CVE-2026-48109
MessagePack-CSharp MessagePack-CSharp, messagepack
MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, A vulnerability exists in the optional LZ4 decompression path used by MessagePack compression modes Lz4Block and Lz4BlockArray. The decoder implementation is based on a deprecated fast-decompression algorithm that does not take a source-length bound. A remote attacker can send a crafted MessagePack payload with manipulated LZ4 token/length fields to force out-of-bounds reads from the compressed input buffer. In affected environments, this can trigger an AccessViolationException during decompression, causing p...
- CVSS
- 8.2
- EPSS
- 0.51% 40.6% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.23