top of page
perceptive_background_267k.jpg

MessagePack is the serializer implementation for Python msgpack.org. Prior to 1.2.1, there is an Out-of-bounds read/crash on Unpacker reuse after a caught error…

Published:

29 juni 2026 om 22:00:00

Alert date:

30 juni 2026 om 23:02:21

Source:

nvd.nist.gov

Click to open the original link from this advisory

Supply Chain & Dependencies, Web Technologies

A vulnerability exists in the Python MessagePack serializer library (msgpack-python) prior to version 1.2.1. The flaw is an out-of-bounds read that occurs when the Unpacker object is reused after a caught error. Repeated use of the Unpacker following an error can cause the process to crash with a segmentation fault (SEGV). This behavior can potentially be exploited to conduct a Denial of Service (DoS) attack. The vulnerability has been assigned CVE-2026-57585. A fix has been released in version 1.2.1 of the library. Users are advised to upgrade to version 1.2.1 or later to mitigate this issue. The fix is available via the official GitHub repository commit and was disclosed through GitHub Security Advisories.

Technical details

Mitigation steps:

Affected products:

msgpack-python (versions prior to 1.2.1)

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page