CVE-2026-48510: medium-severity vulnerability in MessagePack-CSharp
MessagePack-CSharp: LZ4 decompression allocates from unbounded declared output lengths
Published · Updated
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.3epss 0.4%
exploitation probability
0.4%top 67% of all CVEs
observed exploitation
nono source reports it
MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, when MessagePack-CSharp decompresses Lz4Block or Lz4BlockArray payloads, it reads declared uncompressed lengths from the wire and allocates output buffers based on those lengths before validating that the compressed data is valid or that the declared expansion is reasonable. A small payload can claim a very large uncompressed length and force a large allocation before LZ4 decoding begins. This vulnerability is fixed in 2.5.301 and 3.1.7.
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Affected products
MessagePack-CSharp · MessagePack-CSharpRelated CVEs — MessagePack-CSharp
In the same product, most dangerous first.
CVE-2026-48109HIGHMessagePack-CSharp: LZ4 decompression may fail with AccessViolationException after dereferencing memory from bad inputEPSS 0.5%CVE-2026-48506HIGHMessagePack-CSharp: MessagePackReader.Skip can recurse without enforcing maximum object graph depthEPSS 0.5%CVE-2026-48502HIGHMessagePack-CSharp: Denial of service vulnerabilities can swamp the CPU or crash the process with stack and heap overflowsEPSS 0.4%CVE-2026-48509MEDIUMMessagePack-CSharp: ASP.NET Core MessagePackInputFormatter defaults to TrustedData for HTTP request bodiesEPSS 0.4%CVE-2026-48511MEDIUMMessagePack-CSharp: ExpandoObject formatter can perform quadratic insertion work on untrusted mapsEPSS 0.4%CVE-2026-48512MEDIUMMessagePack-CSharp: JSON conversion APIs can recurse without consistent depth enforcementEPSS 0.4%