Vulnerability GHSA-h9q6-hc68-35rp
High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
6 months ago
March 18, 2026 at 12:59 PM UTC
Denial of service in github.com/shamaton/msgpack
v2.0.0 - v2.4.0
v2.0.0 - v2.4.0
Summary
Denial of service in github.com/shamaton/msgpack
Details
The msgpack decoder fails to properly validate the input buffer length when processing truncated fixext data (format codes 0xd4-0xd8). This can lead to an out-of-bounds read and a runtime panic, allowing a denial of service attack.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Unknown
6 months ago
Denial of service in github.com/shamaton/msgpack
v3.0.0 - v3.2.3 GO-2026-4740
v3.0.0 - v3.2.3 GO-2026-4740
Unknown
6 months ago
Denial of service in github.com/shamaton/msgpack
v3.0.0 - v3.2.3 GO-2026-4740
v3.0.0 - v3.2.3 GO-2026-4740
Unknown
6 months ago
Denial of service in github.com/shamaton/msgpack
v3.0.0 - v3.1.0 GO-2026-4513
v3.0.0 - v3.1.0 GO-2026-4513
Unknown
6 months ago
Denial of service in github.com/shamaton/msgpack
v3.0.0 - v3.1.0 GO-2026-4513
v3.0.0 - v3.1.0 GO-2026-4513
High Risk
3 years ago
MessagePack for Golang subject to DoS via Unmarshal panic
v2.0.0 - v2.1.0 GHSA-jr77-8gx4-h5qh
v2.0.0 - v2.1.0 GHSA-jr77-8gx4-h5qh
Impacted packages
Timeline
Published
6 months ago
March 18, 2026 at 12:59 PM UTC
Last Modified
3 hours ago
October 07, 2026 at 05:56 PM UTC