Skip to content

CVE-2026-48109 (High) detected in messagepack.3.1.4.nupkg #40

Description

@mend-bolt-for-github

CVE-2026-48109 - High Severity Vulnerability

Vulnerable Library - messagepack.3.1.4.nupkg

Extremely Fast MessagePack(MsgPack) Serializer for C# (.NET Framework, .NET 6, Unity, Xamarin).

Library home page: https://api.nuget.org/packages/messagepack.3.1.4.nupkg

Path to dependency file: /src/SharpConnector.Tests/SharpConnector.Tests.csproj

Path to vulnerable library: /home/wss-scanner/.nuget/packages/messagepack/3.1.4/messagepack.3.1.4.nupkg,/home/wss-scanner/.nuget/packages/messagepack/3.1.4/messagepack.3.1.4.nupkg,/home/wss-scanner/.nuget/packages/messagepack/3.1.4/messagepack.3.1.4.nupkg

Dependency Hierarchy:

  • enyimmemcachedcore.3.5.0.nupkg (Root Library)
    • messagepack.3.1.4.nupkg (Vulnerable Library)

Found in base branch: develop

Vulnerability Details

MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, A vulnerability exists in the optional LZ4 decompression path used by MessagePack compression modes Lz4Block and Lz4BlockArray. The decoder implementation is based on a deprecated fast-decompression algorithm that does not take a source-length bound. A remote attacker can send a crafted MessagePack payload with manipulated LZ4 token/length fields to force out-of-bounds reads from the compressed input buffer. In affected environments, this can trigger an AccessViolationException during decompression, causing process termination (denial of service). Under some conditions, limited unintended memory disclosure from over-read data may also be possible before failure. This vulnerability is fixed in 2.5.301 and 3.1.7.

Publish Date: 2026-06-22

URL: CVE-2026-48109

CVSS 3 Score Details (8.2)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: Low
    • Integrity Impact: None
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-hv8m-jj95-wg3x

Release Date: 2026-06-11

Fix Resolution: messagepack - 2.5.301,messagepack - 3.1.7


Step up your Open Source Security Game with Mend here

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions