses Protobuf Pure-Python backend to parse untrusted Protocol Buffers data containing an arbitrary number of recursive groups, recursive messages or a series of SGROUP tags can be corrupted by exceeding the Python recursion limit. This can result in a Denial of service by crashing the application with a RecursionError. We recommend upgrading to version =>6.31.1 or beyond commit 17838beda2943d08b8a9d4df5b68f5f04f26d901
                
            References
                    Configurations
                    Configuration 1 (hide)
            
            
  | 
    
History
                    14 Aug 2025, 17:05
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time | 
        
        Google protobuf-python
         | 
|
| CPE | cpe:2.3:a:google:protobuf:6.31.1:*:*:*:*:python:*:* cpe:2.3:a:google:protobuf:4.25.8:*:*:*:*:python:*:*  | 
    cpe:2.3:a:google:protobuf-python:*:*:*:*:*:*:*:* | 
| CVSS | 
        v2 :  v3 :  | 
    
        v2 : unknown
         v3 : 5.3  | 
07 Aug 2025, 15:32
| Type | Values Removed | Values Added | 
|---|---|---|
| CPE | cpe:2.3:a:google:protobuf:5.29.5:*:*:*:*:python:*:* cpe:2.3:a:google:protobuf:6.31.1:*:*:*:*:python:*:* cpe:2.3:a:google:protobuf:4.25.8:*:*:*:*:python:*:*  | 
|
| References | () https://github.com/protocolbuffers/protobuf/commit/17838beda2943d08b8a9d4df5b68f5f04f26d901 - Patch | |
| CVSS | 
        v2 :  v3 :  | 
    
        v2 : unknown
         v3 : 7.5  | 
| First Time | 
        
        Google protobuf
         | 
17 Jun 2025, 20:50
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-06-16 15:15
Updated : 2025-08-14 17:05
NVD link : CVE-2025-4565
Mitre link : CVE-2025-4565
CVE.ORG link : CVE-2025-4565
JSON object : View
Products Affected
                - protobuf-python
 
CWE
                
                    
                        
                        CWE-674
                        
            Uncontrolled Recursion
