generative-ai-python icon indicating copy to clipboard operation
generative-ai-python copied to clipboard

protobuf 5.29.5 reported as vulnerable

Open Arima-dei opened this issue 6 months ago • 0 comments

Description of the bug:

Any project that uses Protobuf Pure-Python backend to parse untrusted Protocol Buffers data containing an arbitrary number of recursive groups, recursive messages or a series of SGROUP tags can be corrupted by exceeding the Python recursion limit. This can result in a Denial of service by crashing the application with a RecursionError. We recommend upgrading to version =>6.31.1 or beyond commit 17838beda2943d08b8a9d4df5b68f5f04f26d901

Actual vs expected behavior:

as per https://nvd.nist.gov/vuln/detail/CVE-2025-4565 , the protobuf 5.29.5 that comes as transitive dependecy has high vulnerability. CVSS-B [8.2 HIGH]. the fix version suggested by them is protobuf 6.31.1 which is not supprted by the google-generativeai .

Any other information you'd like to share?

No response

Arima-dei avatar Jun 19 '25 08:06 Arima-dei