Deserialization of Untrusted Data in msgpack
Critical severity
GitHub Reviewed
Published
Jul 26, 2021
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Withdrawn
This advisory was withdrawn on Sep 15, 2021
Description
Published by the National Vulnerability Database
Jul 21, 2021
Reviewed
Jul 26, 2021
Published to the GitHub Advisory Database
Jul 26, 2021
Withdrawn
Sep 15, 2021
Last updated
Feb 1, 2023
Withdrawn
This advisory was withdrawn by its CNA (Snyk).
Original advisory
All versions of package
msgpack
are vulnerable to Deserialization of Untrusted Data via the unpack function. This does not affect the similarly named package@msgpack/msgpack
.References