VYPR

Protobuf Python

by Google

CVEs (2)

  • CVE-2022-1941HigSep 22, 2022
    risk 0.49cvss 7.5epss 0.01

    A parsing vulnerability for the MessageSet type in the ProtocolBuffers versions prior to and including 3.16.1, 3.17.3, 3.18.2, 3.19.4, 3.20.1 and 3.21.5 for protobuf-cpp, and versions prior to and including 3.16.1, 3.17.3, 3.18.2, 3.19.4, 3.20.1 and 4.21.5 for protobuf-python…

  • CVE-2025-4565MedJun 16, 2025
    risk 0.27cvss 5.3epss 0.00

    Any project that uses Protobuf Pure-Python backend to parse untrusted Protocol Buffers data containing an arbitrary number of recursive groups, recursive messages or a series of SGROUP tags can be corrupted by exceeding the Python recursion limit. This can result in a Denial…