MEDIUM

CVE-2026-90473

2026-09-12 CVSS v3.1
CVSS
5.3

Description

msgpack-java through 0.9.12 contains an integer overflow vulnerability in MessageUnpacker.skipValue() when processing MAP32 containers with large element counts. Attackers can supply a MAP32 element count at or above 0x40000000 that wraps when doubled, causing the parser cursor to desynchronize and attacker-controlled data to be returned in place of later fields.

Weakness (CWE)

CWE-190 Integer Overflow

EPSS Score

0.24%
Probability of exploitation in next 30 days
15.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE