Executive brief
MessagePack for Python is a library used to serialize and deserialize data for efficient communication between systems. A vulnerability exists where reusing a data 'Unpacker' after it encounters an error can cause the application to crash. This could allow an attacker to perform a Denial of Service (DoS) attack by sending specially crafted data that triggers an error and subsequent crash, disrupting business operations.
Technical details
A vulnerability in MessagePack for Python (msgpack) versions 1.2.0 and earlier allows for a Denial of Service (DoS) via a segmentation fault (SEGV). The issue is classified as a Use After Free (CWE-416) or out-of-bounds read that occurs when the 'Unpacker' object is reused after it has already encountered a processing error. An attacker can exploit this by providing untrusted input that triggers an initial error; if the application logic continues to use the same Unpacker instance for subsequent data, the process will crash. The vulnerability is reachable over the network if the application unpacks external data. A fix is available in version 1.2.1, and a manual workaround is to discard and replace the Unpacker instance immediately upon any error.
Affected products
- MessagePack msgpack <= 1.2.0
Timeline
- 2026-06-18: patched: Version 1.2.1 released
- 2026-06-19: advisory: GitHub Advisory GHSA-6v7p-g79w-8964 published
References
- https://github.com/msgpack/msgpack-python/security/advisories/GHSA-6v7p-g79w-8964
- https://github.com/msgpack/msgpack-python/commit/2c56ddb5d0025ed481d962c0f5d62d19dec7476d
- https://github.com/msgpack/msgpack-python/releases/tag/v1.2.1
- https://api.github.com/repos/msgpack/msgpack-python/security-advisories/GHSA-6v7p-g79w-8964