Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-91746.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-91746
Upstream
Published
2026-06-30T22:16:57Z
Modified
2026-09-01T05:28:09Z
Summary
CVE-2026-57585 affecting package python-msgpack for versions less than 1.0.5-3
Details

MessagePack is the serializer implementation for Python msgpack.org. Prior to 1.2.1, there is an Out-of-bounds read/crash on Unpacker reuse after a caught error, potentially leading to a DoS attack. If the Unpacker is used repeatedly after an error occurs, the process may crash with a SEGV. This issue has been fixed in version 1.2.1.

References

Affected packages

Azure Linux:3 / python-msgpack

Package

Name
python-msgpack
Purl
pkg:rpm/azure-linux/python-msgpack

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0.5-3

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-91746.json"