CVE 6.3 MEDIUM

MessagePack-CSharp: InterfaceLookupFormatter bypasses collision-resistant comparer settings_CVE-2026-48516

6.3 / 10
MEDIUM
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Description

MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, InterfaceLookupFormatter<TKey,TElement> constructs an internal Dictionary<TKey, IGrouping<TKey,TElement>> with the default equality comparer instead of the security-aware comparer supplied by options.Security.GetEqualityComparer<TKey>(). This formatter omission allows hash-collision CPU denial of service against ILookup<TKey,TElement> even when the application has opted into the untrusted-data security posture This vulnerability is fixed in 2.5.301 and 3.1.7.

Basic Information

ID CVE-2026-48516
Source GitHub_M
Published Jun 22, 2026 at 21:09

Affected Product

Vendor MessagePack-CSharp
Product MessagePack-CSharp
Version >= 3.1.7, < 3.1.7
Affected Versions MessagePack-CSharp MessagePack-CSharp >= 3.1.7, < 3.1.7
MessagePack-CSharp MessagePack-CSharp < 2.5.301

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.