← Vulnerability feed

Vulnerability record · CVE-2020-5234 · published 31 January 2020

CVE-2020-5234: Messagepack stack-based buffer overflow vulnerability

Messagepack · Messagepack

MessagePack for C# and Unity before version 1.9.11 and 2.1.90 has a vulnerability where untrusted data can lead to DoS attack due to hash collisions and stack overflow. Review the linked GitHub Security Advisory for more information and remediation steps.

6.5 CVSS 3.1 Medium EPSS 1.6% · top 25.5% CWE-121 · Stack-based buffer overflowCWE-787 · Out-of-bounds write
6.5CVSS 3.1 base score, v2 6.8
1.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

MessagePack for C# and Unity before version 1.9.11 and 2.1.90 has a vulnerability where untrusted data can lead to DoS attack due to hash collisions and stack overflow. Review the linked GitHub Security Advisory for more information and remediation steps.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-5234 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.2CVE-2026-48502Messagepack out-of-bounds read vulnerabilityMessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePackReader.ReadDateTime() can allocate stack memory based o…EPSS 0.44%8.2CVE-2026-48109Messagepack improper input validation vulnerabilityMessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, A vulnerability exists in the optional LZ4 decompression path used…EPSS 0.51%7.5CVE-2026-48506Messagepack vulnerabilityMessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePackReader.TrySkip() recursively descends into nested array…EPSS 0.47%6.3CVE-2026-48513Messagepack vulnerabilityMessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, runtime-generated union deserializers emitted by DynamicUnionResol…EPSS 0.40%6.3CVE-2026-48514Messagepack allocation without limits vulnerabilityMessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, UnsafeBlitFormatterBase<T>.Deserialize reads an attacker-controlle…EPSS 0.40%6.3CVE-2026-48515Messagepack allocation without limits vulnerabilityMessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePack-CSharp's multi-dimensional array formatters read dimen…EPSS 0.40%6.3CVE-2026-48516Messagepack vulnerabilityMessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, InterfaceLookupFormatter<TKey,TElement> constructs an internal Dic…EPSS 0.40%6.3CVE-2026-48517Messagepack deserialization of untrusted data vulnerabilityMessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePack-CSharp's typeless deserialization includes MessagePack…EPSS 0.35%

Source: NIST National Vulnerability Database (record CVE-2020-5234), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.