MessagePack-CSharp: ASP.NET Core MessagePackInputFormatter defaults to TrustedData for HTTP request bodies
Modified: 6/25/2026
package
pkg:nuget/MessagePack
MessagePack-CSharp: ASP.NET Core MessagePackInputFormatter defaults to TrustedData for HTTP request bodies
Modified: 6/25/2026
MessagePack-CSharp: ExpandoObject formatter can perform quadratic insertion work on untrusted maps
Modified: 6/25/2026
MessagePack-CSharp: Denial of service vulnerabilities can swamp the CPU or crash the process with stack and heap overflows
Modified: 6/25/2026
MessagePack allows untrusted data to lead to DoS attack due to hash collisions and stack overflow
Modified: 9/10/2026
Untrusted data can lead to DoS attack due to hash collisions and stack overflow in MessagePack
Modified: 9/10/2026
MessagePack-CSharp: JSON conversion APIs can recurse without consistent depth enforcement
Modified: 6/25/2026
MessagePack-CSharp: Multi-dimensional array formatters allocate from unchecked dimensions
Modified: 6/25/2026
MessagePack's LZ4 decompression may fail with AccessViolationException after dereferencing memory from bad input
Modified: 9/10/2026
MessagePack-CSharp: InterfaceLookupFormatter bypasses collision-resistant comparer settings
Modified: 6/25/2026
MessagePack-CSharp: Typeless deserialization type restrictions do not recurse into arrays or generic arguments
Modified: 6/25/2026
MessagePack-CSharp: LZ4 decompression allocates from unbounded declared output lengths
Modified: 6/25/2026
MessagePack-CSharp: MessagePackReader.Skip can recurse without enforcing maximum object graph depth
Modified: 6/25/2026
MessagePack-CSharp: Unity unsafe blit formatter allocates from unbounded byte length
Modified: 6/25/2026
MessagePack-CSharp: DynamicUnionResolver-generated deserializers miss depth enforcement
Modified: 6/25/2026