MessagePack has 12 CVEs on record. Disclosure cadence is accelerating: 11 in the last 90 days against 1 in the 90 before. The busiest recent month was June 2026 with 12. The median CVSS is 7.5 (high). None have a confirmed exploitation report. The dominant weakness classes are CWE-674 (4) and CWE-407 (3).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.5
- Publish → KEV
- —
- Last 90 days
- 11 prev 1
Weakness classes
Products
- MessagePack 12
Worst active — by depth score
CVE-2026-48109High· 8.2 MessagePack's LZ4 decompression may fail with AccessViolationException after dereferencing memory from bad input45CVE-2026-48511Medium· 7.5MessagePack-CSharp: ExpandoObject formatter can perform quadratic insertion work on untrusted maps41CVE-2026-48510Medium· 7.5MessagePack-CSharp: LZ4 decompression allocates from unbounded declared output lengths41CVE-2026-48506High· 7.5MessagePack-CSharp: MessagePackReader.Skip can recurse without enforcing maximum object graph depth41CVE-2026-48502HighMessagePack-CSharp: Denial of service vulnerabilities can swamp the CPU or crash the process with stack and heap overflows41
MessagePack vulnerabilities
CVEs affecting MessagePack, newest first. Open any entry for full detail, references, and exploit status.
12 CVEsRSS
CVE-2026-48502HighMessagePack-CSharp: Denial of service vulnerabilities can swamp the CPU or crash the process with stack and heap overflows
MessagePack-CSharp: Denial of service vulnerabilities can swamp the CPU or crash the process with stack and heap overflows
CVE-2026-48506High· 7.5MessagePack-CSharp: MessagePackReader.Skip can recurse without enforcing maximum object graph depth
MessagePack-CSharp: MessagePackReader.Skip can recurse without enforcing maximum object graph depth
CVE-2026-48509MediumMessagePack-CSharp: ASP.NET Core MessagePackInputFormatter defaults to TrustedData for HTTP request bodies
MessagePack-CSharp: ASP.NET Core MessagePackInputFormatter defaults to TrustedData for HTTP request bodies
CVE-2026-48510Medium· 7.5MessagePack-CSharp: LZ4 decompression allocates from unbounded declared output lengths
MessagePack-CSharp: LZ4 decompression allocates from unbounded declared output lengths
CVE-2026-48511Medium· 7.5MessagePack-CSharp: ExpandoObject formatter can perform quadratic insertion work on untrusted maps
MessagePack-CSharp: ExpandoObject formatter can perform quadratic insertion work on untrusted maps
CVE-2026-48512MediumMessagePack-CSharp: JSON conversion APIs can recurse without consistent depth enforcement
MessagePack-CSharp: JSON conversion APIs can recurse without consistent depth enforcement
CVE-2026-48513MediumMessagePack-CSharp: DynamicUnionResolver-generated deserializers miss depth enforcement
MessagePack-CSharp: DynamicUnionResolver-generated deserializers miss depth enforcement
CVE-2026-48514MediumMessagePack-CSharp: Unity unsafe blit formatter allocates from unbounded byte length
MessagePack-CSharp: Unity unsafe blit formatter allocates from unbounded byte length
CVE-2026-48515MediumMessagePack-CSharp: Multi-dimensional array formatters allocate from unchecked dimensions
MessagePack-CSharp: Multi-dimensional array formatters allocate from unchecked dimensions
CVE-2026-48516MediumMessagePack-CSharp: InterfaceLookupFormatter bypasses collision-resistant comparer settings
MessagePack-CSharp: InterfaceLookupFormatter bypasses collision-resistant comparer settings
CVE-2026-48517MediumMessagePack-CSharp: Typeless deserialization type restrictions do not recurse into arrays or generic arguments
MessagePack-CSharp: Typeless deserialization type restrictions do not recurse into arrays or generic arguments
CVE-2026-48109High· 8.2MessagePack's LZ4 decompression may fail with AccessViolationException after dereferencing memory from bad input
MessagePack's LZ4 decompression may fail with AccessViolationException after dereferencing memory from bad input