CVE-2026-90472
msgpack-java through 0.9.12 contains a stack overflow vulnerability in MessageUnpacker.unpackValue() that recursively deserializes arrays and maps without nesting depth limits. Attackers can craft payloads with deeply nested arrays to exhaust the deserializing thread's stack and trigger StackOverflowError, causing per-request deserialization failures.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.9
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
- EPSS probability
- 0.33%
- CWE
- CWE-674
- Published
- 2026-09-12
- Last modified
- 2026-09-14
Affected products
- msgpack msgpack-java
Weakness type
Related vulnerabilities
- CVE-2026-33498 — Parse Server: Query condition depth bypass via pre-validation transform pipeline
- CVE-2026-32944 — Parse Server crash via deeply nested query condition operators
- CVE-2025-66031 — node-forge ASN.1 Unbounded Recursion
- CVE-2025-54858 — BIG-IP Advanced WAF and ASM vulnerability
- CVE-2025-9624 — OpenSearch 3.2.0 - Nested Boolean/Disjunction asymmetric DoS
- CVE-2026-33508 — Parse Server: LiveQuery subscription query depth bypass
- CVE-2026-72686 — Uncontrolled Recursion in Elasticsearch Leading to Denial of Service
- CVE-2026-72679 — Uncontrolled Recursion in Elasticsearch Leading to Denial of Service