CVE-2026-90472: Msgpack Msgpack-Java
Medium severity, CVSS 5.3. EPSS: 0.6% chance of exploitation in the next 30 days.
msgpack-java through 0.9.12 contains a stack overflow vulnerability in MessageUnpacker.unpackValue() that recursively deserializes arrays and maps without nesting depth limits. Attackers can craft payloads with deeply nested arrays to exhaust the deserializing thread's stack and trigger StackOverflowError, causing per-request deserialization failures.
Affected products
- Msgpack Msgpack-Java: up to and including 0.9.12
Published 2026-09-12. Last modified 2026-09-23.