MessagePack for Golang subject to DoS via Unmarshal panic
High severity
GitHub Reviewed
Published
Nov 11, 2022
to the GitHub Advisory Database
•
Updated Aug 30, 2023
Description
Published by the National Vulnerability Database
Nov 10, 2022
Published to the GitHub Advisory Database
Nov 11, 2022
Reviewed
Nov 16, 2022
Last updated
Aug 30, 2023
Unmarshal can panic on some inputs, possibly allowing for denial of service attacks. This issue has been patched in version 2.1.1.
References