messagepack records
14 published records for vendor messagepack.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-674 Uncontrolled Recursion3
- CWE-770 Allocation of Resources Without Limits or Throttling2
- CWE-407 Inefficient Algorithmic Complexity2
- CWE-20 Improper Input Validation1
- CWE-328 Use of Weak Hash1
- CWE-1188 Initialization of a Resource with an Insecure Default1
The weakness classes this vendor ships most often: where to look.
CWEAll records
14 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
34Monitor | CVE-2024-48924No exploit | MessagePack allows untrusted data to lead to DoS attack due to hash collisions and stack overflowmessagepack-csharp · messagepack-csharp · CWE-328 | High8.7 | — | 0.4% | Oct 17, 2024 |
32Monitor | CVE-2026-48109No exploit | MessagePack-CSharp: LZ4 decompression may fail with AccessViolationException after dereferencing memory from bad inputmessagepack · messagepack · CWE-20 | High8.2 | — | 0.5% | Jun 22, 2026 |
32Monitor | CVE-2026-48502No exploit | MessagePack-CSharp: Denial of service vulnerabilities can swamp the CPU or crash the process with stack and heap overflowsmessagepack · messagepack · CWE-125 | High8.2 | — | 0.4% | Jun 22, 2026 |
30Monitor | CVE-2026-48506No exploit | MessagePack-CSharp: MessagePackReader.Skip can recurse without enforcing maximum object graph depthmessagepack · messagepack · CWE-674 | High7.5 | — | 0.5% | Jun 22, 2026 |
26Monitor | CVE-2020-5234No exploit | Untrusted data can lead to DoS attack in MessagePack for C# and Unitymessagepack · messagepack · CWE-121 | Medium6.5 | — | 1.6% | Jan 31, 2020 |
25Monitor | CVE-2026-48509No exploit | MessagePack-CSharp: ASP.NET Core MessagePackInputFormatter defaults to TrustedData for HTTP request bodiesmessagepack · messagepack · CWE-1188 | Medium6.3 | — | 0.4% | Jun 22, 2026 |
25Monitor | CVE-2026-48516No exploit | MessagePack-CSharp: InterfaceLookupFormatter bypasses collision-resistant comparer settingsmessagepack · messagepack · CWE-407 | Medium6.3 | — | 0.4% | Jun 22, 2026 |
25Monitor | CVE-2026-48511No exploit | MessagePack-CSharp: ExpandoObject formatter can perform quadratic insertion work on untrusted mapsmessagepack · messagepack · CWE-407 | Medium6.3 | — | 0.4% | Jun 22, 2026 |
25Monitor | CVE-2026-48510No exploit | MessagePack-CSharp: LZ4 decompression allocates from unbounded declared output lengthsmessagepack · messagepack · CWE-409 | Medium6.3 | — | 0.4% | Jun 22, 2026 |
25Monitor | CVE-2026-48512No exploit | MessagePack-CSharp: JSON conversion APIs can recurse without consistent depth enforcementmessagepack · messagepack · CWE-674 | Medium6.3 | — | 0.4% | Jun 22, 2026 |
25Monitor | CVE-2026-48513No exploit | MessagePack-CSharp: DynamicUnionResolver generated deserializers miss depth enforcementmessagepack · messagepack · CWE-674 | Medium6.3 | — | 0.4% | Jun 22, 2026 |
25Monitor | CVE-2026-48514No exploit | MessagePack-CSharp: Unity unsafe blit formatter allocates from unbounded byte lengthmessagepack · messagepack · CWE-770 | Medium6.3 | — | 0.4% | Jun 22, 2026 |
25Monitor | CVE-2026-48515No exploit | MessagePack-CSharp: Multi-dimensional array formatters allocate from unchecked dimensionsmessagepack · messagepack · CWE-770 | Medium6.3 | — | 0.4% | Jun 22, 2026 |
25Monitor | CVE-2026-48517No exploit | MessagePack-CSharp: Typeless deserialization type restrictions do not recurse into arrays or generic argumentsmessagepack · messagepack · CWE-470 | Medium6.3 | — | 0.3% | Jun 22, 2026 |
- CVE-2024-4892434Monitor
MessagePack allows untrusted data to lead to DoS attack due to hash collisions and stack overflow
HighCVSS 8.7No exploitEPSS 0%messagepack-csharp · messagepack-csharpOct 17, 2024
- CVE-2026-4810932Monitor
MessagePack-CSharp: LZ4 decompression may fail with AccessViolationException after dereferencing memory from bad input
HighCVSS 8.2No exploitEPSS 1%messagepack · messagepackJun 22, 2026
- CVE-2026-4850232Monitor
MessagePack-CSharp: Denial of service vulnerabilities can swamp the CPU or crash the process with stack and heap overflows
HighCVSS 8.2No exploitEPSS 0%messagepack · messagepackJun 22, 2026
- CVE-2026-4850630Monitor
MessagePack-CSharp: MessagePackReader.Skip can recurse without enforcing maximum object graph depth
HighCVSS 7.5No exploitEPSS 0%messagepack · messagepackJun 22, 2026
- CVE-2020-523426Monitor
Untrusted data can lead to DoS attack in MessagePack for C# and Unity
MediumCVSS 6.5No exploitEPSS 2%messagepack · messagepackJan 31, 2020
- CVE-2026-4850925Monitor
MessagePack-CSharp: ASP.NET Core MessagePackInputFormatter defaults to TrustedData for HTTP request bodies
MediumCVSS 6.3No exploitEPSS 0%messagepack · messagepackJun 22, 2026
- CVE-2026-4851625Monitor
MessagePack-CSharp: InterfaceLookupFormatter bypasses collision-resistant comparer settings
MediumCVSS 6.3No exploitEPSS 0%messagepack · messagepackJun 22, 2026
- CVE-2026-4851125Monitor
MessagePack-CSharp: ExpandoObject formatter can perform quadratic insertion work on untrusted maps
MediumCVSS 6.3No exploitEPSS 0%messagepack · messagepackJun 22, 2026
- CVE-2026-4851025Monitor
MessagePack-CSharp: LZ4 decompression allocates from unbounded declared output lengths
MediumCVSS 6.3No exploitEPSS 0%messagepack · messagepackJun 22, 2026
- CVE-2026-4851225Monitor
MessagePack-CSharp: JSON conversion APIs can recurse without consistent depth enforcement
MediumCVSS 6.3No exploitEPSS 0%messagepack · messagepackJun 22, 2026
- CVE-2026-4851325Monitor
MessagePack-CSharp: DynamicUnionResolver generated deserializers miss depth enforcement
MediumCVSS 6.3No exploitEPSS 0%messagepack · messagepackJun 22, 2026
- CVE-2026-4851425Monitor
MessagePack-CSharp: Unity unsafe blit formatter allocates from unbounded byte length
MediumCVSS 6.3No exploitEPSS 0%messagepack · messagepackJun 22, 2026
- CVE-2026-4851525Monitor
MessagePack-CSharp: Multi-dimensional array formatters allocate from unchecked dimensions
MediumCVSS 6.3No exploitEPSS 0%messagepack · messagepackJun 22, 2026
- CVE-2026-4851725Monitor
MessagePack-CSharp: Typeless deserialization type restrictions do not recurse into arrays or generic arguments
MediumCVSS 6.3No exploitEPSS 0%messagepack · messagepackJun 22, 2026