{"id":"GHSA-hv8m-jj95-wg3x","summary":" MessagePack's LZ4 decompression may fail with AccessViolationException after dereferencing memory from bad input","details":"### Impact\n\nA vulnerability exists in the optional LZ4 decompression path used by MessagePack compression modes `Lz4Block` and `Lz4BlockArray`.\n\nThe decoder implementation is based on a deprecated fast-decompression algorithm that does not take a source-length bound. A remote attacker can send a crafted MessagePack payload with manipulated LZ4 token/length fields to force out-of-bounds reads from the compressed input buffer. In affected environments, this can trigger an `AccessViolationException` during decompression, causing process termination (denial of service). Under some conditions, limited unintended memory disclosure from over-read data may also be possible before failure.\n\nThis issue affects applications that deserialize untrusted data while LZ4 compression is enabled.\n\n### Patches\n\nThe v2 versions are patched as of 2.5.301.\nThe v3 versions are patched as of 3.1.7.\n\n### Workarounds\n\nInstead of upgrading, an application may take the following precautions:\n\n1. Disable LZ4 compression for untrusted input paths (`Lz4Block`, `Lz4BlockArray`).\n2. Only accept compressed payloads from strongly trusted producers.\n3. Isolate deserialization in a separate process/container with restart supervision to limit availability impact.\n\n### Resources\n\n- MESSAGEPACKCSHARP-010","aliases":["CVE-2026-48109"],"modified":"2026-07-17T21:11:31.055689226Z","published":"2026-06-11T20:34:10Z","database_specific":{"cwe_ids":["CWE-20"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-06-11T20:34:10Z","nvd_published_at":"2026-06-22T22:16:46Z"},"references":[{"type":"WEB","url":"https://github.com/MessagePack-CSharp/MessagePack-CSharp/security/advisories/GHSA-hv8m-jj95-wg3x"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48109"},{"type":"PACKAGE","url":"https://github.com/MessagePack-CSharp/MessagePack-CSharp"}],"affected":[{"package":{"name":"MessagePack","ecosystem":"NuGet","purl":"pkg:nuget/MessagePack"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.5.301"}]}],"versions":["0.1.0-beta","0.2.0-beta","0.2.1-beta","0.2.2-beta","0.2.3-beta","0.3.0-beta","0.4.0","0.4.1","0.4.2","0.5.0","0.6.0","0.6.1","0.7.0","0.7.2","0.8.0","0.8.1","0.8.2","0.8.3","0.8.4","0.8.5","1.0.0","1.0.1","1.0.2","1.0.3","1.1.0","1.1.1","1.1.1.1","1.1.2","1.2.0","1.2.0.1","1.2.0.2","1.2.1","1.2.2","1.2.3","1.3.0","1.3.1","1.3.1.1","1.3.2","1.3.3","1.4.0","1.4.1","1.4.2","1.4.3","1.4.4","1.5.0","1.5.0.1","1.5.0.2","1.5.1","1.6.0","1.6.0.1","1.6.0.2","1.6.0.3","1.6.1","1.6.1.1","1.6.1.2","1.6.2","1.7.0","1.7.1","1.7.2","1.7.3","1.7.3.1","1.7.3.2","1.7.3.3","1.7.3.4","1.7.3.7","1.8.71-beta","1.8.74","1.8.80","1.9.11","1.9.3","1.9.3-g129239b107","2.0.107-alpha","2.0.108-alpha","2.0.110-alpha","2.0.110-alpha-g1e44a9106f","2.0.119-beta","2.0.123-beta","2.0.171-beta","2.0.204-beta","2.0.221-beta","2.0.231-rc","2.0.270-rc","2.0.299-rc","2.0.323","2.0.335","2.1.115","2.1.143","2.1.152","2.1.165","2.1.194","2.1.80","2.1.90","2.2.113","2.2.36-alpha","2.2.44-rc","2.2.60","2.2.85","2.3.112","2.3.58-alpha","2.3.73-alpha","2.3.75","2.3.85","2.4.14-alpha","2.4.23-alpha","2.4.35","2.4.59","2.5.103","2.5.108","2.5.124","2.5.129","2.5.140","2.5.168","2.5.171","2.5.172","2.5.187","2.5.192","2.5.198","2.5.205","2.5.64-alpha","2.5.94"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-hv8m-jj95-wg3x/GHSA-hv8m-jj95-wg3x.json"}},{"package":{"name":"MessagePack","ecosystem":"NuGet","purl":"pkg:nuget/MessagePack"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.0.214-rc.1"},{"fixed":"3.1.7"}]}],"versions":["3.0.300","3.0.308","3.1.0","3.1.1","3.1.2","3.1.3","3.1.4","3.1.5","3.1.6"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-hv8m-jj95-wg3x/GHSA-hv8m-jj95-wg3x.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"}]}