CVE-2026-32284

HIGH

Denial of service in github.com/shamaton/msgpack

Title source: cna
STIX 2.1

Description

The msgpack decoder fails to properly validate the input buffer length when processing truncated fixext data (format codes 0xd4-0xd8). This can lead to an out-of-bounds read and a runtime panic, allowing a denial of service attack.

Scores

CVSS v3 7.5
EPSS 0.0038
EPSS Percentile 29.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-125
Status published
Products (5)
github.com/shamaton/msgpack/github.com/shamaton/msgpack
github.com/shamaton/msgpack/v2/github.com/shamaton/msgpack/v2
github.com/shamaton/msgpack/v3/github.com/shamaton/msgpack/v3
shamaton/msgpack < 3.1.2
shamaton/msgpack 0 (2 CPE variants)Go
Published Mar 26, 2026
Tracked Since Mar 27, 2026