Msgpack is a serialization library providing a compact binary message format, with vulnerability exposure centered on its core messagepack implementation. The durable signal reflects memory-handling concerns typical of serialization libraries, with observed weaknesses including excessive memory allocation, resource-consumption issues, and parsing edge cases that arise from accepting and deserializing untrusted input. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Msgpack over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-21452HIGH MessagePack for Java is a serializer implementation for Java. A denial-of-service vulnerability exists in versions prior to 0.9.11 when deserializing .msgpack files containing EXT3 | Jan 2, 2026 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Msgpack.
Media articles that mention a CVE ID that affects a product developed by Msgpack — matched by CVE ID, not by vendor name.