Vulnerabilities
Summary — last 7 days
New vulnerabilities2,811▲ 64 vs. last week
Critical / high1,484▲ 296 vs. last week
New active exploitation (KEV)5▼ 5 vs. last week
Unscored (no CVSS)68▼ 448 vs. last week
23 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Analyzed | Low (2.1) | 0.23% | — | Msgpack Messagepack | 7/30/2026 | 8/5/2026 | MessagePack for Ruby is an implementation of the MessagePack binary serialization format. Prior to 1.8.2, MessagePack::Buffer#clear in ext/msgpack/buffer.c leaves rmem_last, rmem_end, and rmem_owner stale after _msgpack_buffer_shift_chunk returns an rmem page to the shared pool, allowing a subsequent Buffer#write and… | |
| Analyzed | High (7.5) | 0.49% | — | Msgpack Messagepack | 6/30/2026 | 8/6/2026 | MessagePack is the serializer implementation for Python msgpack.org. Prior to 1.2.1, there is an Out-of-bounds read/crash on Unpacker reuse after a caught error, potentially leading to a DoS attack. If the Unpacker is used repeatedly after an error occurs, the process may crash with a SEGV. This issue has been fixed… | |
| Analyzed | Medium (6.3) | 0.35% | — | Messagepack | 6/22/2026 | 6/25/2026 | MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePack-CSharp's typeless deserialization includes MessagePackSerializerOptions.ThrowIfDeserializingTypeIsDisallowed(Type) as a safety check for dangerous types. The default implementation checks the outer type name, but it does not… | |
| Analyzed | Medium (6.3) | 0.40% | — | Messagepack | 6/22/2026 | 6/25/2026 | MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, InterfaceLookupFormatter<TKey,TElement> constructs an internal Dictionary<TKey, IGrouping<TKey,TElement>> with the default equality comparer instead of the security-aware comparer supplied by… | |
| Analyzed | Medium (6.3) | 0.40% | — | Messagepack | 6/22/2026 | 6/25/2026 | MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePack-CSharp's multi-dimensional array formatters read dimension lengths directly from the payload and allocate T[,], T[,,], or T[,,,] before validating that the dimension product matches the encoded element count. The formatter… | |
| Analyzed | Medium (6.3) | 0.40% | — | Messagepack | 6/22/2026 | 6/25/2026 | MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, UnsafeBlitFormatterBase<T>.Deserialize reads an attacker-controlled byteLength from an extension payload and allocates an array based on that value before validating it against the extension header length or remaining payload bytes. The… | |
| Analyzed | Medium (6.3) | 0.40% | — | Messagepack | 6/22/2026 | 6/25/2026 | MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, runtime-generated union deserializers emitted by DynamicUnionResolver do not call MessagePackSecurity.DepthStep(ref reader) and do not decrement reader.Depth around recursive deserialization and skip paths. This means union… | |
| Analyzed | Medium (6.3) | 0.40% | — | Messagepack | 6/22/2026 | 6/25/2026 | MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePack-CSharp's JSON conversion helpers contain multiple recursion paths that do not consistently enforce a depth limit. These paths are in the JSON conversion component rather than normal typed MessagePack deserialization.… | |
| Analyzed | Medium (6.3) | 0.40% | — | Messagepack | 6/22/2026 | 6/25/2026 | MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, ExpandoObjectFormatter.Deserialize populates System.Dynamic.ExpandoObject by calling IDictionary<string, object>.Add for each map entry. ExpandoObject internally maintains member names in array-like structures, so inserting many… | |
| Analyzed | Medium (6.3) | 0.40% | — | Messagepack | 6/22/2026 | 6/25/2026 | MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, when MessagePack-CSharp decompresses Lz4Block or Lz4BlockArray payloads, it reads declared uncompressed lengths from the wire and allocates output buffers based on those lengths before validating that the compressed data is valid or… | |
