Description
msgpack-java through 0.9.12 contains a stack overflow vulnerability in MessageUnpacker.unpackValue() that recursively deserializes arrays and maps without nesting depth limits. Attackers can craft payloads with deeply nested arrays to exhaust the deserializing thread's stack and trigger StackOverflowError, causing per-request deserialization failures.
Published: 2026-09-12
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via stack exhaustion
Action: Patch
AI Analysis

Impact

msgpack-java versions up to 0.9.12 implement a recursive unpacking routine that processes arrays and maps without restricting the depth of nesting. When an attacker sends a MessagePack payload with many nested array or map until the Java thread’s stack is exhausted, raising a StackOverflowError. This condition terminates the current request and can cause the application to hang or fail to process further requests that share the same thread, leading to a denial‑of‑service effect for that request.

Affected Systems

Any Java application that includes msgpack-java version 0.9.12 or earlier and performs deserialization of external MessagePack data is vulnerable. Commonly used Java services, frameworks, or application components that rely on this library for data exchange are impacted.

Risk and Exploitability

The CVSS score of 6.9 denotes moderate severity, while the EPSS score of less than 1% indicates a very low likelihood of exploitation. The vulnerability is not present in CISA’s KEV catalog, and no publicly reported exploits exist. The likely attack vector is remote network: an attacker can craft a malicious MessagePack payload and send it to any endpoint that performs deserialization. No special privileges are required; the exploit simply triggers a stack overflow, causing the affected request to abort and possibly affecting other requests that share the same processing thread.

Generated by OpenCVE AI on September 15, 2026 at 18:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update to the newest available version of msgpack-java that contains a fix for nested array depth limits, if one has been released; if a suitable patch is not publicly available, consult the vendor for a security update.
  • Implement input validation to measure the depth of incoming MessagePack payloads and reject any that exceed a defined safe threshold before invoking the unpacking routine.
  • Enforce rate limiting or isolate MessagePack processing in a dedicated thread pool with constrained stack size, so that a single malicious request cannot exhaust the stack of threads shared by other requests.

Generated by OpenCVE AI on September 15, 2026 at 18:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 12 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Description msgpack-java through 0.9.12 contains a stack overflow vulnerability in MessageUnpacker.unpackValue() that recursively deserializes arrays and maps without nesting depth limits. Attackers can craft payloads with deeply nested arrays to exhaust the deserializing thread's stack and trigger StackOverflowError, causing per-request deserialization failures.
Title msgpack-java through 0.9.12 Stack Overflow via Nested Arrays
First Time appeared Msgpack
Msgpack messagepack
Weaknesses CWE-674
CPEs cpe:2.3:a:msgpack:messagepack:*:*:*:*:*:java:*:*
Vendors & Products Msgpack
Msgpack messagepack
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Msgpack Messagepack
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:21:43.291Z

Reserved: 2026-09-12T02:03:23.163Z

Link: CVE-2026-90472

cve-icon Vulnrichment

Updated: 2026-09-14T16:08:03.626Z

cve-icon NVD

Status : Deferred

Published: 2026-09-12T11:16:34.180

Modified: 2026-09-23T17:17:47.347

Link: CVE-2026-90472

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T18:30:14Z

Weaknesses