msgpack has 5 CVEs on record. 3 were published in the last 90 days. The median CVSS is 6.4 (medium). None have a confirmed exploitation report. Most affected products: msgpack (3), msgpack-java (2).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.4
- Publish → KEV
- —
- Last 90 days
- 3 prev 2
Worst active — by depth score
CVE-2026-90472Medium· 5.3msgpack-java through 0.9.12 contains a stack overflow vulnerability in MessageUnpacker.unpackValue() that recursively deserializes arrays and maps without nesting depth limits41GHSA-6v7p-g79w-8964High· 7.5MessagePack for Python: Out-of-bounds read / crash on Unpacker reuse after a caught error41CVE-2026-57585High· 7.5MessagePack for Python: Out-of-bounds read / crash on Unpacker reuse after a caught error41CVE-2026-90473Medium· 5.3msgpack-java through 0.9.12 contains an integer overflow vulnerability in MessageUnpacker.skipValue() when processing MAP32 containers with large element counts29CVE-2026-54522LowMessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure14
msgpack vulnerabilities
CVEs affecting msgpack, newest first. Open any entry for full detail, references, and exploit status.
5 CVEsRSS
CVE-2026-90473Medium· 5.3msgpack-java through 0.9.12 contains an integer overflow vulnerability in MessageUnpacker.skipValue() when processing MAP32 containers with large element counts
msgpack-java through 0.9.12 contains an integer overflow vulnerability in MessageUnpacker.skipValue() when processing MAP32 containers with large element counts. Attackers can supply a MAP32 element count at or above 0x40000000 that wrap…
CVE-2026-90472Medium· 5.3PoCmsgpack-java through 0.9.12 contains a stack overflow vulnerability in MessageUnpacker.unpackValue() that recursively deserializes arrays and maps without nesting depth limits
msgpack-java through 0.9.12 contains a stack overflow vulnerability in MessageUnpacker.unpackValue() that recursively deserializes arrays and maps without nesting depth limits. Attackers can craft payloads with deeply nested arrays to ex…
CVE-2026-54522LowMessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
CVE-2026-57585High· 7.5MessagePack for Python: Out-of-bounds read / crash on Unpacker reuse after a caught error
MessagePack for Python: Out-of-bounds read / crash on Unpacker reuse after a caught error
GHSA-6v7p-g79w-8964High· 7.5MessagePack for Python: Out-of-bounds read / crash on Unpacker reuse after a caught error
MessagePack for Python: Out-of-bounds read / crash on Unpacker reuse after a caught error