Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Messagepack Project

First CVE: Jan 31, 2020Active for: 6 yearsTotal CVEs: 14

MessagePack Project maintains a serialization library used across polyglot systems and embedded in many data-interchange and RPC frameworks, despite its narrow product footprint. The limited disclosure record centers on the core MessagePack product and carries minimal structural signal beyond serialization-layer data handling; live severity, exploitation, and coverage details are shown alongside this summary.

FAUCET AI Generated
14
Total CVEs
Bottom 1%
4.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
7.6
Avg CVSS Score
Higher Avg CVSS Score than 57% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Messagepack Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 31, 2020
6 years ago
Most Recent CVE
Jun 22, 2026
32 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-48509CRITICAL
MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, the parameterless MessagePackInputFormatter() constructor uses default serializer options, which
Jun 22, 20269.136NONO
CVE-2026-48109HIGH
MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, A vulnerability exists in the optional LZ4 decompression path used by MessagePack compression mod
Jun 22, 20268.233NONO
CVE-2026-48502HIGH
MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePackReader.ReadDateTime() can allocate stack memory based on an attacker-controlled Messag
Jun 22, 20267.532NONO
CVE-2026-48506HIGH
MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePackReader.TrySkip() recursively descends into nested arrays and maps without incrementing
Jun 22, 20267.531NONO
CVE-2026-48510HIGH
MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, when MessagePack-CSharp decompresses Lz4Block or Lz4BlockArray payloads, it reads declared uncomp
Jun 22, 20267.531NONO
CVE-2026-48511HIGH
MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, ExpandoObjectFormatter.Deserialize populates System.Dynamic.ExpandoObject by calling IDictionary<
Jun 22, 20267.530NONO
CVE-2026-48512HIGH
MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePack-CSharp's JSON conversion helpers contain multiple recursion paths that do not consist
Jun 22, 20267.530NONO
CVE-2026-48513HIGH
MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, runtime-generated union deserializers emitted by DynamicUnionResolver do not call MessagePackSecu
Jun 22, 20267.530NONO
CVE-2026-48515HIGH
MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePack-CSharp's multi-dimensional array formatters read dimension lengths directly from the
Jun 22, 20267.530NONO
CVE-2026-48516HIGH
MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, InterfaceLookupFormatter<TKey,TElement> constructs an internal Dictionary<TKey, IGrouping<TKey,TE
Jun 22, 20267.530NONO
View all 14 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products14 CVEs
86%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network14 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None14 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low1 (7.1%)
High0 (0.0%)
None13 (92.9%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Messagepack Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Messagepack Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Messagepack Project's Products

View all 2 CNAs →