CVE-2026-32284: Shamaton Msgpack

High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.

The msgpack decoder fails to properly validate the input buffer length when processing truncated fixext data (format codes 0xd4-0xd8). This can lead to an out-of-bounds read and a runtime panic, allowing a denial of service attack.

Affected products

  • Shamaton Msgpack: up to and including 3.1.2

Published 2026-03-26. Last modified 2026-10-07.