{"id":"CVE-2026-88351","published":"2026-09-24T15:17:50.423","lastModified":"2026-09-25T18:17:31.257","description":"An integer overflow vulnerability exists in the MPack Node API in MPack 1.1.1 on 32-bit platforms. When parsing a specially crafted MessagePack array32 or map32 object with an excessively large element count, the page allocation size calculation in mpack_tree_parse_children() can overflow size_t and produce an undersized allocation. Subsequent parsing writes mpack_node_data_t records beyond the allocated heap buffer, resulting in heap-buffer-overflow, memory corruption, and denial of service.","cvssScore":9.8,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-190"],"vendors":[],"products":[],"references":[{"url":"https://github.com/ludocode/mpack/commit/3d54d1215bdb5478d3ddecaf85884c58b382cd9b","tags":[]},{"url":"https://github.com/ludocode/mpack/issues/123","tags":[]},{"url":"https://github.com/ludocode/mpack/issues/123","tags":[]}],"exploitRefs":[{"url":"https://github.com/ludocode/mpack/commit/3d54d1215bdb5478d3ddecaf85884c58b382cd9b","tags":[]},{"url":"https://github.com/ludocode/mpack/issues/123","tags":[]},{"url":"https://github.com/ludocode/mpack/issues/123","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw is an integer overflow vulnerability in the MPack Node API that can lead to heap-buffer-overflow, memory corruption, and denial of service. This matters because it can be exploited to crash the application or gain control over the system.","exploitability":"Exploitation is moderately hard as it requires crafting a specially crafted MessagePack array32 or map32 object with an excessively large element count. The attacker must have the ability to send such a payload to the affected application.","blast_radius":"If exploited, the vulnerability could result in a denial of service for the affected application, potentially impacting availability and reliability of the service.","remediation":"Upgrade to MPack 1.1.2 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["heap-overflow","denial-of-service","api-vulnerability"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-27T08:52:19.268Z"}}