Vulnerabilities
18 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-48109 | MessagePack for C# is a MessagePack serializer for C#. MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, A vulnerability exists in the optional LZ4 decompression path used by MessagePack compression modes Lz4Block and Lz4BlockArray. The decoder implementation is based on a deprecated fast-decompression algorithm that does not take a source-length bound. A remote attacker can send a crafted MessagePack payload with manipulated LZ4 token/length fields to force out-of-bounds reads from the compressed input buffer. In affected environments, this can trigger an AccessViolationException during decompression, causing process termination (denial of service). Under some conditions, limited unintended memory disclosure from over-read data may also be possible before failure. This vulnerability is fixed in 2.5.301 and 3.1.7. NVD description · AI analysis pending | 8.2 group max | <1% |
| — | ||
| CVE-2022-41719 | Unmarshal can panic on some inputs, possibly allowing for denial of service attacks. Unmarshal can panic on some inputs, possibly allowing for denial of service attacks. NVD description · AI analysis pending | 7.5 | 1% | PoC |
| — | |
| CVE-2021-45692 | An issue was discovered in the messagepack-rs crate through 2021-01-26 for Rust. An issue was discovered in the messagepack-rs crate through 2021-01-26 for Rust. deserialize_extension_others may read from uninitialized memory locations. NVD description · AI analysis pending | 9.8 | 1% |
| — | ||
| CVE-2020-5234 | MessagePack for C# and Unity before version 1.9.11 and 2.1.90 has a vulnerability where untrusted data can lead to DoS attack due to hash collisions and stack o MessagePack for C# and Unity before version 1.9.11 and 2.1.90 has a vulnerability where untrusted data can lead to DoS attack due to hash collisions and stack overflow. Review the linked GitHub Security Advisory for more information and remediation steps. NVD description · AI analysis pending | 6.5 | 2% |
| — |