CVE-2026-90473: Msgpack Msgpack-Java
Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.
msgpack-java through 0.9.12 contains an integer overflow vulnerability in MessageUnpacker.skipValue() when processing MAP32 containers with large element counts. Attackers can supply a MAP32 element count at or above 0x40000000 that wraps when doubled, causing the parser cursor to desynchronize and attacker-controlled data to be returned in place of later fields.
Affected products
- Msgpack Msgpack-Java: up to and including 0.9.12
Published 2026-09-12. Last modified 2026-09-23.