<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 15:40:36 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-36467</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-36467</link>
      <description>EUVD-2026-36467</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-36467</guid>
    </item>
    <item>
      <title>fkie_cve-2020-5234</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-5234</link>
      <description>&lt;p&gt;MessagePack for C# and Unity before version 1.9.11 and 2.1.90 has a vulnerability where untrusted data can lead to DoS attack due to hash collisions and stack overflow. Review the linked GitHub Security Advisory for more information and remediation steps.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;MessagePack for C# and Unity before version 1.9.11 and 2.1.90 has a vulnerability where untrusted data can lead to DoS attack due to hash collisions and stack overflow. Review the linked GitHub Security Advisory for more information and remediation steps.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-5234</guid>
    </item>
    <item>
      <title>GHSA-7q36-4xx7-xcxf — Untrusted data can lead to DoS attack due to hash collisions and stack overflow in MessagePack</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7q36-4xx7-xcxf</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; NuGet: MessagePack, NuGet: MessagePack.ImmutableCollection, NuGet: MessagePack.ReactiveProperty, NuGet: MessagePack.UnityShims, NuGet: MessagePack.Unity&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;When this library is used to deserialize messagepack data from an untrusted source, there is a risk of a denial of service attack by either of two vectors:&lt;/p&gt;
&lt;p&gt;1. hash collisions - leading to large CPU consumption disproportionate to the size of the data being deserialized.
1. stack overflow - leading to the deserializing process crashing.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;The following steps are required to mitigate this risk.&lt;/p&gt;
&lt;p&gt;1. Upgrade to a version of the library where a fix is available
1. Add code to your application to put MessagePack into the defensive `UntrustedData` mode.
1. Identify all MessagePack extensions that implement `IMessagePackFormatter&amp;lt;T&amp;gt;` implementations that do not ship with the MessagePack library to include the security mitigations. This includes those acquired from 3rd party packages and classes included directly into your project. Any AOT formatters generated with the MPC tool must be regenerated with the patched version of mpc.
1. Review your messagepack-serializable data structures for hash-based collections that use custom or unusual types for the hashed key. See below for details on handling such situations.&lt;/p&gt;
&lt;p&gt;Review the `MessagePackSecurity` class to tweak any settings as necessary to strike the right balance between performance, functionality, and security.&lt;/p&gt;
&lt;p&gt;Specialized `IEqualityComparer&amp;lt;T&amp;gt;` implementations provide the hash collision resistance.
Each type of hashed key may require a specialized implementation of its own.
The patched MessagePack library…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; NuGet: MessagePack, NuGet: MessagePack.ImmutableCollection, NuGet: MessagePack.ReactiveProperty, NuGet: MessagePack.UnityShims, NuGet: MessagePack.Unity&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;When this library is used to deserialize messagepack data from an untrusted source, there is a risk of a denial of service attack by either of two vectors:&lt;/p&gt;
&lt;p&gt;1. hash collisions - leading to large CPU consumption disproportionate to the size of the data being deserialized.
1. stack overflow - leading to the deserializing process crashing.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;The following steps are required to mitigate this risk.&lt;/p&gt;
&lt;p&gt;1. Upgrade to a version of the library where a fix is available
1. Add code to your application to put MessagePack into the defensive `UntrustedData` mode.
1. Identify all MessagePack extensions that implement `IMessagePackFormatter&amp;lt;T&amp;gt;` implementations that do not ship with the MessagePack library to include the security mitigations. This includes those acquired from 3rd party packages and classes included directly into your project. Any AOT formatters generated with the MPC tool must be regenerated with the patched version of mpc.
1. Review your messagepack-serializable data structures for hash-based collections that use custom or unusual types for the hashed key. See below for details on handling such situations.&lt;/p&gt;
&lt;p&gt;Review the `MessagePackSecurity` class to tweak any settings as necessary to strike the right balance between performance, functionality, and security.&lt;/p&gt;
&lt;p&gt;Specialized `IEqualityComparer&amp;lt;T&amp;gt;` implementations provide the hash collision resistance.
Each type of hashed key may require a specialized implementation of its own.
The patched MessagePack library…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7q36-4xx7-xcxf</guid>
    </item>
    <item>
      <title>gsd-2020-5234</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-5234</link>
      <description>gsd-2020-5234</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-5234</guid>
    </item>
  </channel>
</rss>
