Executive brief
A vulnerability in the MessagePack-CSharp library could allow an attacker to cause a denial-of-service (DoS) condition by overwhelming a system's CPU. This occurs when the library processes specially crafted data that bypasses security settings intended to prevent hash-collision attacks. If exploited, this could lead to significant application slowdowns or service outages, impacting business operations and availability.
Technical details
The InterfaceLookupFormatter<TKey, TElement> in MessagePack-CSharp fails to use the security-aware equality comparer provided by the application's configuration, defaulting instead to a standard comparer. This vulnerability belongs to the Inefficient Algorithmic Complexity (CWE-407) class. An attacker can exploit this by providing a serialized payload containing many keys that result in hash collisions, degrading dictionary insertion performance from constant time to quadratic time. This bypasses the protections intended by the MessagePackSecurity.UntrustedData setting. The issue is fixed in versions 2.5.301 and 3.1.7.
Affected products
- MessagePack-CSharp MessagePack-CSharp < 2.5.301, >= 3.0, < 3.1.7
Timeline
- 2026-06-09: disclosed
- 2026-06-22: advisory: NVD publication date
- 2026-06-25: patched: GitHub Advisory reviewed and updated with patch information