MessagePack vulnerabilities
CVEs whose affected-version data names the MessagePack package (nuget). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
12 CVEsRSS
CVE-2026-48502HighMessagePack-CSharp: Denial of service vulnerabilities can swamp the CPU or crash the process with stack and heap overflows
MessagePack-CSharp: Denial of service vulnerabilities can swamp the CPU or crash the process with stack and heap overflows
CVE-2026-48506High· 7.5MessagePack-CSharp: MessagePackReader.Skip can recurse without enforcing maximum object graph depth
MessagePack-CSharp: MessagePackReader.Skip can recurse without enforcing maximum object graph depth
CVE-2026-48509MediumMessagePack-CSharp: ASP.NET Core MessagePackInputFormatter defaults to TrustedData for HTTP request bodies
MessagePack-CSharp: ASP.NET Core MessagePackInputFormatter defaults to TrustedData for HTTP request bodies
CVE-2026-48510Medium· 7.5MessagePack-CSharp: LZ4 decompression allocates from unbounded declared output lengths
MessagePack-CSharp: LZ4 decompression allocates from unbounded declared output lengths
CVE-2026-48511Medium· 7.5MessagePack-CSharp: ExpandoObject formatter can perform quadratic insertion work on untrusted maps
MessagePack-CSharp: ExpandoObject formatter can perform quadratic insertion work on untrusted maps
CVE-2026-48512MediumMessagePack-CSharp: JSON conversion APIs can recurse without consistent depth enforcement
MessagePack-CSharp: JSON conversion APIs can recurse without consistent depth enforcement
CVE-2026-48513MediumMessagePack-CSharp: DynamicUnionResolver-generated deserializers miss depth enforcement
MessagePack-CSharp: DynamicUnionResolver-generated deserializers miss depth enforcement
CVE-2026-48514MediumMessagePack-CSharp: Unity unsafe blit formatter allocates from unbounded byte length
MessagePack-CSharp: Unity unsafe blit formatter allocates from unbounded byte length
CVE-2026-48515MediumMessagePack-CSharp: Multi-dimensional array formatters allocate from unchecked dimensions
MessagePack-CSharp: Multi-dimensional array formatters allocate from unchecked dimensions
CVE-2026-48516MediumMessagePack-CSharp: InterfaceLookupFormatter bypasses collision-resistant comparer settings
MessagePack-CSharp: InterfaceLookupFormatter bypasses collision-resistant comparer settings
CVE-2026-48517MediumMessagePack-CSharp: Typeless deserialization type restrictions do not recurse into arrays or generic arguments
MessagePack-CSharp: Typeless deserialization type restrictions do not recurse into arrays or generic arguments
CVE-2026-48109High· 8.2MessagePack's LZ4 decompression may fail with AccessViolationException after dereferencing memory from bad input
MessagePack's LZ4 decompression may fail with AccessViolationException after dereferencing memory from bad input