
8 MessagePack for .NET advisories dropped in June 2026. CVE-2026-48109 is the headline. High severity (CVSS 8.2). Out-of-bounds read in the LZ4 path. A crafted payload crashes the process. No try/catch saves it. The fix is easy: MessagePack 2.5.301 or 3.1.7. Unless you're on .NET 6. The EOL SignalR pin freezes MessagePack at 2.1.90 — and Microsoft won't ship another serviced release. That's how end-of-life turns a one-line fix into an unreachable one. HeroDevs NES for .NET delivers the patched builds. Stay secure, migrate on your own timeline. #dotnet #CVE #OpenSourceSecurity #EndOfLife
Post summary
The advisory highlights an out‑of‑bounds read vulnerability in MessagePack for .NET and stresses upgrading to 2.5.301 or 3.1.7, or using HeroDevs patched builds to mitigate the issue.
