{"schema_version":"1.9.0","id":"CVE-2025-4565","published":"2025-06-16T14:50:40.906Z","modified":"2026-08-12T15:13:30.778220Z","aliases":["GHSA-8qvm-5x2c-j2w7","PYSEC-2026-1806"],"related":["CGA-w3jp-gh75-25j4","SUSE-SU-2025:02309-1","SUSE-SU-2025:02310-1","SUSE-SU-2025:02311-1","SUSE-SU-2025:20514-1","SUSE-SU-2025:20672-1","SUSE-SU-2025:3722-1","SUSE-SU-2026:1653-1","SUSE-SU-2026:20753-1","SUSE-SU-2026:20907-1","openSUSE-SU-2025:15265-1","openSUSE-SU-2026:20390-1"],"summary":"Unbounded recursion in Python Protobuf","details":"Any project that uses Protobuf Pure-Python backend to parse untrusted Protocol Buffers data containing an arbitrary number of recursive groups, recursive messages or a series of SGROUP tags can be corrupted by exceeding the Python recursion limit. This can result in a Denial of service by crashing the application with a RecursionError. We recommend upgrading to version =>6.31.1 or beyond commit 17838beda2943d08b8a9d4df5b68f5f04f26d901","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/protocolbuffers/protobuf","events":[{"introduced":"0"},{"fixed":"a4cbdd3ed0042e8f9b9c30e8b0634096d9532809"},{"introduced":"d6511091a0cab1ad13f676a02676ad2a0e5eb9ae"},{"fixed":"f5de0a0495faa63b4186fc767324f8b9a7bf4fc4"},{"introduced":"d295af5c3002c08e1bfd9d7f9e175d0a4d015f1e"},{"fixed":"74211c0dfc2777318ab53c2cd2c317a2ef9012de"},{"fixed":"17838beda2943d08b8a9d4df5b68f5f04f26d901"}],"database_specific":{"cpe":"cpe:2.3:a:google:protobuf-python:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"4.25.8"},{"introduced":"5.26.0"},{"fixed":"5.29.5"},{"introduced":"6.30.0"},{"fixed":"6.31.1"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v27-dev","v26-dev","v4.25.0-rc1","v3.25.0-rc1","v25.0-rc1","v28-dev","v31-dev","v6.31.0-rc1","v4.31.0-rc1","v31.0-rc1","rust-prerelease-4.31.0-beta1","v30-dev","rust-prerelease-4.30.0-beta1","v29-dev","v5.29.0-rc1","v3.29.0-rc1","v29.0-rc1","v3.20.0-rc2","v3.12.3","v3.0.0-beta-3-pre-1","v3.0.0-beta-2","v3.0.0-beta-1-bzl-fix","v3.0.0-beta-1","v3.0.0-alpha-4","v3.0.0-alpha-3","v2.6.1rc1","v2.6.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-4565.json","vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["228606868923603677769672827467256280418","47561640358373228211429691835822805840","43839354369203371833717701412287303719","215908973485308819892957006685588128161"],"threshold":0.9},"id":"CVE-2025-4565-28660012","signature_type":"Line","signature_version":"v1","source":"https://github.com/protocolbuffers/protobuf/commit/74211c0dfc2777318ab53c2cd2c317a2ef9012de","target":{"file":"java/core/src/main/java/com/google/protobuf/RuntimeVersion.java"}},{"deprecated":false,"digest":{"line_hashes":["234249782041082941473730652632081580949","1239930494250163717274066415174407419","67316742155608480760959593469768444953","215908973485308819892957006685588128161"],"threshold":0.9},"id":"CVE-2025-4565-4655b7e0","signature_type":"Line","signature_version":"v1","source":"https://github.com/protocolbuffers/protobuf/commit/f5de0a0495faa63b4186fc767324f8b9a7bf4fc4","target":{"file":"java/core/src/main/java/com/google/protobuf/RuntimeVersion.java"}}],"vanir_signatures_modified":"2026-08-12T15:13:30Z"}}],"references":[{"type":"WEB","url":"https://github.com/protocolbuffers/protobuf/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/4xxx/CVE-2025-4565.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-4565"},{"type":"FIX","url":"https://github.com/protocolbuffers/protobuf/commit/17838beda2943d08b8a9d4df5b68f5f04f26d901"},{"type":"PACKAGE","url":"https://pypi.org/project/protobuf/"}],"database_specific":{"cna_assigner":"Google","cwe_ids":["CWE-674"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/4xxx/CVE-2025-4565.json"},"severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}