Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS1qcjc3LThneDQtaDVxaM4AAv0s

MessagePack for Golang subject to DoS via Unmarshal panic

Unmarshal can panic on some inputs, possibly allowing for denial of service attacks. This issue has been patched in version 2.1.1.

Permalink: https://github.com/advisories/GHSA-jr77-8gx4-h5qh
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1qcjc3LThneDQtaDVxaM4AAv0s
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: 11 months ago
Updated: about 1 month ago


CVSS Score: 7.5
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Identifiers: GHSA-jr77-8gx4-h5qh, CVE-2022-41719
References:

Affected Packages

go:github.com/shamaton/msgpack/v2
Versions: < 2.1.1
Fixed in: 2.1.1