Vulnerability GO-2026-4513
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
6 months ago
March 16, 2026 at 08:27 PM UTC
Denial of service in github.com/shamaton/msgpack
v0.9.0 - v1.2.1
v0.9.0 - v1.2.1
Summary
Denial of service in github.com/shamaton/msgpack
Details
The msgpack decoder fails to properly validate the input buffer length when processing truncated fixext data (format codes 0xd4-0xd8). This can lead to an out-of-bounds read and a runtime panic, allowing a denial of service attack.
References
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Unknown
6 months ago
Denial of service in github.com/shamaton/msgpack
v3.0.0 - v3.2.3 GO-2026-4740
v3.0.0 - v3.2.3 GO-2026-4740
Unknown
6 months ago
Denial of service in github.com/shamaton/msgpack
v3.0.0 - v3.2.3 GO-2026-4740
v3.0.0 - v3.2.3 GO-2026-4740
Unknown
6 months ago
Denial of service in github.com/shamaton/msgpack
v3.0.0 - v3.2.3 GO-2026-4740
v3.0.0 - v3.2.3 GO-2026-4740
High Risk
6 months ago
Denial of service in github.com/shamaton/msgpack
v3.0.0 - v3.1.0 GHSA-h9q6-hc68-35rp
v3.0.0 - v3.1.0 GHSA-h9q6-hc68-35rp
High Risk
6 months ago
Denial of service in github.com/shamaton/msgpack
v3.0.0 - v3.1.0 GHSA-h9q6-hc68-35rp
v3.0.0 - v3.1.0 GHSA-h9q6-hc68-35rp
Impacted packages
Timeline
Published
6 months ago
March 16, 2026 at 08:27 PM UTC
Last Modified
3 hours ago
October 07, 2026 at 05:56 PM UTC