Intel

AIKIDO-2026-858049

MessagePack is vulnerable to Deserialization of Untrusted Data

Deserialization of Untrusted Data Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published 5 days ago

59

Medium Risk

This Affects:

DOTNETMessagePack
1.4.0 - 2.5.198
Fixed in 2.5.205
3.0.3 - 3.1.4
Fixed in 3.1.5
Are you affected? Scan for Free

TL;DR

MessagePack's Typeless (dynamic) serialization mode resolves an embedded type name from the payload and instantiates the corresponding .NET type, gated only by the default DisallowedTypes denylist in MessagePackSerializerOptions. Before this fix, that denylist omits several classes commonly used as .NET deserialization gadgets, including ObjectDataProvider, ClaimsIdentity, and SessionSecurityToken, so untrusted MessagePack payloads processed with Typeless deserialization can instantiate those types and reach known gadget behavior. The fix adds these types to the default DisallowedTypes set so TypelessFormatter rejects them during deserialization.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you deserialize untrusted MessagePack data using Typeless (dynamic) type resolution.

Background info

MessagePack is vulnerable to Deserialization of Untrusted Data in versions 1.4.0 - 2.5.198 and 3.0.3 - 3.1.4.

How to fix this

Upgrade the MessagePack library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform