HIGH7.5
GHSA-h9q6-hc68-35rp
Denial of service in github.com/shamaton/msgpack
Details
The msgpack decoder fails to properly validate the input buffer length when processing truncated fixext data (format codes 0xd4-0xd8). This can lead to an out-of-bounds read and a runtime panic, allowing a denial of service attack.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/shamaton/msgpack/v2
Introduced in:
0No fixed version published yet for github.com/shamaton/msgpack/v2 (go modules). Pin to a known-safe version or switch to an alternative.
Go/github.com/shamaton/msgpack/v3
Introduced in:
0No fixed version published yet for github.com/shamaton/msgpack/v3 (go modules). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2026-32284[ADVISORY]
- https://github.com/golang/vulndb/issues/4513[WEB]
- https://github.com/shamaton/msgpack/issues/59[WEB]
- https://github.com/shamaton/msgpack[PACKAGE]
- https://pkg.go.dev/vuln/GO-2026-4513[WEB]
- https://securityinfinity.com/research/shamaton-msgpack-oob-panic-fixext-dos-2026[WEB]