| Analyzed | Medium (6.3) | 0.42% | — | Messagepack | 6/22/2026 | 6/25/2026 | MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, the parameterless MessagePackInputFormatter() constructor uses default serializer options, which resolve to MessagePackSerializerOptions.Standard with MessagePackSecurity.TrustedData. The formatter is designed for ASP.NET Core MVC… | |
| Analyzed | High (7.5) | 0.47% | — | Messagepack | 6/22/2026 | 6/23/2026 | MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePackReader.TrySkip() recursively descends into nested arrays and maps without incrementing the reader depth or calling the configured depth checks. This bypasses MessagePackSecurity.MaximumObjectGraphDepth, the library's… | |
| Analyzed | High (8.2) | 0.44% | — | Messagepack | 6/22/2026 | 6/23/2026 | MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePackReader.ReadDateTime() can allocate stack memory based on an attacker-controlled MessagePack extension length. In the slow path for timestamp extension parsing, the computed tokenSize includes the extension body length from… | |
| Analyzed | High (8.2) | 0.51% | — | Messagepack | 6/22/2026 | 6/23/2026 | MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, A vulnerability exists in the optional LZ4 decompression path used by MessagePack compression modes Lz4Block and Lz4BlockArray. The decoder implementation is based on a deprecated fast-decompression algorithm that does not take a… | |
| Deferred | High (7.5) | 0.63% | — | Nerdbank MessagepackAI | 5/14/2026 | 6/17/2026 | Nerdbank.MessagePack is a NativeAOT-compatible MessagePack serialization library. Prior to 1.1.62, Nerdbank.MessagePack contains an uncontrolled stack allocation vulnerability in DateTime decoding. A malicious MessagePack payload can declare an oversized timestamp extension length, causing the reader to allocate an… | |
| Analyzed | High (7.5) | 0.60% | — | Msgpack Messagepack | 1/2/2026 | 6/17/2026 | MessagePack for Java is a serializer implementation for Java. A denial-of-service vulnerability exists in versions prior to 0.9.11 when deserializing .msgpack files containing EXT32 objects with attacker-controlled payload lengths. While MessagePack-Java parses extension headers lazily, it later trusts the declared… | |
| Deferred | High (8.7) | 0.37% | — | Messagepack-csharpAI | 10/17/2024 | 6/17/2026 | ### Impact When this library is used to deserialize messagepack data from an untrusted source, there is a risk of a denial of service attack by an attacker that sends data contrived to produce hash collisions, leading to large CPU consumption disproportionate to the size of the data being deserialized. This is similar… | |
| Modified | High (7.5) | 1.1% | — | Messagepack Project Messagepack | 11/10/2022 | 6/17/2026 | Unmarshal can panic on some inputs, possibly allowing for denial of service attacks. | |
| Modified | Critical (9.8) | 1.2% | — | Messagepack-rs Project Messagepack-rs | 12/27/2021 | 6/17/2026 | An issue was discovered in the messagepack-rs crate through 2021-01-26 for Rust. deserialize_string_primitive may read from uninitialized memory locations. | |
| Modified | Critical (9.8) | 1.4% | — | Messagepack-rs Project Messagepack-rs | 12/27/2021 | 6/17/2026 | An issue was discovered in the messagepack-rs crate through 2021-01-26 for Rust. deserialize_extension_others may read from uninitialized memory locations. | |
| Modified | Critical (9.8) | 1.2% | — | Messagepack-rs Project Messagepack-rs | 12/27/2021 | 6/17/2026 | An issue was discovered in the messagepack-rs crate through 2021-01-26 for Rust. deserialize_string may read from uninitialized memory locations. | |
| Modified | Critical (9.8) | 1.2% | — | Messagepack-rs Project Messagepack-rs | 12/27/2021 | 6/17/2026 | An issue was discovered in the messagepack-rs crate through 2021-01-26 for Rust. deserialize_binary may read from uninitialized memory locations. | |
| Modified | Medium (6.5) | 1.6% | — | Messagepack | 1/31/2020 | 6/17/2026 | MessagePack for C# and Unity before version 1.9.11 and 2.1.90 has a vulnerability where untrusted data can lead to DoS attack due to hash collisions and stack overflow. Review the linked GitHub Security Advisory for more information and remediation steps. |