Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-90472

Опубликовано: 12 сент. 2026
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

msgpack-java through 0.9.12 contains a stack overflow vulnerability in MessageUnpacker.unpackValue() that recursively deserializes arrays and maps without nesting depth limits. Attackers can craft payloads with deeply nested arrays to exhaust the deserializing thread's stack and trigger StackOverflowError, causing per-request deserialization failures.

EPSS

Процентиль: 26%
0.00333
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-674

Связанные уязвимости

CVSS3: 5.3
ubuntu
5 дней назад

msgpack-java through 0.9.12 contains a stack overflow vulnerability in MessageUnpacker.unpackValue() that recursively deserializes arrays and maps without nesting depth limits. Attackers can craft payloads with deeply nested arrays to exhaust the deserializing thread's stack and trigger StackOverflowError, causing per-request deserialization failures.

CVSS3: 5.3
debian
5 дней назад

msgpack-java through 0.9.12 contains a stack overflow vulnerability in ...

CVSS3: 5.3
github
5 дней назад

msgpack-java through 0.9.12 contains a stack overflow vulnerability in MessageUnpacker.unpackValue() that recursively deserializes arrays and maps without nesting depth limits. Attackers can craft payloads with deeply nested arrays to exhaust the deserializing thread's stack and trigger StackOverflowError, causing per-request deserialization failures.

EPSS

Процентиль: 26%
0.00333
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-674