Intel

AIKIDO-2026-487768

MessagePack is vulnerable to Regular Expression Denial of Service (ReDoS)

Regular Expression Denial of Service (ReDoS)GHSA-fx6j-x9m5-vmrf Published 4 days ago

59

Medium Risk

This Affects:

DOTNETMessagePack
2.1.115 - 2.5.303
Fixed in 2.5.305
3.0 - 3.1.9
Fixed in 3.1.10
Are you affected? Scan for Free

TL;DR

MessagePack's AssemblyNameVersionSelectorRegex field in MessagePackSerializerOptions uses unescaped . metacharacters between the \d+ groups that strip assembly version metadata from type names during deserialization. When AllowAssemblyVersionMismatch is enabled, a type name with a long digit run after , Version= forces the regex engine through O(N^3) backtracking, and a single crafted payload of a few kilobytes blocks a thread for minutes. A small number of concurrent payloads exhausts the thread pool and denies service to legitimate requests. The fix escapes the dot metacharacters so each version segment matches a literal period instead of triggering backtracking.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you enable AllowAssemblyVersionMismatch on MessagePackSerializerOptions while deserializing type names from untrusted input.

Background info

MessagePack is vulnerable to Regular Expression Denial of Service (ReDoS) in versions 2.1.115 - 2.5.303 and 3.0 - 3.1.9.

How to fix this

Upgrade the MessagePack library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform