Vulnerabilities

Summary — last 7 days

New vulnerabilities2,811▲ 64 vs. last week
Critical / high1,484▲ 296 vs. last week
New active exploitation (KEV)5▼ 5 vs. last week
Unscored (no CVSS)68▼ 448 vs. last week
–

23 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
AnalyzedLow (2.1)0.23%—Msgpack Messagepack7/30/20268/5/2026
MessagePack for Ruby is an implementation of the MessagePack binary serialization format. Prior to 1.8.2, MessagePack::Buffer#clear in ext/msgpack/buffer.c leaves rmem_last, rmem_end, and rmem_owner stale after _msgpack_buffer_shift_chunk returns an rmem page to the shared pool, allowing a subsequent Buffer#write and…
AnalyzedHigh (7.5)0.49%—Msgpack Messagepack6/30/20268/6/2026
MessagePack is the serializer implementation for Python msgpack.org. Prior to 1.2.1, there is an Out-of-bounds read/crash on Unpacker reuse after a caught error, potentially leading to a DoS attack. If the Unpacker is used repeatedly after an error occurs, the process may crash with a SEGV. This issue has been fixed…
AnalyzedMedium (6.3)0.35%—Messagepack6/22/20266/25/2026
MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePack-CSharp's typeless deserialization includes MessagePackSerializerOptions.ThrowIfDeserializingTypeIsDisallowed(Type) as a safety check for dangerous types. The default implementation checks the outer type name, but it does not…
AnalyzedMedium (6.3)0.40%—Messagepack6/22/20266/25/2026
MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, InterfaceLookupFormatter<TKey,TElement> constructs an internal Dictionary<TKey, IGrouping<TKey,TElement>> with the default equality comparer instead of the security-aware comparer supplied by…
AnalyzedMedium (6.3)0.40%—Messagepack6/22/20266/25/2026
MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePack-CSharp's multi-dimensional array formatters read dimension lengths directly from the payload and allocate T[,], T[,,], or T[,,,] before validating that the dimension product matches the encoded element count. The formatter…
AnalyzedMedium (6.3)0.40%—Messagepack6/22/20266/25/2026
MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, UnsafeBlitFormatterBase<T>.Deserialize reads an attacker-controlled byteLength from an extension payload and allocates an array based on that value before validating it against the extension header length or remaining payload bytes. The…
AnalyzedMedium (6.3)0.40%—Messagepack6/22/20266/25/2026
MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, runtime-generated union deserializers emitted by DynamicUnionResolver do not call MessagePackSecurity.DepthStep(ref reader) and do not decrement reader.Depth around recursive deserialization and skip paths. This means union…
AnalyzedMedium (6.3)0.40%—Messagepack6/22/20266/25/2026
MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePack-CSharp's JSON conversion helpers contain multiple recursion paths that do not consistently enforce a depth limit. These paths are in the JSON conversion component rather than normal typed MessagePack deserialization.…
AnalyzedMedium (6.3)0.40%—Messagepack6/22/20266/25/2026
MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, ExpandoObjectFormatter.Deserialize populates System.Dynamic.ExpandoObject by calling IDictionary<string, object>.Add for each map entry. ExpandoObject internally maintains member names in array-like structures, so inserting many…
AnalyzedMedium (6.3)0.40%—Messagepack6/22/20266/25/2026
MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, when MessagePack-CSharp decompresses Lz4Block or Lz4BlockArray payloads, it reads declared uncompressed lengths from the wire and allocates output buffers based on those lengths before validating that the compressed data is valid or…
AnalyzedMedium (6.3)0.42%—Messagepack6/22/20266/25/2026
MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, the parameterless MessagePackInputFormatter() constructor uses default serializer options, which resolve to MessagePackSerializerOptions.Standard with MessagePackSecurity.TrustedData. The formatter is designed for ASP.NET Core MVC…
AnalyzedHigh (7.5)0.47%—Messagepack6/22/20266/23/2026
MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePackReader.TrySkip() recursively descends into nested arrays and maps without incrementing the reader depth or calling the configured depth checks. This bypasses MessagePackSecurity.MaximumObjectGraphDepth, the library's…
AnalyzedHigh (8.2)0.44%—Messagepack6/22/20266/23/2026
MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePackReader.ReadDateTime() can allocate stack memory based on an attacker-controlled MessagePack extension length. In the slow path for timestamp extension parsing, the computed tokenSize includes the extension body length from…
AnalyzedHigh (8.2)0.51%—Messagepack6/22/20266/23/2026
MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, A vulnerability exists in the optional LZ4 decompression path used by MessagePack compression modes Lz4Block and Lz4BlockArray. The decoder implementation is based on a deprecated fast-decompression algorithm that does not take a…
DeferredHigh (7.5)0.63%—Nerdbank MessagepackAI5/14/20266/17/2026
Nerdbank.MessagePack is a NativeAOT-compatible MessagePack serialization library. Prior to 1.1.62, Nerdbank.MessagePack contains an uncontrolled stack allocation vulnerability in DateTime decoding. A malicious MessagePack payload can declare an oversized timestamp extension length, causing the reader to allocate an…
AnalyzedHigh (7.5)0.60%—Msgpack Messagepack1/2/20266/17/2026
MessagePack for Java is a serializer implementation for Java. A denial-of-service vulnerability exists in versions prior to 0.9.11 when deserializing .msgpack files containing EXT32 objects with attacker-controlled payload lengths. While MessagePack-Java parses extension headers lazily, it later trusts the declared…
DeferredHigh (8.7)0.37%—Messagepack-csharpAI10/17/20246/17/2026
### Impact When this library is used to deserialize messagepack data from an untrusted source, there is a risk of a denial of service attack by an attacker that sends data contrived to produce hash collisions, leading to large CPU consumption disproportionate to the size of the data being deserialized. This is similar…
ModifiedHigh (7.5)1.1%—Messagepack Project Messagepack11/10/20226/17/2026
Unmarshal can panic on some inputs, possibly allowing for denial of service attacks.
ModifiedCritical (9.8)1.2%—Messagepack-rs Project Messagepack-rs12/27/20216/17/2026
An issue was discovered in the messagepack-rs crate through 2021-01-26 for Rust. deserialize_string_primitive may read from uninitialized memory locations.
ModifiedCritical (9.8)1.4%—Messagepack-rs Project Messagepack-rs12/27/20216/17/2026
An issue was discovered in the messagepack-rs crate through 2021-01-26 for Rust. deserialize_extension_others may read from uninitialized memory locations.
ModifiedCritical (9.8)1.2%—Messagepack-rs Project Messagepack-rs12/27/20216/17/2026
An issue was discovered in the messagepack-rs crate through 2021-01-26 for Rust. deserialize_string may read from uninitialized memory locations.
ModifiedCritical (9.8)1.2%—Messagepack-rs Project Messagepack-rs12/27/20216/17/2026
An issue was discovered in the messagepack-rs crate through 2021-01-26 for Rust. deserialize_binary may read from uninitialized memory locations.
ModifiedMedium (6.5)1.6%—Messagepack1/31/20206/17/2026
MessagePack for C# and Unity before version 1.9.11 and 2.1.90 has a vulnerability where untrusted data can lead to DoS attack due to hash collisions and stack overflow. Review the linked GitHub Security Advisory for more information and remediation steps.