CVE-2026-48502
EUVD-2026-3838922.06.2026, 22:16
MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePackReader.ReadDateTime() can allocate stack memory based on an attacker-controlled MessagePack extension length. In the slow path for timestamp extension parsing, the computed tokenSize includes the extension body length from the wire and is used in a stackalloc operation before the extension length is validated as one of the valid timestamp sizes. A very small payload can claim a large timestamp extension body and cause a stack allocation large enough to trigger an uncatchable StackOverflowException, terminating the host process. This vulnerability is fixed in 2.5.301 and 3.1.7.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| messagepack | messagepack | 𝑥 < 2.5.301 |
| messagepack | messagepack | 3.0.3 ≤ 𝑥 < 3.1.7 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration