FlawAtlas
Search the atlas
CVE-2026-32284 High

Denial of service in github.com/shamaton/msgpack

Denial of service in github.com/shamaton/msgpack

Exploit probability 0.4%
Published March 23, 2026
Required by Not available
Last source change May 29, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

3 explicit affected versions

Go github.com/shamaton/msgpack
Go github.com/shamaton/msgpack/v2
Go github.com/shamaton/msgpack/v3
Go github.com/shamaton/msgpack
Go github.com/shamaton/msgpack/v2
Go github.com/shamaton/msgpack/v3
Go github.com/shamaton/msgpack/v2
Go github.com/shamaton/msgpack/v3

03 / CONNECTIONS

Connected vulnerabilities

related OPENSUSE-SU-2026:21483-1

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2026-32284

The msgpack decoder fails to properly validate the input buffer length when processing truncated fixext data (format codes 0xd4-0xd8). This can lead to an out-of-bounds read and a runtime panic, allowing a denial of service attack.

View original source
Open Source Vulnerabilities GHSA-h9q6-hc68-35rp

The msgpack decoder fails to properly validate the input buffer length when processing truncated fixext data (format codes 0xd4-0xd8). This can lead to an out-of-bounds read and a runtime panic, allowing a denial of service attack.

View original source
Open Source Vulnerabilities GO-2026-4513

The msgpack decoder fails to properly validate the input buffer length when processing truncated fixext data (format codes 0xd4-0xd8). This can lead to an out-of-bounds read and a runtime panic, allowing a denial of service attack.

View original source

05 / REFERENCES

Further evidence