messagepack-csharp
OSS Librariesoss-project
Top products
Latest CVEs
The 12 most recently published vulnerabilities affecting messagepack-csharp.
- CVE-2026-48109MessagePack-CSharp: LZ4 decompression may fail with AccessViolationException after dereferencing memory from bad input8.2
- CVE-2026-48502MessagePack-CSharp: Denial of service vulnerabilities can swamp the CPU or crash the process with stack and heap overflows7.5
- CVE-2026-48506MessagePack-CSharp: MessagePackReader.Skip can recurse without enforcing maximum object graph depth7.5
- CVE-2026-48509MessagePack-CSharp: ASP.NET Core MessagePackInputFormatter defaults to TrustedData for HTTP request bodies9.1
- CVE-2026-48510MessagePack-CSharp: LZ4 decompression allocates from unbounded declared output lengths7.5
- CVE-2026-48511MessagePack-CSharp: ExpandoObject formatter can perform quadratic insertion work on untrusted maps7.5
- CVE-2026-48512MessagePack-CSharp: JSON conversion APIs can recurse without consistent depth enforcement7.5
- CVE-2026-48513MessagePack-CSharp: DynamicUnionResolver generated deserializers miss depth enforcement7.5
- CVE-2026-48514MessagePack-CSharp: Unity unsafe blit formatter allocates from unbounded byte length7.5
- CVE-2026-48515MessagePack-CSharp: Multi-dimensional array formatters allocate from unchecked dimensions7.5
- CVE-2026-48516MessagePack-CSharp: InterfaceLookupFormatter bypasses collision-resistant comparer settings7.5
- CVE-2026-48517MessagePack-CSharp: Typeless deserialization type restrictions do not recurse into arrays or generic arguments7.5