Junglewise Threat Intelligence

CVE-2026-88350: MPack integer overflow in string allocation functions

CVE-2026-88350 · Severity: info · Published 2026-09-22

Executive brief

MPack is a lightweight data serialization library used in applications that process MessagePack format data. An integer overflow in string allocation functions can cause a heap buffer overflow, potentially leading to memory corruption, information disclosure, or code execution when processing specially crafted input.

Technical details

An integer overflow vulnerability exists in mpack_node_cstr_alloc() and mpack_node_utf8_cstr_alloc() functions in MPack 1.1.1, where a uint32 overflow in length calculation (len+1) results in undersized buffer allocation. The vulnerability can be triggered remotely by sending a malicious MessagePack message with a crafted string length, allowing heap buffer overflow on both 32-bit and 64-bit platforms. A fix was implemented by adding overflow checks in the affected allocation functions.

Affected products

  • ludocode MPack 1.1.1

Timeline

  • 2026-09-22: disclosed
  • 2026-08-06: patched

References