CVE-2026-32284

The msgpack decoder fails to properly validate the input buffer length when processing truncated fixext data (format codes 0xd4-0xd8). This can lead to an out-of-bounds read and a runtime panic, allowing a denial of service attack.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:shamaton:msgpack:*:*:*:*:*:go:*:*

History

No history.

Information

Published : 2026-03-26 20:16

Updated : 2026-06-17 10:35


NVD link : CVE-2026-32284

Mitre link : CVE-2026-32284

CVE.ORG link : CVE-2026-32284


JSON object : View

Products Affected

shamaton

  • msgpack
CWE
CWE-125

Out-of-bounds Read