Affected versions of this crate pre-allocate memory on deserializing raw buffers without checking whether there is sufficient data available.
This allows an attacker to do denial-of-service attacks by sending small msgpack messages that allocate gigabytes of memory.
{ "license": "CC0-1.0" }