CVE-2026-90472 MEDIUM

CVE-2026-90472: msgpack-java through 0.9.12 Stack Overflow via Nested Arrays

Vendor Msgpack
Product msgpack-java
Weakness CWE-674
Published September 12, 2026
Last update September 12, 2026

CVSS base score

6.9/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality —
Integrity —

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

What the vulnerability does

01Description

msgpack-java through 0.9.12 contains a stack overflow vulnerability in MessageUnpacker.unpackValue() that recursively deserializes arrays and maps without nesting depth limits. Attackers can craft payloads with deeply nested arrays to exhaust the deserializing thread's stack and trigger StackOverflowError, causing per-request deserialization failures.

Key dates

02Disclosure timeline

September 12, 2026 CVE published