MessagePack for C# and Unity before version 1.9.11 and 2.1.90 has a vulnerability where untrusted data can lead to DoS attack due to hash collisions and stack overflow. Review the linked GitHub Security Advisory for more information and remediation steps.
{
"unresolved_ranges": [
{
"cpes": [
"cpe:2.3:a:messagepack:messagepack:*:*:*:*:*:c\\#:*:*",
"cpe:2.3:a:messagepack:messagepack:2.0.110:alpha:*:*:*:c\\#:*:*",
"cpe:2.3:a:messagepack:messagepack:2.0.119:beta:*:*:*:c\\#:*:*",
"cpe:2.3:a:messagepack:messagepack:2.0.123:beta:*:*:*:c\\#:*:*",
"cpe:2.3:a:messagepack:messagepack:2.0.204:beta:*:*:*:c\\#:*:*",
"cpe:2.3:a:messagepack:messagepack:2.0.270:rc:*:*:*:c\\#:*:*",
"cpe:2.3:a:messagepack:messagepack:2.0.299:rc:*:*:*:c\\#:*:*",
"cpe:2.3:a:messagepack:messagepack:2.0.94:alpha:*:*:*:c\\#:*:*"
],
"source": "CPE_FIELD",
"vendor_product": "messagepack:messagepack",
"extracted_events": [
{
"fixed": "1.9.3"
},
{
"introduced": "2.0.323"
},
{
"fixed": "2.1.80"
},
{
"last_affected": "2.0.94-alpha"
},
{
"last_affected": "2.0.110-alpha"
},
{
"last_affected": "2.0.119-beta"
},
{
"last_affected": "2.0.123-beta"
},
{
"last_affected": "2.0.204-beta"
},
{
"last_affected": "2.0.270-rc"
},
{
"last_affected": "2.0.299-rc"
}
]
}
]
}