Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

MessagePack-CSharp — Vulnerabilities & Security Advisories 13

Browse all 13 CVE security advisories affecting MessagePack-CSharp. AI-powered Chinese analysis, POCs, and references for each vulnerability.

This page aggregates security vulnerability data for the MessagePack-CSharp library, a .NET implementation of the MessagePack serialization format. The collection covers identified security flaws within the library across its supported versions, spanning a timeline from early public releases through the most recent advisories. Readers can utilize this resource to track the vendor’s security advisories, analyze the prevalence of specific weakness classes such as deserialization issues or denial of state conditions, and review the complete vulnerability history associated with this product. By centralizing these records, the page provides a structured view of the library’s security posture, allowing developers and security analysts to assess exposure risks and prioritize remediation efforts based on historical patterns and current threat landscapes. The data reflects confirmed weaknesses reported in public databases, offering insights into the evolving security challenges faced by serialization libraries in the .NET ecosystem. This overview serves as a reference point for understanding the long-term security trajectory of MessagePack-CSharp and its implications for applications relying on efficient binary data formats.

Found 13 results / 13 Clear Filters
Top products by MessagePack-CSharp: MessagePack-CSharp
CVE ID Title CVSS Severity Published
CVE-2026-48109 MessagePack-CSharp: LZ4 decompression may fail with AccessViolationException after dereferencing memory from bad input — MessagePack-CSharp CWE-20 8.2 High 2026-06-22
CVE-2026-48502 MessagePack-CSharp: Denial of service vulnerabilities can swamp the CPU or crash the process with stack and heap overflows — MessagePack-CSharp CWE-125 - - 2026-06-22
CVE-2026-48506 MessagePack-CSharp: MessagePackReader.Skip can recurse without enforcing maximum object graph depth — MessagePack-CSharp CWE-674 7.5 High 2026-06-22
CVE-2026-48509 MessagePack-CSharp: ASP.NET Core MessagePackInputFormatter defaults to TrustedData for HTTP request bodies — MessagePack-CSharp CWE-1188 - - 2026-06-22
CVE-2026-48510 MessagePack-CSharp: LZ4 decompression allocates from unbounded declared output lengths — MessagePack-CSharp CWE-409 - - 2026-06-22
CVE-2026-48511 MessagePack-CSharp: ExpandoObject formatter can perform quadratic insertion work on untrusted maps — MessagePack-CSharp CWE-407 - - 2026-06-22
CVE-2026-48512 MessagePack-CSharp: JSON conversion APIs can recurse without consistent depth enforcement — MessagePack-CSharp CWE-674 - - 2026-06-22
CVE-2026-48513 MessagePack-CSharp: DynamicUnionResolver generated deserializers miss depth enforcement — MessagePack-CSharp CWE-674 - - 2026-06-22
CVE-2026-48514 MessagePack-CSharp: Unity unsafe blit formatter allocates from unbounded byte length — MessagePack-CSharp CWE-770 - - 2026-06-22
CVE-2026-48515 MessagePack-CSharp: Multi-dimensional array formatters allocate from unchecked dimensions — MessagePack-CSharp CWE-770 - - 2026-06-22
CVE-2026-48516 MessagePack-CSharp: InterfaceLookupFormatter bypasses collision-resistant comparer settings — MessagePack-CSharp CWE-407 - - 2026-06-22
CVE-2026-48517 MessagePack-CSharp: Typeless deserialization type restrictions do not recurse into arrays or generic arguments — MessagePack-CSharp CWE-470 - - 2026-06-22
CVE-2024-48924 MessagePack allows untrusted data to lead to DoS attack due to hash collisions and stack overflow — MessagePack-CSharp CWE-328 7.5AI High AI 2024-10-17

This page lists every published CVE security advisory associated with MessagePack-CSharp. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.