CVE-2026-54522
- EPSS 0.14%
- Veröffentlicht 30.07.2026 16:33:06
- Zuletzt bearbeitet 05.08.2026 19:41:34
MessagePack for Ruby is an implementation of the MessagePack binary serialization format. Prior to 1.8.2, MessagePack::Buffer#clear in ext/msgpack/buffer.c leaves rmem_last, rmem_end, and rmem_owner stale after _msgpack_buffer_shift_chunk returns an ...
CVE-2026-57585
- EPSS 0.28%
- Veröffentlicht 30.06.2026 21:36:23
- Zuletzt bearbeitet 06.08.2026 15:51:03
MessagePack is the serializer implementation for Python msgpack.org. Prior to 1.2.1, there is an Out-of-bounds read/crash on Unpacker reuse after a caught error, potentially leading to a DoS attack. If the Unpacker is used repeatedly after an error ...
CVE-2026-21452
- EPSS 0.56%
- Veröffentlicht 02.01.2026 20:47:44
- Zuletzt bearbeitet 05.02.2026 19:21:02
MessagePack for Java is a serializer implementation for Java. A denial-of-service vulnerability exists in versions prior to 0.9.11 when deserializing .msgpack files containing EXT32 objects with attacker-controlled payload lengths. While MessagePack-...