MessagePack for C# and Unity before version 1.9.11 and 2.1.90 has a vulnerability where untrusted data can lead to DoS attack due to hash collisions and stack overflow. Review the linked GitHub Security Advisory for more information and remediation steps.
{
"versions": [
{
"introduced": "0"
},
{
"fixed": "1.9.3"
},
{
"introduced": "2.0.323"
},
{
"fixed": "2.1.80"
},
{
"introduced": "0"
},
{
"last_affected": "2.0.94-alpha"
},
{
"introduced": "0"
},
{
"last_affected": "2.0.110-alpha"
},
{
"introduced": "0"
},
{
"last_affected": "2.0.119-beta"
},
{
"introduced": "0"
},
{
"last_affected": "2.0.123-beta"
},
{
"introduced": "0"
},
{
"last_affected": "2.0.204-beta"
},
{
"introduced": "0"
},
{
"last_affected": "2.0.270-rc"
},
{
"introduced": "0"
},
{
"last_affected": "2.0.299-rc"
}
]
}