


Perceptive Security
SOC/SIEM Consultancy

MessagePack is the serializer implementation for Python msgpack.org. Prior to 1.2.1, there is an Out-of-bounds read/crash on Unpacker reuse after a caught error…
Published:
29 juni 2026 om 22:00:00
Alert date:
30 juni 2026 om 23:02:21
Source:
nvd.nist.gov
Supply Chain & Dependencies, Web Technologies
A vulnerability exists in the Python MessagePack serializer library (msgpack-python) prior to version 1.2.1. The flaw is an out-of-bounds read that occurs when the Unpacker object is reused after a caught error. Repeated use of the Unpacker following an error can cause the process to crash with a segmentation fault (SEGV). This behavior can potentially be exploited to conduct a Denial of Service (DoS) attack. The vulnerability has been assigned CVE-2026-57585. A fix has been released in version 1.2.1 of the library. Users are advised to upgrade to version 1.2.1 or later to mitigate this issue. The fix is available via the official GitHub repository commit and was disclosed through GitHub Security Advisories.
Technical details
Mitigation steps:
Affected products:
msgpack-python (versions prior to 1.2.1)
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-57585
https://github.com/msgpack/msgpack-python/commit/2c56ddb5d0025ed481d962c0f5d62d19dec7476d
https://github.com/msgpack/msgpack-python/security/advisories/GHSA-6v7p-g79w-8964
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
