Junglewise Threat Intelligence

MessagePack for Python use after free on Unpacker reuse

Severity: high · CVSS 7.5 · Published 2026-06-19

Executive brief

MessagePack for Python is a library used to serialize and deserialize data for efficient communication between systems. A vulnerability exists where reusing a data 'Unpacker' after it encounters an error can cause the application to crash. This could allow an attacker to perform a Denial of Service (DoS) attack by sending specially crafted data that triggers an error and subsequent crash, disrupting business operations.

Technical details

A vulnerability in MessagePack for Python (msgpack) versions 1.2.0 and earlier allows for a Denial of Service (DoS) via a segmentation fault (SEGV). The issue is classified as a Use After Free (CWE-416) or out-of-bounds read that occurs when the 'Unpacker' object is reused after it has already encountered a processing error. An attacker can exploit this by providing untrusted input that triggers an initial error; if the application logic continues to use the same Unpacker instance for subsequent data, the process will crash. The vulnerability is reachable over the network if the application unpacks external data. A fix is available in version 1.2.1, and a manual workaround is to discard and replace the Unpacker instance immediately upon any error.

Affected products

  • MessagePack msgpack <= 1.2.0

Timeline

  • 2026-06-18: patched: Version 1.2.1 released
  • 2026-06-19: advisory: GitHub Advisory GHSA-6v7p-g79w-8964 published

References