Messagepack is a compact binary serialization library whose vulnerability footprint is centered on its single core product and dominated by memory-safety issues including out-of-bounds writes and stack-based buffer overflows, typical of parsing-oriented code that handles untrusted input. Current exploitation activity, severity breakdown, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Messagepack over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-48509CRITICAL MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, the parameterless MessagePackInputFormatter() constructor uses default serializer options, which | Jun 22, 2026 | 9.1 | 36 | NO | NO |
CVE-2026-48109HIGH MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, A vulnerability exists in the optional LZ4 decompression path used by MessagePack compression mod | Jun 22, 2026 | 8.2 | 33 | NO | NO |
CVE-2026-48502HIGH MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePackReader.ReadDateTime() can allocate stack memory based on an attacker-controlled Messag | Jun 22, 2026 | 7.5 | 32 | NO | NO |
CVE-2026-48506HIGH MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePackReader.TrySkip() recursively descends into nested arrays and maps without incrementing | Jun 22, 2026 | 7.5 | 31 | NO | NO |
CVE-2026-48510HIGH MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, when MessagePack-CSharp decompresses Lz4Block or Lz4BlockArray payloads, it reads declared uncomp | Jun 22, 2026 | 7.5 | 31 | NO | NO |
CVE-2026-48511HIGH MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, ExpandoObjectFormatter.Deserialize populates System.Dynamic.ExpandoObject by calling IDictionary< | Jun 22, 2026 | 7.5 | 30 | NO | NO |
CVE-2026-48512HIGH MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePack-CSharp's JSON conversion helpers contain multiple recursion paths that do not consist | Jun 22, 2026 | 7.5 | 30 | NO | NO |
CVE-2026-48513HIGH MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, runtime-generated union deserializers emitted by DynamicUnionResolver do not call MessagePackSecu | Jun 22, 2026 | 7.5 | 30 | NO | NO |
CVE-2026-48515HIGH MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePack-CSharp's multi-dimensional array formatters read dimension lengths directly from the | Jun 22, 2026 | 7.5 | 30 | NO | NO |
CVE-2026-48516HIGH MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, InterfaceLookupFormatter<TKey,TElement> constructs an internal Dictionary<TKey, IGrouping<TKey,TE | Jun 22, 2026 | 7.5 | 30 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Messagepack.
Media articles that mention a CVE ID that affects a product developed by Messagepack — matched by CVE ID, not by vendor name.