msgpack CVE Vulnerabilities & CVE List (1)

Products (CPE): — CVEs: 1

msgpack vulnerability overview

This page aggregates publicly disclosed CVE and security risk information related to msgpack, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.

Vulnerability distribution trend (last 24 months)

Showing 11 of 1 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2026-21452 MessagePack for Java is a serializer implementation for Java. A denial-of-service vulnerability exists in versions prior to 0.9.11 when deserializing .msgpack files containing EXT32 objects with attacker-controlled payload lengths. While MessagePack-Java parses extension headers lazily, it later trusts the declared EXT payload length when materializing the extension data. When ExtensionValue.getData() is invoked, the library attempts to allocate a byte array of the declared length without enforc [email protected] 7.5 0.02% 2026-01-02 2026-02-05
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence