Crash due to uncontrolled recursion in protobuf crate
Moderate severity
GitHub Reviewed
Published
Mar 7, 2025
to the GitHub Advisory Database
•
Updated Mar 7, 2025
Description
Published to the GitHub Advisory Database
Mar 7, 2025
Reviewed
Mar 7, 2025
Last updated
Mar 7, 2025
Affected version of this crate did not properly parse unknown fields when parsing a user-supplied input.
This allows an attacker to cause a stack overflow when parsing the message on untrusted data.
References