LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-48109

messagepack · messagepack

Published
CVSS8.2
Severityhigh
WeaknessCWE-20
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H

Description

MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, A vulnerability exists in the optional LZ4 decompression path used by MessagePack compression modes Lz4Block and Lz4BlockArray. The decoder implementation is based on a deprecated fast-decompression algorithm that does not take a source-length bound. A remote attacker can send a crafted MessagePack payload with manipulated LZ4 token/length fields to force out-of-bounds reads from the compressed input buffer. In affected environments, this can trigger an AccessViolationException during decompression, causing process termination (denial of service). Under some conditions, limited unintended memory disclosure fro

References

← Back to the CVE Tracker

Our coverage of CVE-2026-48109

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-48109.