CVE-2025-53605 affecting package rust for versions less than 1.72.0-11
Details
The protobuf crate before 3.7.2 for Rust allows uncontrolled recursion in the protobuf::codedinputstream::CodedInputStream::skip_group parsing of unknown fields in untrusted input.