Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-90473— msgpack-java through 0.9.12 Integer Overflow via MAP32

Quick assessment

Affected
msgpack msgpack-java
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

msgpack-java 0.9.12 及更早版本中存在一个整数溢出漏洞,位于 方法中,发生在处理具有大量元素计数的 MAP32 容器时。攻击者可以提供一个大于或等于 的 MAP32 元素计数,当该计数值被加倍时发生整数回绕(wrap),导致解析器游标(cursor)失去同步,使得攻击者控制的数据被错误地返回,替代了后续字段的正常内容。

CVSS 5.3 · Medium

Possible ATT&CK Techniques 1 AI

T1210 · Exploitation of Remote Services

Affected Version Matrix 1

VendorProduct Version RangeStatus
msgpack msgpack-java ≤ 0.9.12 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-90473

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
msgpack-java through 0.9.12 Integer Overflow via MAP32
Source: CVE Program / CVE List V5
Vulnerability Description
msgpack-java through 0.9.12 contains an integer overflow vulnerability in MessageUnpacker.skipValue() when processing MAP32 containers with large element counts. Attackers can supply a MAP32 element count at or above 0x40000000 that wraps when doubled, causing the parser cursor to desynchronize and attacker-controlled data to be returned in place of later fields.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
整数溢出或超界折返
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
msgpack msgpack-java 0 ~ 0.9.12 -

II. Public POCs for CVE-2026-90473

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-90473

登录查看更多情报信息。

Vendor Advisories for CVE-2026-90473 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-90473

No comments yet


Leave a comment