High severity7.5NVD Advisory· Published Jun 22, 2026· Updated Jun 25, 2026
CVE-2026-48516
CVE-2026-48516
Description
MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, InterfaceLookupFormatter<TKey,TElement> constructs an internal Dictionary<TKey, IGrouping<TKey,TElement>> with the default equality comparer instead of the security-aware comparer supplied by options.Security.GetEqualityComparer(). This formatter omission allows hash-collision CPU denial of service against ILookup<TKey,TElement> even when the application has opted into the untrusted-data security posture This vulnerability is fixed in 2.5.301 and 3.1.7.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
MessagePackNuGet | < 2.5.301 | 2.5.301 |
MessagePackNuGet | >= 3.0, < 3.1.7 | 3.1.7 |
Affected products
2- Range: <2.5.301, <3.1.7
Patches
Vulnerability mechanics
References
3- github.com/MessagePack-CSharp/MessagePack-CSharp/security/advisories/GHSA-q2h6-ghwm-5qm8nvdMitigationVendor AdvisoryWEB
- github.com/advisories/GHSA-q2h6-ghwm-5qm8ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-48516ghsaADVISORY
News mentions
1- MessagePack C#: Ten Vulnerabilities Disclosed Together, Affecting Deserialization and SecurityVypr Intelligence · Jun 22, 2026