CVE-2026-90472

Source
https://cve.org/CVERecord?id=CVE-2026-90472
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90472.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-90472
Downstream
Published
2026-09-12T11:06:11Z
Modified
2026-09-16T03:30:53Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
msgpack-java through 0.9.12 Stack Overflow via Nested Arrays
Details

msgpack-java through 0.9.12 contains a stack overflow vulnerability in MessageUnpacker.unpackValue() that recursively deserializes arrays and maps without nesting depth limits. Attackers can craft payloads with deeply nested arrays to exhaust the deserializing thread's stack and trigger StackOverflowError, causing per-request deserialization failures.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-674"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90472.json"
}
References

Affected packages

Git / github.com/msgpack/msgpack-java

Affected ranges

Type
GIT
Repo
https://github.com/msgpack/msgpack-java
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "0.9.12"
        },
        {
            "fixed": "0.9.12"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ]
}

Affected versions

0.*
0.7.0
0.7.0-M6
0.7.0-p4
0.7.0-p5
0.7.0-p6
0.7.0-p7
0.7.0-p8
0.7.0-p9
0.7.1
0.8.0
0.8.1
0.8.10
0.8.11
0.8.12
0.8.13
0.8.14
0.8.15
0.8.16
0.8.17
0.8.18
0.8.19
0.8.2
0.8.20
0.8.21
0.8.22
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
msgpack-0.*
msgpack-0.6.2
msgpack-0.6.4
msgpack-0.6.5
msgpack-0.6.6
msgpack-0.6.7
msgpack-0.6.8
v0.*
v0.8.15
v0.8.22
v0.8.23
v0.8.24
v0.9.0
v0.9.1
v0.9.10
v0.9.11
v0.9.2
v0.9.3
v0.9.4
v0.9.5
v0.9.6
v0.9.7
v0.9.8
v0.9.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90472.json"