๐Ÿ” CVE Alert

CVE-2026-48512

UNKNOWN 0.0

MessagePack-CSharp: JSON conversion APIs can recurse without consistent depth enforcement

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePack-CSharp's JSON conversion helpers contain multiple recursion paths that do not consistently enforce a depth limit. These paths are in the JSON conversion component rather than normal typed MessagePack deserialization. MessagePackSerializer.ConvertFromJson recursively processes nested JSON arrays and objects in FromJsonCore() without consulting MessagePackSecurity.MaximumObjectGraphDepth. TinyJsonReader.ReadNextToken() recursively consumes comma and colon separator characters, allowing even malformed JSON with long separator runs to consume one stack frame per character. MessagePackSerializer.ConvertToJson applies depth checks to arrays and maps, but the typeless extension branch for ext-100 recursively calls ToJsonCore() without applying MessagePackSecurity.DepthStep(ref reader). Each path can allow attacker-controlled input to exhaust the process stack and trigger an uncatchable StackOverflowException instead of failing with a catchable parse or serialization exception. This vulnerability is fixed in 2.5.301 and 3.1.7.

CWE CWE-674
Vendor messagepack-csharp
Product messagepack-csharp
Published Jun 22, 2026
Stay Ahead of the Next One

Get instant alerts for messagepack-csharp messagepack-csharp

Be the first to know when new unknown vulnerabilities affecting messagepack-csharp messagepack-csharp are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

MessagePack-CSharp / MessagePack-CSharp
>= 3.1.7, < 3.1.7 < 2.5.301

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/MessagePack-CSharp/MessagePack-CSharp/security/advisories/GHSA-cj9g-3mj2-g8vv