Modification of assumed-immutable data in msgpack5 - #VU152777
Published: September 29, 2026
Vulnerability details
The vulnerability allows a remote attacker to modify caller-provided input data.
The vulnerability exists due to modification of assumed-immutable data in the msgpack5 decoder when decoding a negative signed 64-bit integer. A remote attacker can provide specially crafted MessagePack input to modify caller-provided input data.
Positive integers and other MessagePack value types are not affected.