CVE-2026-48109Patch(messagepack / messagepack)

LOWCVSS 8.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch messagepack messagepack systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, A vulnerability exists in the optional LZ4 decompression path used by MessagePack compression modes Lz4Block and Lz4BlockArray. The decoder implementation is based on a deprecated fast-decompression algorithm that does not take a source-length bound. A remote attacker can send a crafted MessagePack payload with manipulated LZ4 token/length fields to force out-of-bounds reads from the compressed input buffer. In affected environments, this can trigger an AccessViolationException during decompression, causing process termination (denial of service). Under some conditions, limited unintended memory disclosure from over-read data may also be possible before failure. This vulnerability is fixed in 2.5.301 and 3.1.7.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • messagepack

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Products
messagepack

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-08: 1Patch / Workaround · 2026-07-08: 1Technical Details · 2026-07-08: 107-08
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • HeroDevs@herodevs
    Patch

    8 MessagePack for .NET advisories dropped in June 2026. CVE-2026-48109 is the headline. High severity (CVSS 8.2). Out-of-bounds read in the LZ4 path. A crafted payload crashes the process. No try/catch saves it. The fix is easy: MessagePack 2.5.301 or 3.1.7. Unless you're on .NET 6. The EOL SignalR pin freezes MessagePack at 2.1.90 — and Microsoft won't ship another serviced release. That's how end-of-life turns a one-line fix into an unreachable one. HeroDevs NES for .NET delivers the patched builds. Stay secure, migrate on your own timeline. #dotnet #CVE #OpenSourceSecurity #EndOfLife

    Post summary

    The advisory highlights an out‑of‑bounds read vulnerability in MessagePack for .NET and stresses upgrading to 2.5.301 or 3.1.7, or using HeroDevs patched builds to mitigate the issue.

    00000135
    2.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmessagepackmessagepack-c\#-

Explore more