Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.3 CVE-2026-48517

MessagePack-CSharp: Typeless deserialization type restrictions do not recurse into arrays or generic arguments_CVE-2026-48517

MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePack-CSharp's typeless deserialization includes MessagePa...

MessagePack-CSharp MessagePack-CSharp >= 3.1.7, < 3.1.7 CVE
MEDIUM 6.3 CVE-2026-48516

MessagePack-CSharp: InterfaceLookupFormatter bypasses collision-resistant comparer settings_CVE-2026-48516

MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, InterfaceLookupFormatter constructs an internal Dictionary with ...

MessagePack-CSharp MessagePack-CSharp >= 3.1.7, < 3.1.7 CVE
MEDIUM 6.3 CVE-2026-48515

MessagePack-CSharp: Multi-dimensional array formatters allocate from unchecked dimensions_CVE-2026-48515

MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePack-CSharp's multi-dimensional array formatters read dim...

MessagePack-CSharp MessagePack-CSharp >= 3.1.7, < 3.1.7 CVE
MEDIUM 6.3 CVE-2026-48514

MessagePack-CSharp: Unity unsafe blit formatter allocates from unbounded byte length_CVE-2026-48514

MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, UnsafeBlitFormatterBase.Deserialize reads an attacker-controlled...

MessagePack-CSharp MessagePack-CSharp >= 3.1.7, < 3.1.7 CVE
MEDIUM 6.3 CVE-2026-48513

MessagePack-CSharp: DynamicUnionResolver generated deserializers miss depth enforcement_CVE-2026-48513

MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, runtime-generated union deserializers emitted by DynamicUnionRes...

MessagePack-CSharp MessagePack-CSharp >= 3.1.7, < 3.1.7 CVE
MEDIUM 6.3 CVE-2026-48512

MessagePack-CSharp: JSON conversion APIs can recurse without consistent depth enforcement_CVE-2026-48512

MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePack-CSharp's JSON conversion helpers contain multiple re...

MessagePack-CSharp MessagePack-CSharp >= 3.1.7, < 3.1.7 CVE
MEDIUM 6.3 CVE-2026-48511

MessagePack-CSharp: ExpandoObject formatter can perform quadratic insertion work on untrusted maps_CVE-2026-48511

MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, ExpandoObjectFormatter.Deserialize populates System.Dynamic.Expa...

MessagePack-CSharp MessagePack-CSharp >= 3.1.7, < 3.1.7 CVE
MEDIUM 6.3 CVE-2026-48510

MessagePack-CSharp: LZ4 decompression allocates from unbounded declared output lengths_CVE-2026-48510

MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, when MessagePack-CSharp decompresses Lz4Block or Lz4BlockArray p...

MessagePack-CSharp MessagePack-CSharp >= 3.1.7, < 3.1.7 CVE
MEDIUM 6.3 CVE-2026-48509

MessagePack-CSharp: ASP.NET Core MessagePackInputFormatter defaults to TrustedData for HTTP request bodies_CVE-2026-48509

MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, the parameterless MessagePackInputFormatter() constructor uses d...

MessagePack-CSharp MessagePack-CSharp >= 3.1.7, < 3.1.7 CVE
MEDIUM 6.5 CVE-2026-48500

Filament: Unauthenticated temporary file upload on auth pages_CVE-2026-48500

Filament is a collection of full-stack components for accelerated Laravel development. From 3.0.0 until 3.3.52, 4.11.5, and 5.6.5, any schema can c...

filamentphp filament >= 3.0.0, < 3.3.52 CVE