|
1261
|
7.5 |
HIGH
Network
|
messagepack
|
messagepack
|
MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, runtime-generated union deserializers emitted by DynamicUnionResolver do not call MessagePackSecurity.DepthStep(ref …
New
|
CWE-674
Uncontrolled Recursion
|
CVE-2026-48513
|
2026-06-26 01:16 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1262
|
7.5 |
HIGH
Network
|
messagepack
|
messagepack
|
MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePack-CSharp's JSON conversion helpers contain multiple recursion paths that do not consistently enforce a dep…
New
|
CWE-674
Uncontrolled Recursion
|
CVE-2026-48512
|
2026-06-26 01:16 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1263
|
7.5 |
HIGH
Network
|
messagepack
|
messagepack
|
MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, ExpandoObjectFormatter.Deserialize populates System.Dynamic.ExpandoObject by calling IDictionary<string, object>.Add…
New
|
CWE-407
Inefficient Algorithmic Complexity
|
CVE-2026-48511
|
2026-06-26 01:16 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1264
|
7.5 |
HIGH
Network
|
messagepack
|
messagepack
|
MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, when MessagePack-CSharp decompresses Lz4Block or Lz4BlockArray payloads, it reads declared uncompressed lengths from…
New
|
CWE-409 CWE-770
Improper Handling of Highly Compressed Data (Data Amplification) Allocation of Resources Without Limits or Throttling
|
CVE-2026-48510
|
2026-06-26 01:16 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1265
|
9.1 |
CRITICAL
Network
|
messagepack
|
messagepack
|
MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, the parameterless MessagePackInputFormatter() constructor uses default serializer options, which resolve to MessageP…
New
|
CWE-1188
Insecure Default Initialization of Resource
|
CVE-2026-48509
|
2026-06-26 01:16 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1266
|
4.4 |
MEDIUM
Network
|
-
|
-
|
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, the ImageElement component in packages/gazzodown renders user-controlled src values directly into <a…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-47733
|
2026-06-26 01:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1267
|
- |
|
-
|
-
|
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.2, 8.3.4, 8.2.4, 8.1.5, 8.0.6, 7.13.8, and 7.10.12, Rocket.Chat allows users deactivated through…
New
|
CWE-613
Insufficient Session Expiration
|
CVE-2026-45757
|
2026-06-26 01:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1268
|
5.3 |
MEDIUM
Network
|
-
|
-
|
This fix provides extra hardening for the 5.4.x branch by doing extra validation of incoming answers from authoritative servers.
New
|
CWE-20
Improper Input Validation
|
CVE-2026-42389
|
2026-06-26 01:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1269
|
5.9 |
MEDIUM
Network
|
-
|
-
|
Incomplete validation of the SOA record present in a catalog zone might lead to a crash.
New
|
CWE-20
Improper Input Validation
|
CVE-2026-42388
|
2026-06-26 01:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1270
|
5.9 |
MEDIUM
Network
|
-
|
-
|
A malicious authoritative server can send a crafted zone via the ZoneToCache function that leads to a crash of the Recursor due to insuffcient input validation.
New
|
CWE-20
Improper Input Validation
|
CVE-2026-42387
|
2026-06-26 01:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|