14 Total advisories
14 Vulnerabilities
0 Malware
Dependency scanning
Check whether MessagePack is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 8.2
CVE-2026-48109
MessagePack's LZ4 decompression may fail with AccessViolationException after dereferencing memory from bad input
UNKNOWN
CVE-2024-48924
MessagePack allows untrusted data to lead to DoS attack due to hash collisions and stack overflow
MEDIUM 4.8
CVE-2020-5234
Untrusted data can lead to DoS attack due to hash collisions and stack overflow in MessagePack
UNKNOWN
CVE-2026-48517
MessagePack-CSharp: Typeless deserialization type restrictions do not recurse into arrays or generic arguments
UNKNOWN
CVE-2026-48516
MessagePack-CSharp: InterfaceLookupFormatter bypasses collision-resistant comparer settings
UNKNOWN
CVE-2026-48513
MessagePack-CSharp: DynamicUnionResolver-generated deserializers miss depth enforcement
UNKNOWN
CVE-2026-48515
MessagePack-CSharp: Multi-dimensional array formatters allocate from unchecked dimensions
UNKNOWN
CVE-2026-48514
MessagePack-CSharp: Unity unsafe blit formatter allocates from unbounded byte length
UNKNOWN
CVE-2026-48512
MessagePack-CSharp: JSON conversion APIs can recurse without consistent depth enforcement
HIGH 7.5
CVE-2026-48511
MessagePack-CSharp: ExpandoObject formatter can perform quadratic insertion work on untrusted maps
HIGH 7.5
CVE-2026-48506
MessagePack-CSharp: MessagePackReader.Skip can recurse without enforcing maximum object graph depth
UNKNOWN
CVE-2026-48509
MessagePack-CSharp: ASP.NET Core MessagePackInputFormatter defaults to TrustedData for HTTP request bodies
HIGH 7.5
CVE-2026-48510
MessagePack-CSharp: LZ4 decompression allocates from unbounded declared output lengths
UNKNOWN
CVE-2026-48502
MessagePack-CSharp: Denial of service vulnerabilities can swamp the CPU or crash the process with stack and heap overflows
Browse more NuGet advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes