CVE-2026-48109: MessagePack-CSharp: LZ4 decompression may fail with AccessViolationException after dereferencing memory from bad input
Impact
A vulnerability exists in the optional LZ4 decompression path used by MessagePack compression modes Lz4Block and Lz4BlockArray.
The decoder implementation is based on a deprecated fast-decompression algorithm that does not take a source-length bound. A remote attacker can send a crafted MessagePack payload with manipulated LZ4 token/length fields to force out-of-bounds reads from the compressed input buffer. In affected environments, this can trigger an AccessViolationException during decompression, causing process termination (denial of service). Under some conditions, limited unintended memory disclosure from over-read data may also be possible before failure.
This issue affects applications that deserialize untrusted data while LZ4 compression is enabled.
Patches
The v2 versions are patched as of 2.5.301. The v3 versions are patched as of 3.1.7.
Workarounds
Instead of upgrading, an application may take the following precautions:
1. Disable LZ4 compression for untrusted input paths (Lz4Block, Lz4BlockArray). 2. Only accept compressed payloads from strongly trusted producers. 3. Isolate deserialization in a separate process/container with restart supervision to limit availability impact.
Resources
- MESSAGEPACKCSHARP-010
Other sources
MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, A vulnerability exists in the optional LZ4 decompression path used by MessagePack compression modes Lz4Block and Lz4BlockArray. The decoder implementation is based on a deprecated fast-decompression algorithm that does not take a source-length bound. A remote attacker can send a crafted MessagePack payload with manipulated LZ4 token/length fields to force out-of-bounds reads from the compressed input buffer. In affected environments, this can trigger an AccessViolationException during decompression, causing process termination (denial of service). Under some conditions, limited unintended memory disclosure from over-read data may also be possible before failure. This vulnerability is fixed in 2.5.301 and 3.1.7.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
nuget/MessagePackto a version that resolves this vulnerability.Fixed in 3.1.7 - Upgrade
Upgrade
nuget/MessagePackto a version that resolves this vulnerability.Fixed in 2.5.301 - Configuration
Disable LZ4 compression for untrusted input paths by not enabling the Lz4Block or Lz4BlockArray compression modes.
MessagePack (nuget/MessagePack) compression_mode = disable LZ4 (do not use Lz4Block or Lz4BlockArray) - Compensating control
Isolate deserialization of untrusted data into a separate process or container with restart supervision to limit availability impact if decompression causes a crash.
- Compensating control
Only accept compressed (LZ4) payloads from strongly trusted producers; validate and restrict sources before decompressing.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48109?
CVE-2026-48109 has a high severity rating of 8.2.
How do I fix CVE-2026-48109?
To fix CVE-2026-48109, update to the latest version of the MessagePack library that addresses this vulnerability.
What impact does CVE-2026-48109 have on my system?
CVE-2026-48109 allows a remote attacker to exploit a weakness in the LZ4 decompression path used by MessagePack, potentially leading to a denial of service.
What software is affected by CVE-2026-48109?
CVE-2026-48109 affects the MessagePack library used in NuGet packages.
Is CVE-2026-48109 exploitable remotely?
Yes, CVE-2026-48109 can be exploited remotely due to its inherent vulnerability in handling compressed data.