CVE-2026-48502

Severity CVSS v4.0:
HIGH
Type:
CWE-125 Out-of-bounds Read
Publication date:
22/06/2026
Last modified:
23/06/2026

Description

MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePackReader.ReadDateTime() can allocate stack memory based on an attacker-controlled MessagePack extension length. In the slow path for timestamp extension parsing, the computed tokenSize includes the extension body length from the wire and is used in a stackalloc operation before the extension length is validated as one of the valid timestamp sizes. A very small payload can claim a large timestamp extension body and cause a stack allocation large enough to trigger an uncatchable StackOverflowException, terminating the host process. This vulnerability is fixed in 2.5.301 and 3.1.7.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:messagepack:messagepack:*:*:*:*:*:c\#:*:* 2.5.301 (excluding)
cpe:2.3:a:messagepack:messagepack:*:*:*:*:*:c\#:*:* 3.0.3 (including) 3.1.7 (excluding)