<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T13:55:14.766224+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-330327</id>
    <title>EUVD-2026-330327</title>
    <updated>2026-10-06T13:55:14.813641+00:00</updated>
    <content>EUVD-2026-330327</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-330327"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-48515</id>
    <title>fkie_cve-2026-48515</title>
    <updated>2026-10-06T13:55:14.813679+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePack-CSharp's multi-dimensional array formatters read dimension lengths directly from the payload and allocate T[,], T[,,], or T[,,,] before validating that the dimension product matches the encoded element count. The formatter reads a guarded element array header, but allocation of the target multi-dimensional array happens before the dimensions are checked against that element count. A small payload can therefore declare large dimensions, provide an empty or tiny inner array, and cause a large heap allocation before element data is validated. This vulnerability is fixed in 2.5.301 and 3.1.7.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-48515"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-cxmj-83gh-fp49</id>
    <title>GHSA-cxmj-83gh-fp49 — MessagePack-CSharp: Multi-dimensional array formatters allocate from unchecked dimensions</title>
    <updated>2026-10-06T13:55:14.813716+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> NuGet: MessagePack</p>
<p>## Summary</p>
<p>MessagePack-CSharp's multi-dimensional array formatters read dimension lengths directly from the payload and allocate `T[,]`, `T[,,]`, or `T[,,,]` before validating that the dimension product matches the encoded element count.</p>
<p>The formatter reads a guarded element array header, but allocation of the target multi-dimensional array happens before the dimensions are checked against that element count. A small payload can therefore declare large dimensions, provide an empty or tiny inner array, and cause a large heap allocation before element data is validated.</p>
<p>## Impact</p>
<p>Applications are affected when they deserialize untrusted MessagePack payloads into models containing multi-dimensional arrays such as `T[,]`, `T[,,]`, or `T[,,,]`.</p>
<p>An attacker can encode large dimension integers and a small guarded element array. The formatter allocates the target array from the dimensions before confirming that the product of dimensions is consistent with the element count.</p>
<p>The result can be out-of-memory exceptions, container termination on memory-constrained hosts, large object heap pressure, or severe CPU cost from zero-initializing oversized arrays. `MessagePackSecurity.UntrustedData` does not provide a general allocation cap for this path.</p>
<p>## Affected components</p>
<p>- Package: `MessagePack`
- APIs: `TwoDimensionalArrayFormatter&lt;T&gt;.Deserialize`, `ThreeDimensionalArrayFormatter&lt;T&gt;.Deserialize`, `FourDimensionalArrayFormatter&lt;T&gt;.Deserialize`
- Data shapes: `T[,]`, `T[,,]`, and…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-cxmj-83gh-fp49"/>
  </entry>
</feed>
