CVE-2026-44375: Aarnott Nerdbank.messagepack

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

Nerdbank.MessagePack is a NativeAOT-compatible MessagePack serialization library. Prior to 1.1.62, Nerdbank.MessagePack contains an uncontrolled stack allocation vulnerability in DateTime decoding. A malicious MessagePack payload can declare an oversized timestamp extension length, causing the reader to allocate an attacker-controlled number of bytes on the stack. This can trigger a StackOverflowException, which is not catchable by user code and terminates the process. This vulnerability is fixed in 1.1.62.

Affected products

  • Aarnott Nerdbank.messagepack: before 1.1.62 (fixed in 1.1.62)

Published 2026-05-14. Last modified 2026-06-17.