msgpack vulnerabilities
CVEs whose affected-version data names the msgpack package (pip, rubygems). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-54522LowMessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
▾ Sunlitmsgpack · msgpackEPSS 0.16%via GHSA
CVE-2026-57585High· 7.5MessagePack for Python: Out-of-bounds read / crash on Unpacker reuse after a caught error
MessagePack for Python: Out-of-bounds read / crash on Unpacker reuse after a caught error
▾ Twilightmsgpack · msgpackEPSS 0.49%via OSV
GHSA-6v7p-g79w-8964High· 7.5MessagePack for Python: Out-of-bounds read / crash on Unpacker reuse after a caught error
MessagePack for Python: Out-of-bounds read / crash on Unpacker reuse after a caught error
▾ Twilightmsgpack · msgpackvia GHSA