Vulnerability GHSA-jr77-8gx4-h5qh
High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
3 years ago
November 11, 2022 at 12:00 PM UTC
MessagePack for Golang subject to DoS via Unmarshal panic
v2.0.0 - v2.1.0
v2.0.0 - v2.1.0
Summary
MessagePack for Golang subject to DoS via Unmarshal panic
Details
Unmarshal can panic on some inputs, possibly allowing for denial of service attacks. This issue has been patched in version 2.1.1.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Unknown
6 months ago
Denial of service in github.com/shamaton/msgpack
v2.0.0 - v2.4.2 GO-2026-4740
v2.0.0 - v2.4.2 GO-2026-4740
High Risk
6 months ago
Denial of service in github.com/shamaton/msgpack
v2.0.0 - v2.4.0 GHSA-h9q6-hc68-35rp
v2.0.0 - v2.4.0 GHSA-h9q6-hc68-35rp
Unknown
6 months ago
Denial of service in github.com/shamaton/msgpack
v2.0.0 - v2.4.0 GO-2026-4513
v2.0.0 - v2.4.0 GO-2026-4513
Unknown
3 years ago
Panic in github.com/shamaton/msgpack/v2
v2.0.0 - v2.1.0 GO-2022-0972
v2.0.0 - v2.1.0 GO-2022-0972
Impacted packages
Timeline
Published
3 years ago
November 11, 2022 at 12:00 PM UTC
Last Modified
2 years ago
November 08, 2023 at 04:10 AM UTC