Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h5hr-vppv-v9cg

Опубликовано: 12 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.9
CVSS3: 5.3

Описание

msgpack-java through 0.9.12 contains a stack overflow vulnerability in MessageUnpacker.unpackValue() that recursively deserializes arrays and maps without nesting depth limits. Attackers can craft payloads with deeply nested arrays to exhaust the deserializing thread's stack and trigger StackOverflowError, causing per-request deserialization failures.

msgpack-java through 0.9.12 contains a stack overflow vulnerability in MessageUnpacker.unpackValue() that recursively deserializes arrays and maps without nesting depth limits. Attackers can craft payloads with deeply nested arrays to exhaust the deserializing thread's stack and trigger StackOverflowError, causing per-request deserialization failures.

EPSS

Процентиль: 26%
0.00333
Низкий

6.9 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-674

Связанные уязвимости

CVSS3: 5.3
ubuntu
5 дней назад

msgpack-java through 0.9.12 contains a stack overflow vulnerability in MessageUnpacker.unpackValue() that recursively deserializes arrays and maps without nesting depth limits. Attackers can craft payloads with deeply nested arrays to exhaust the deserializing thread's stack and trigger StackOverflowError, causing per-request deserialization failures.

CVSS3: 5.3
nvd
5 дней назад

msgpack-java through 0.9.12 contains a stack overflow vulnerability in MessageUnpacker.unpackValue() that recursively deserializes arrays and maps without nesting depth limits. Attackers can craft payloads with deeply nested arrays to exhaust the deserializing thread's stack and trigger StackOverflowError, causing per-request deserialization failures.

CVSS3: 5.3
debian
5 дней назад

msgpack-java through 0.9.12 contains a stack overflow vulnerability in ...

EPSS

Процентиль: 26%
0.00333
Низкий

6.9 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-674