Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

MessagePack-CSharp — Vulnerabilities & Security Advisories 13

All 13 CVE vulnerabilities found in MessagePack-CSharp, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known vulnerabilities and weaknesses associated with the MessagePack-CSharp library, a popular serialization format for .NET. The current collection encompasses security flaws ranging from critical remote code execution risks to lower-severity configuration errors discovered between 2020 and 2024. By consolidating data from multiple advisory sources, this resource provides a unified view of the threat landscape affecting this specific component. Readers can track vendor advisories to stay informed about patches and mitigations for newly disclosed issues. The structured presentation allows developers to deeply understand specific weakness classes, such as deserialization flaws or injection attacks, that commonly impact MessagePack implementations. Furthermore, users can look up the comprehensive vulnerability history of MessagePack-CSharp to assess the long-term security posture of the library. This historical context is essential for conducting thorough risk assessments during application development or dependency audits. The page is designed to support security professionals and developers in making informed decisions about library adoption and upgrade timelines. It serves as a reference point for identifying patterns in reported defects and understanding the evolution of security fixes over time. Access to this aggregated information helps reduce the time required to cross-reference disparate sources. Ultimately, this page aims to enhance transparency and facilitate proactive security management for users relying on MessagePack-CSharp in their software ecosystems.

Vendor: MessagePack-CSharp

CVE ID Title CVSS Severity Published
CVE-2026-48109 MessagePack-CSharp: LZ4 decompression may fail with AccessViolationException after dereferencing memory from bad input CWE-20 8.2 High 2026-06-22
CVE-2026-48502 MessagePack-CSharp: Denial of service vulnerabilities can swamp the CPU or crash the process with stack and heap overflows CWE-125 - - 2026-06-22
CVE-2026-48506 MessagePack-CSharp: MessagePackReader.Skip can recurse without enforcing maximum object graph depth CWE-674 7.5 High 2026-06-22
CVE-2026-48509 MessagePack-CSharp: ASP.NET Core MessagePackInputFormatter defaults to TrustedData for HTTP request bodies CWE-1188 - - 2026-06-22
CVE-2026-48510 MessagePack-CSharp: LZ4 decompression allocates from unbounded declared output lengths CWE-409 - - 2026-06-22
CVE-2026-48511 MessagePack-CSharp: ExpandoObject formatter can perform quadratic insertion work on untrusted maps CWE-407 - - 2026-06-22
CVE-2026-48512 MessagePack-CSharp: JSON conversion APIs can recurse without consistent depth enforcement CWE-674 - - 2026-06-22
CVE-2026-48513 MessagePack-CSharp: DynamicUnionResolver generated deserializers miss depth enforcement CWE-674 - - 2026-06-22
CVE-2026-48514 MessagePack-CSharp: Unity unsafe blit formatter allocates from unbounded byte length CWE-770 - - 2026-06-22
CVE-2026-48515 MessagePack-CSharp: Multi-dimensional array formatters allocate from unchecked dimensions CWE-770 - - 2026-06-22
CVE-2026-48516 MessagePack-CSharp: InterfaceLookupFormatter bypasses collision-resistant comparer settings CWE-407 - - 2026-06-22
CVE-2026-48517 MessagePack-CSharp: Typeless deserialization type restrictions do not recurse into arrays or generic arguments CWE-470 - - 2026-06-22
CVE-2024-48924 MessagePack allows untrusted data to lead to DoS attack due to hash collisions and stack overflow CWE-328 7.5AI High AI 2024-10-17

All 13 known CVE vulnerabilities affecting MessagePack-CSharp with full Chinese analysis, references, and POCs where available.