MessagePack vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-48517MediumMessagePack: MessagePack-CSharp: Typeless deserialization type restrictions do not recurse into arrays or generic argumentsCVE-2026-48516MediumMessagePack: MessagePack-CSharp: InterfaceLookupFormatter bypasses collision-resistant comparer settingsCVE-2026-48515MediumMessagePack: MessagePack-CSharp: Multi-dimensional array formatters allocate from unchecked dimensionsCVE-2026-48514MediumMessagePack: MessagePack-CSharp: Unity unsafe blit formatter allocates from unbounded byte lengthCVE-2026-48513MediumMessagePack: MessagePack-CSharp: DynamicUnionResolver-generated deserializers miss depth enforcementCVE-2026-48512MediumMessagePack: MessagePack-CSharp: JSON conversion APIs can recurse without consistent depth enforcementCVE-2026-48511MediumMessagePack: MessagePack-CSharp: ExpandoObject formatter can perform quadratic insertion work on untrusted mapsCVE-2026-48510MediumMessagePack: MessagePack-CSharp: LZ4 decompression allocates from unbounded declared output lengthsCVE-2026-48509MediumMessagePack: MessagePack-CSharp: ASP.NET Core MessagePackInputFormatter defaults to TrustedData for HTTP request bodiesCVE-2026-48506HighMessagePack: MessagePack-CSharp: MessagePackReader.Skip can recurse without enforcing maximum object graph depthCVE-2026-48502HighMessagePack: MessagePack-CSharp: Denial of service vulnerabilities can swamp the CPU or crash the process with stack and heap overflowsCVE-2026-48109HighMessagePack: MessagePack's LZ4 decompression may fail with AccessViolationException after dereferencing memory from bad inputCVE-2024-48924MediumMessagePack: MessagePack allows untrusted data to lead to DoS attack due to hash collisions and stack overflowCVE-2020-5234MediumMessagePack: Untrusted data can lead to DoS attack due to hash collisions and stack overflow in MessagePack

Stop the waste.
Protect your environment with Kodem.