GHSA-mx67-wv8x-hvv9

Suggest an improvement
Source
https://github.com/advisories/GHSA-mx67-wv8x-hvv9
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/07/GHSA-mx67-wv8x-hvv9/GHSA-mx67-wv8x-hvv9.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-mx67-wv8x-hvv9
Aliases
  • CVE-2021-23410
Withdrawn
2021-09-15T19:12:25Z
Published
2021-07-26T21:24:09Z
Modified
2026-09-10T03:49:15Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Deserialization of Untrusted Data in msgpack
Details

Withdrawn

This advisory was withdrawn by its CNA (Snyk).

Original advisory

All versions of package msgpack are vulnerable to Deserialization of Untrusted Data via the unpack function. This does not affect the similarly named package @msgpack/msgpack.

Database specific
{
    "cwe_ids":  [
        "CWE-502"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2021-07-26T17:38:45Z",
    "nvd_published_at":  "2021-07-21T17:15:00Z",
    "severity":  "CRITICAL"
}
References

Affected packages

npm / msgpack

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
1.0.3

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/07/GHSA-mx67-wv8x-hvv9/GHSA-mx67-wv8x-hvv9.json"