Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

MessagePack-CSharp — Vulnerabilities & Security Advisories 13

Browse all 13 CVE security advisories affecting MessagePack-CSharp. AI-powered Chinese analysis, POCs, and references for each vulnerability.

This page catalogs security vulnerabilities associated with the MessagePack-CSharp vendor for the .NET serialization library. It focuses on weakness classifications that impact the integrity and reliability of data exchange in applications relying on this specific package. The content aggregates known security issues, tracking the historical and current state of flaws discovered within the software. The collection encompasses a broad spectrum of vulnerability types, including but not limited to buffer overflows, deserialization issues, and improper input validation errors. This dataset covers vulnerabilities reported from the initial release of the library through the most recent advisories, ensuring a comprehensive view of the security landscape over time. By consolidating these records, the page serves as a centralized resource for understanding the risk profile of the MessagePack-CSharp implementation across different versions. Visitors to this resource can efficiently track vendor advisories to stay informed about critical patches and updates. It also facilitates a deeper understanding of specific weakness classes by providing context on how they manifest in this particular library. Furthermore, users can look up the vulnerability history of the product to assess past exposures and determine if their current version remains susceptible to known exploits, thereby supporting more informed risk management decisions.

Top products by MessagePack-CSharp: MessagePack-CSharp
CVE IDTitleCVSSSeverityPublished
CVE-2026-48109 MessagePack-CSharp: LZ4 decompression may fail with AccessViolationException after dereferencing memory from bad input — MessagePack-CSharpCWE-20 8.2 High2026-06-22
CVE-2026-48502 MessagePack-CSharp: Denial of service vulnerabilities can swamp the CPU or crash the process with stack and heap overflows — MessagePack-CSharpCWE-125--2026-06-22
CVE-2026-48506 MessagePack-CSharp: MessagePackReader.Skip can recurse without enforcing maximum object graph depth — MessagePack-CSharpCWE-674 7.5 High2026-06-22
CVE-2026-48509 MessagePack-CSharp: ASP.NET Core MessagePackInputFormatter defaults to TrustedData for HTTP request bodies — MessagePack-CSharpCWE-1188--2026-06-22
CVE-2026-48510 MessagePack-CSharp: LZ4 decompression allocates from unbounded declared output lengths — MessagePack-CSharpCWE-409--2026-06-22
CVE-2026-48511 MessagePack-CSharp: ExpandoObject formatter can perform quadratic insertion work on untrusted maps — MessagePack-CSharpCWE-407--2026-06-22
CVE-2026-48512 MessagePack-CSharp: JSON conversion APIs can recurse without consistent depth enforcement — MessagePack-CSharpCWE-674--2026-06-22
CVE-2026-48513 MessagePack-CSharp: DynamicUnionResolver generated deserializers miss depth enforcement — MessagePack-CSharpCWE-674--2026-06-22
CVE-2026-48514 MessagePack-CSharp: Unity unsafe blit formatter allocates from unbounded byte length — MessagePack-CSharpCWE-770--2026-06-22
CVE-2026-48515 MessagePack-CSharp: Multi-dimensional array formatters allocate from unchecked dimensions — MessagePack-CSharpCWE-770--2026-06-22
CVE-2026-48516 MessagePack-CSharp: InterfaceLookupFormatter bypasses collision-resistant comparer settings — MessagePack-CSharpCWE-407--2026-06-22
CVE-2026-48517 MessagePack-CSharp: Typeless deserialization type restrictions do not recurse into arrays or generic arguments — MessagePack-CSharpCWE-470--2026-06-22
CVE-2024-48924 MessagePack allows untrusted data to lead to DoS attack due to hash collisions and stack overflow — MessagePack-CSharpCWE-328 7.5AIHighAI2024-10-17

This page lists every published CVE security advisory associated with MessagePack-CSharp. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.