Impact
msgpack-java versions up to 0.9.12 implement a recursive unpacking routine that processes arrays and maps without restricting the depth of nesting. When an attacker sends a MessagePack payload with many nested array or map until the Java thread’s stack is exhausted, raising a StackOverflowError. This condition terminates the current request and can cause the application to hang or fail to process further requests that share the same thread, leading to a denial‑of‑service effect for that request.
Affected Systems
Any Java application that includes msgpack-java version 0.9.12 or earlier and performs deserialization of external MessagePack data is vulnerable. Commonly used Java services, frameworks, or application components that rely on this library for data exchange are impacted.
Risk and Exploitability
The CVSS score of 6.9 denotes moderate severity, while the EPSS score of less than 1% indicates a very low likelihood of exploitation. The vulnerability is not present in CISA’s KEV catalog, and no publicly reported exploits exist. The likely attack vector is remote network: an attacker can craft a malicious MessagePack payload and send it to any endpoint that performs deserialization. No special privileges are required; the exploit simply triggers a stack overflow, causing the affected request to abort and possibly affecting other requests that share the same processing thread.
OpenCVE Enrichment