Improper Handling of Syntactically Invalid Structure in msgpack5 - #VU152781
Published: September 29, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper handling of syntactically invalid structure in the msgpack5 streaming decoder when processing a decoder stream beginning with the reserved MessagePack byte 0xc1. A remote attacker can supply a stream beginning with 0xc1 followed by additional data to cause a denial of service.