HIGH7.5
GHSA-jr77-8gx4-h5qh
MessagePack for Golang subject to DoS via Unmarshal panic
Quick fix
GHSA-jr77-8gx4-h5qh — github.com/shamaton/msgpack/v2: upgrade to the fixed version with the command below.
go get github.com/shamaton/msgpack/v2@v2.1.1Details
Unmarshal can panic on some inputs, possibly allowing for denial of service attacks. This issue has been patched in version 2.1.1.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/shamaton/msgpack/v2
Introduced in:
0Fixed in: 2.1.1Fix
go get github.com/shamaton/msgpack/v2@v2.1.1References
- https://nvd.nist.gov/vuln/detail/CVE-2022-41719[ADVISORY]
- https://github.com/shamaton/msgpack/issues/31[WEB]
- https://github.com/shamaton/msgpack/pull/32[WEB]
- https://github.com/shamaton/msgpack[PACKAGE]
- https://github.com/shamaton/msgpack/releases/tag/v2.1.1[WEB]
- https://pkg.go.dev/vuln/GO-2022-0972[WEB]