Messagepack
This hub aggregates every CVE we track for Messagepack, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
17
CVEs tracked
1
Critical
14
High
0
In CISA KEV
Severity distribution
HIGH14MEDIUM2CRITICAL1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
0
0
0
13
1
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Messagepack.
- CVE-2026-54522MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure5.4
- CVE-2026-57585MessagePack: Out-of-bounds read/crash on Unpacker reuse after caught error7.5
- CVE-2026-48109MessagePack-CSharp: LZ4 decompression may fail with AccessViolationException after dereferencing memory from bad input8.2
- CVE-2026-48502MessagePack-CSharp: Denial of service vulnerabilities can swamp the CPU or crash the process with stack and heap overflows7.5
- CVE-2026-48506MessagePack-CSharp: MessagePackReader.Skip can recurse without enforcing maximum object graph depth7.5
- CVE-2026-48509MessagePack-CSharp: ASP.NET Core MessagePackInputFormatter defaults to TrustedData for HTTP request bodies9.1
- CVE-2026-48510MessagePack-CSharp: LZ4 decompression allocates from unbounded declared output lengths7.5
- CVE-2026-48511MessagePack-CSharp: ExpandoObject formatter can perform quadratic insertion work on untrusted maps7.5
- CVE-2026-48512MessagePack-CSharp: JSON conversion APIs can recurse without consistent depth enforcement7.5
- CVE-2026-48513MessagePack-CSharp: DynamicUnionResolver generated deserializers miss depth enforcement7.5
- CVE-2026-48514MessagePack-CSharp: Unity unsafe blit formatter allocates from unbounded byte length7.5
- CVE-2026-48515MessagePack-CSharp: Multi-dimensional array formatters allocate from unchecked dimensions7.5
- CVE-2026-48516MessagePack-CSharp: InterfaceLookupFormatter bypasses collision-resistant comparer settings7.5
- CVE-2026-48517MessagePack-CSharp: Typeless deserialization type restrictions do not recurse into arrays or generic arguments7.5
- CVE-2026-21452MessagePack-Java Vulnerable to Remote Denial of Service via Malicious .msgpack Model File Triggering Unbounded EXT Payload Allocation7.5
Product normalization is registry-driven with AI assist and human review. How it works