msgpack
Security Risk Profile
37
/100
lowSecurity Risk Score
Comprehensive risk assessment based on 3 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from January 2, 2026 to present
3
Total CVEs
2
Critical+High
0
Exploited
0
Unpatched
Threat Assessment
Avg CVSS
5.7
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
0
Critical/High
Risk Level
37/100
low
📈 1 in Last 30 Days
Severity Distribution
Critical
0High
2Medium
0Low
1Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
1Age Distribution
Common Weaknesses (CWE)
1
Use After Free
2
Most Affected Products
1. MessagePack for Ruby MessagePack1
2. rubygems/msgpack1
3. msgpack Messagepack Ruby1
4. Microsoft azl3 rubygem-msgpack 1.7.2-11
5. MessagePack msgpack-python1
Recent Vulnerabilities
See more →CVE-2026-54522
CVSS 2.1low
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
7/30/2026
CVE-2026-57585
CVSS 7.5high
MessagePack: Out-of-bounds read/crash on Unpacker reuse after caught error
6/30/2026
CVE-2026-21452
CVSS 7.5EPSS 0%high
MessagePack-Java Vulnerable to Remote Denial of Service via Malicious .msgpack Model File Triggering Unbounded EXT Payload Allocation
1/2/2026
Monitor msgpack in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.