MessagePack is vulnerable to Regular Expression Denial of Service (ReDoS)
59
Medium Risk
MessagePack's AssemblyNameVersionSelectorRegex field in MessagePackSerializerOptions uses unescaped . metacharacters between the \d+ groups that strip assembly version metadata from type names during deserialization. When AllowAssemblyVersionMismatch is enabled, a type name with a long digit run after , Version= forces the regex engine through O(N^3) backtracking, and a single crafted payload of a few kilobytes blocks a thread for minutes. A small number of concurrent payloads exhausts the thread pool and denies service to legitimate requests. The fix escapes the dot metacharacters so each version segment matches a literal period instead of triggering backtracking.
You are affected if you are using a version that falls within the vulnerable range and you enable AllowAssemblyVersionMismatch on MessagePackSerializerOptions while deserializing type names from untrusted input.
MessagePack is vulnerable to Regular Expression Denial of Service (ReDoS) in versions 2.1.115 - 2.5.303 and 3.0 - 3.1.9.
Upgrade the MessagePack library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.