CVE-2026-48511: fallo de gravedad media en MessagePack-CSharp
MessagePack-CSharp: ExpandoObject formatter can perform quadratic insertion work on untrusted maps
Publicada el · Actualizada el
13Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 6.3epss 0.4%
probabilidad de explotación
0.4%top 67% de las CVE
explotación observada
noninguna fuente lo reporta
MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, ExpandoObjectFormatter.Deserialize populates System.Dynamic.ExpandoObject by calling IDictionary<string, object>.Add for each map entry. ExpandoObject internally maintains member names in array-like structures, so inserting many distinct keys can require repeated linear scans and array copies. For large attacker-controlled maps, this produces quadratic CPU and allocation behavior. The issue is especially surprising because ExpandoObjectResolver.Options is configured with MessagePackSecurity.UntrustedData, but collision-resistant dictionary comparers cannot protect ExpandoObject insertion internals. This vulnerability is fixed in 2.5.301 and 3.1.7.
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Productos afectados
MessagePack-CSharp · MessagePack-CSharpCVEs relacionadas — MessagePack-CSharp
En el mismo producto, de las más peligrosas a las menos.
CVE-2026-48109HIGHMessagePack-CSharp: LZ4 decompression may fail with AccessViolationException after dereferencing memory from bad inputEPSS 0.5%CVE-2026-48506HIGHMessagePack-CSharp: MessagePackReader.Skip can recurse without enforcing maximum object graph depthEPSS 0.5%CVE-2026-48502HIGHMessagePack-CSharp: Denial of service vulnerabilities can swamp the CPU or crash the process with stack and heap overflowsEPSS 0.4%CVE-2026-48509MEDIUMMessagePack-CSharp: ASP.NET Core MessagePackInputFormatter defaults to TrustedData for HTTP request bodiesEPSS 0.4%CVE-2026-48510MEDIUMMessagePack-CSharp: LZ4 decompression allocates from unbounded declared output lengthsEPSS 0.4%CVE-2026-48512MEDIUMMessagePack-CSharp: JSON conversion APIs can recurse without consistent depth enforcementEPSS 0.4%