CVE-2026-90473
msgpack-java through 0.9.12 contains an integer overflow vulnerability in MessageUnpacker.skipValue() when processing MAP32 containers with
CVSS
5.3
Medium
EPSS
—
KEV
—
Exploit Today
0
0-100
Published: Sep 12, 2026 · Last modified: Sep 12, 2026 · CWE-190
Not enough EPSS history yet.
msgpack-java through 0.9.12 contains an integer overflow vulnerability in MessageUnpacker.skipValue() when processing MAP32 containers with large element counts. Attackers can supply a MAP32 element count at or above 0x40000000 that wraps when doubled, causing the parser cursor to desynchronize and attacker-controlled data to be returned in place of later fields.
- github.comhttps://github.com/msgpack/msgpack-java
- github.comhttps://github.com/msgpack/msgpack-java/blob/v0.9.12/msgpack-core/src/main/java/org/msgpack/core/MessageUnpacker.java#L573-L581
- github.comhttps://github.com/msgpack/msgpack-java/issues/1014
- www.vulncheck.comhttps://www.vulncheck.com/advisories/msgpack-java-through-0.9.12-integer-overflow-via-map32
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-542417.4 HIG—
——0libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.1.1 use signed 32-bit arithmetic to calculate the sample adaptive offset input-buffer size, allowing a crafted HEVC stream with large dimensions and 16-bit luma samples to cause an integer overflow, an undersized allocation, and an out-of-bounds heap read that may expose heap data in decoded output or crash the decoder. Version 1.1.1 contains a patch.22hCVE-2026-542407.4 HIG—
——0libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.1.1 use signed 32-bit arithmetic to calculate pixel offsets, allowing a crafted HEVC stream with large image dimensions to trigger an integer overflow and cause out-of-bounds heap reads or writes, potentially disclosing data, corrupting memory, or crashing the decoder. Version 1.1.1 contains a patch.22hCVE-2026-870208.1 HIG—
——0An integer overflow in a specified pitch and buffer-size computation leads to a heap out-of-bounds write when Orthanc DICOM Server decodes an attacker-supplied PNG.1dCVE-2026-891467.5 HIG—
——0libp2p-rendezvous through 0.17.1 fails to validate registration TTL values in discovery responses, allowing attackers to trigger timer arithmetic overflow. A malicious rendezvous server can send a discovery response with an unbounded TTL value that causes the client node process to panic when computing the expiry timer.1dCVE-2026-891586.5 MED12.6%
——4PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write.1dCVE-2026-891575.7 MED1.0%
——0PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an attacker can provide a large pattern.1d