nuget

MessagePack

View on nuget registry
14 Total advisories
14 Vulnerabilities
0 Malware

Dependency scanning

Check whether MessagePack is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

HIGH 8.2
NuGet

CVE-2026-48109

MessagePack's LZ4 decompression may fail with AccessViolationException after dereferencing memory from bad input

UNKNOWN
NuGet

CVE-2024-48924

MessagePack allows untrusted data to lead to DoS attack due to hash collisions and stack overflow

MEDIUM 4.8
NuGet

CVE-2020-5234

Untrusted data can lead to DoS attack due to hash collisions and stack overflow in MessagePack

UNKNOWN
NuGet

CVE-2026-48517

MessagePack-CSharp: Typeless deserialization type restrictions do not recurse into arrays or generic arguments

UNKNOWN
NuGet

CVE-2026-48516

MessagePack-CSharp: InterfaceLookupFormatter bypasses collision-resistant comparer settings

UNKNOWN
NuGet

CVE-2026-48513

MessagePack-CSharp: DynamicUnionResolver-generated deserializers miss depth enforcement

UNKNOWN
NuGet

CVE-2026-48515

MessagePack-CSharp: Multi-dimensional array formatters allocate from unchecked dimensions

UNKNOWN
NuGet

CVE-2026-48514

MessagePack-CSharp: Unity unsafe blit formatter allocates from unbounded byte length

UNKNOWN
NuGet

CVE-2026-48512

MessagePack-CSharp: JSON conversion APIs can recurse without consistent depth enforcement

HIGH 7.5
NuGet

CVE-2026-48511

MessagePack-CSharp: ExpandoObject formatter can perform quadratic insertion work on untrusted maps

HIGH 7.5
NuGet

CVE-2026-48506

MessagePack-CSharp: MessagePackReader.Skip can recurse without enforcing maximum object graph depth

UNKNOWN
NuGet

CVE-2026-48509

MessagePack-CSharp: ASP.NET Core MessagePackInputFormatter defaults to TrustedData for HTTP request bodies

HIGH 7.5
NuGet

CVE-2026-48510

MessagePack-CSharp: LZ4 decompression allocates from unbounded declared output lengths

UNKNOWN
NuGet

CVE-2026-48502

MessagePack-CSharp: Denial of service vulnerabilities can swamp the CPU or crash the process with stack and heap overflows

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes