CVE-2022-41719

MessagePack for Golang subject to DoS via Unmarshal panic in go/github.com/shamaton/msgpack/v2

Identifiers

GHSA-jr77-8gx4-h5qh, CVE-2022-41719

Package Slug

go/github.com/shamaton/msgpack/v2

Vulnerability

MessagePack for Golang subject to DoS via Unmarshal panic

Description

Unmarshal can panic on some inputs, possibly allowing for denial of service attacks.

Affected Versions

All versions before 2.1.1

Solution

Upgrade to version 2.1.1 or above.

Last Modified

2022-11-17

source