← Back to search

CVE-2026-88351

9.8 CRITICALpublic exploit available

Published 2026-09-24 · Updated 2026-09-25

AI risk analysis

Summary
The flaw is an integer overflow vulnerability in the MPack Node API that can lead to heap-buffer-overflow, memory corruption, and denial of service. This matters because it can be exploited to crash the application or gain control over the system.
Exploitability
Exploitation is moderately hard as it requires crafting a specially crafted MessagePack array32 or map32 object with an excessively large element count. The attacker must have the ability to send such a payload to the affected application.
Blast radius
If exploited, the vulnerability could result in a denial of service for the affected application, potentially impacting availability and reliability of the service.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to MPack 1.1.2 or later.
heap-overflowdenial-of-serviceapi-vulnerability

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

An integer overflow vulnerability exists in the MPack Node API in MPack 1.1.1 on 32-bit platforms. When parsing a specially crafted MessagePack array32 or map32 object with an excessively large element count, the page allocation size calculation in mpack_tree_parse_children() can overflow size_t and produce an undersized allocation. Subsequent parsing writes mpack_node_data_t records beyond the allocated heap buffer, resulting in heap-buffer-overflow, memory corruption, and denial of service.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-190

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.