CVE-2026-32284: Shamaton Msgpack
High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.
The msgpack decoder fails to properly validate the input buffer length when processing truncated fixext data (format codes 0xd4-0xd8). This can lead to an out-of-bounds read and a runtime panic, allowing a denial of service attack.
Affected products
- Shamaton Msgpack: up to and including 3.1.2
Published 2026-03-26. Last modified 2026-10-07.