msgpack-java through 0.9.12 contains an integer overflow vulnerability in MessageUnpacker.skipValue() when processing MAP32 containers with large element counts. Attackers can supply a MAP32 element count at or above 0x40000000 that wraps when doubled, causing the parser cursor to desynchronize and attacker-controlled data to be returned in place of later fields.

Project Subscriptions

Vendors Products
Msgpack Subscribe
Messagepack Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sat, 12 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Description msgpack-java through 0.9.12 contains an integer overflow vulnerability in MessageUnpacker.skipValue() when processing MAP32 containers with large element counts. Attackers can supply a MAP32 element count at or above 0x40000000 that wraps when doubled, causing the parser cursor to desynchronize and attacker-controlled data to be returned in place of later fields.
Title msgpack-java through 0.9.12 Integer Overflow via MAP32
First Time appeared Msgpack
Msgpack messagepack
Weaknesses CWE-190
CPEs cpe:2.3:a:msgpack:messagepack:*:*:*:*:*:java:*:*
Vendors & Products Msgpack
Msgpack messagepack
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-12T11:06:12.224Z

Reserved: 2026-09-12T02:03:27.571Z

Link: CVE-2026-90473

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-12T11:16:34.347

Modified: 2026-09-12T11:16:34.347

Link: CVE-2026-90473

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses