msgpack
MessagePack implementation for Ruby / msgpack.org[Ruby]
Activity
- Latest release
- 3d ago
- Total releases
- 97
- Cadence
- ~38 days
- Last 12 months
- 5
Reach
- Stars
- 790
Details
- License
- Apache-2.0
- First release
- Aug 15, 2008
| Version | Released | |
|---|---|---|
1.8.5
patch
| ||
1.8.4
patch
| ||
1.8.3
patch
|
1.8.3
patch
Dependencies (8)
Changelog
Compare changes
|
|
1.8.2
patch
|
1.8.2
patch
Dependencies (8)
Changelog
Compare changes
|
|
1.8.1
patch
1 CVE
CVE-2026-54522
GHSA-4mrv-5p47-p938
Jul 30, 2026
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
Low
Local
Low
None
None
Summary
Details
PoCSingle self-contained script (builds msgpack from rubygems with AddressSanitizer, then runs the PoC):
Expected output:
ImpactSame-process cross-buffer information disclosure and corruption: after CreditPranjali Thakur - depthfirst (depthfirst.com) Affected versions
0.0.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
+ 81 more Show less
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0pre1
0.6.1
0.6.2
0.7.0
0.7.0dev1
0.7.1
0.7.2
0.7.2dev1
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.0.pre1
1.4.1
1.4.2
1.4.3
1.4.4
1.4.4.pre1
1.4.5
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
1.8.1
patch
Dependencies (8)
Changelog
Compare changes
|
|
1.8.0
minor
1 CVE
CVE-2026-54522
GHSA-4mrv-5p47-p938
Jul 30, 2026
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
Low
Local
Low
None
None
Summary
Details
PoCSingle self-contained script (builds msgpack from rubygems with AddressSanitizer, then runs the PoC):
Expected output:
ImpactSame-process cross-buffer information disclosure and corruption: after CreditPranjali Thakur - depthfirst (depthfirst.com) Affected versions
0.0.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
+ 81 more Show less
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0pre1
0.6.1
0.6.2
0.7.0
0.7.0dev1
0.7.1
0.7.2
0.7.2dev1
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.0.pre1
1.4.1
1.4.2
1.4.3
1.4.4
1.4.4.pre1
1.4.5
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
1.8.0
minor
Dependencies (8)
Changelog
Compare changes
|
|
1.7.5
patch
1 CVE
CVE-2026-54522
GHSA-4mrv-5p47-p938
Jul 30, 2026
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
Low
Local
Low
None
None
Summary
Details
PoCSingle self-contained script (builds msgpack from rubygems with AddressSanitizer, then runs the PoC):
Expected output:
ImpactSame-process cross-buffer information disclosure and corruption: after CreditPranjali Thakur - depthfirst (depthfirst.com) Affected versions
0.0.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
+ 81 more Show less
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0pre1
0.6.1
0.6.2
0.7.0
0.7.0dev1
0.7.1
0.7.2
0.7.2dev1
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.0.pre1
1.4.1
1.4.2
1.4.3
1.4.4
1.4.4.pre1
1.4.5
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
1.7.5
patch
Dependencies (8)
Changelog
Compare changes
|
|
1.7.4
patch
1 CVE
CVE-2026-54522
GHSA-4mrv-5p47-p938
Jul 30, 2026
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
Low
Local
Low
None
None
Summary
Details
PoCSingle self-contained script (builds msgpack from rubygems with AddressSanitizer, then runs the PoC):
Expected output:
ImpactSame-process cross-buffer information disclosure and corruption: after CreditPranjali Thakur - depthfirst (depthfirst.com) Affected versions
0.0.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
+ 81 more Show less
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0pre1
0.6.1
0.6.2
0.7.0
0.7.0dev1
0.7.1
0.7.2
0.7.2dev1
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.0.pre1
1.4.1
1.4.2
1.4.3
1.4.4
1.4.4.pre1
1.4.5
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
1.7.4
patch
Dependencies (8)
Changelog
Compare changes
|
|
1.7.3
patch
1 CVE
CVE-2026-54522
GHSA-4mrv-5p47-p938
Jul 30, 2026
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
Low
Local
Low
None
None
Summary
Details
PoCSingle self-contained script (builds msgpack from rubygems with AddressSanitizer, then runs the PoC):
Expected output:
ImpactSame-process cross-buffer information disclosure and corruption: after CreditPranjali Thakur - depthfirst (depthfirst.com) Affected versions
0.0.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
+ 81 more Show less
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0pre1
0.6.1
0.6.2
0.7.0
0.7.0dev1
0.7.1
0.7.2
0.7.2dev1
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.0.pre1
1.4.1
1.4.2
1.4.3
1.4.4
1.4.4.pre1
1.4.5
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
1.7.3
patch
Dependencies (8)
Changelog
Compare changes
|
|
1.7.2
patch
1 CVE
CVE-2026-54522
GHSA-4mrv-5p47-p938
Jul 30, 2026
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
Low
Local
Low
None
None
Summary
Details
PoCSingle self-contained script (builds msgpack from rubygems with AddressSanitizer, then runs the PoC):
Expected output:
ImpactSame-process cross-buffer information disclosure and corruption: after CreditPranjali Thakur - depthfirst (depthfirst.com) Affected versions
0.0.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
+ 81 more Show less
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0pre1
0.6.1
0.6.2
0.7.0
0.7.0dev1
0.7.1
0.7.2
0.7.2dev1
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.0.pre1
1.4.1
1.4.2
1.4.3
1.4.4
1.4.4.pre1
1.4.5
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
1.7.2
patch
Dependencies (8)
Changelog
Compare changes
|
|
1.7.1
patch
1 CVE
CVE-2026-54522
GHSA-4mrv-5p47-p938
Jul 30, 2026
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
Low
Local
Low
None
None
Summary
Details
PoCSingle self-contained script (builds msgpack from rubygems with AddressSanitizer, then runs the PoC):
Expected output:
ImpactSame-process cross-buffer information disclosure and corruption: after CreditPranjali Thakur - depthfirst (depthfirst.com) Affected versions
0.0.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
+ 81 more Show less
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0pre1
0.6.1
0.6.2
0.7.0
0.7.0dev1
0.7.1
0.7.2
0.7.2dev1
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.0.pre1
1.4.1
1.4.2
1.4.3
1.4.4
1.4.4.pre1
1.4.5
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
1.7.1
patch
Dependencies (8)
Changelog
Compare changes
|
|
1.7.0
minor
1 CVE
CVE-2026-54522
GHSA-4mrv-5p47-p938
Jul 30, 2026
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
Low
Local
Low
None
None
Summary
Details
PoCSingle self-contained script (builds msgpack from rubygems with AddressSanitizer, then runs the PoC):
Expected output:
ImpactSame-process cross-buffer information disclosure and corruption: after CreditPranjali Thakur - depthfirst (depthfirst.com) Affected versions
0.0.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
+ 81 more Show less
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0pre1
0.6.1
0.6.2
0.7.0
0.7.0dev1
0.7.1
0.7.2
0.7.2dev1
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.0.pre1
1.4.1
1.4.2
1.4.3
1.4.4
1.4.4.pre1
1.4.5
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
1.7.0
minor
Dependencies (8)
Changelog
Compare changes
|
|
1.6.1
patch
1 CVE
CVE-2026-54522
GHSA-4mrv-5p47-p938
Jul 30, 2026
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
Low
Local
Low
None
None
Summary
Details
PoCSingle self-contained script (builds msgpack from rubygems with AddressSanitizer, then runs the PoC):
Expected output:
ImpactSame-process cross-buffer information disclosure and corruption: after CreditPranjali Thakur - depthfirst (depthfirst.com) Affected versions
0.0.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
+ 81 more Show less
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0pre1
0.6.1
0.6.2
0.7.0
0.7.0dev1
0.7.1
0.7.2
0.7.2dev1
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.0.pre1
1.4.1
1.4.2
1.4.3
1.4.4
1.4.4.pre1
1.4.5
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
1.6.1
patch
Dependencies (8)
Changelog
Compare changes
|
|
1.6.0
minor
1 CVE
CVE-2026-54522
GHSA-4mrv-5p47-p938
Jul 30, 2026
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
Low
Local
Low
None
None
Summary
Details
PoCSingle self-contained script (builds msgpack from rubygems with AddressSanitizer, then runs the PoC):
Expected output:
ImpactSame-process cross-buffer information disclosure and corruption: after CreditPranjali Thakur - depthfirst (depthfirst.com) Affected versions
0.0.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
+ 81 more Show less
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0pre1
0.6.1
0.6.2
0.7.0
0.7.0dev1
0.7.1
0.7.2
0.7.2dev1
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.0.pre1
1.4.1
1.4.2
1.4.3
1.4.4
1.4.4.pre1
1.4.5
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.5.6
patch
1 CVE
CVE-2026-54522
GHSA-4mrv-5p47-p938
Jul 30, 2026
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
Low
Local
Low
None
None
Summary
Details
PoCSingle self-contained script (builds msgpack from rubygems with AddressSanitizer, then runs the PoC):
Expected output:
ImpactSame-process cross-buffer information disclosure and corruption: after CreditPranjali Thakur - depthfirst (depthfirst.com) Affected versions
0.0.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
+ 81 more Show less
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0pre1
0.6.1
0.6.2
0.7.0
0.7.0dev1
0.7.1
0.7.2
0.7.2dev1
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.0.pre1
1.4.1
1.4.2
1.4.3
1.4.4
1.4.4.pre1
1.4.5
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.5.5
patch
1 CVE
CVE-2026-54522
GHSA-4mrv-5p47-p938
Jul 30, 2026
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
Low
Local
Low
None
None
Summary
Details
PoCSingle self-contained script (builds msgpack from rubygems with AddressSanitizer, then runs the PoC):
Expected output:
ImpactSame-process cross-buffer information disclosure and corruption: after CreditPranjali Thakur - depthfirst (depthfirst.com) Affected versions
0.0.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
+ 81 more Show less
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0pre1
0.6.1
0.6.2
0.7.0
0.7.0dev1
0.7.1
0.7.2
0.7.2dev1
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.0.pre1
1.4.1
1.4.2
1.4.3
1.4.4
1.4.4.pre1
1.4.5
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.5.4
patch
1 CVE
CVE-2026-54522
GHSA-4mrv-5p47-p938
Jul 30, 2026
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
Low
Local
Low
None
None
Summary
Details
PoCSingle self-contained script (builds msgpack from rubygems with AddressSanitizer, then runs the PoC):
Expected output:
ImpactSame-process cross-buffer information disclosure and corruption: after CreditPranjali Thakur - depthfirst (depthfirst.com) Affected versions
0.0.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
+ 81 more Show less
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0pre1
0.6.1
0.6.2
0.7.0
0.7.0dev1
0.7.1
0.7.2
0.7.2dev1
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.0.pre1
1.4.1
1.4.2
1.4.3
1.4.4
1.4.4.pre1
1.4.5
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.5.3
patch
1 CVE
CVE-2026-54522
GHSA-4mrv-5p47-p938
Jul 30, 2026
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
Low
Local
Low
None
None
Summary
Details
PoCSingle self-contained script (builds msgpack from rubygems with AddressSanitizer, then runs the PoC):
Expected output:
ImpactSame-process cross-buffer information disclosure and corruption: after CreditPranjali Thakur - depthfirst (depthfirst.com) Affected versions
0.0.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
+ 81 more Show less
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0pre1
0.6.1
0.6.2
0.7.0
0.7.0dev1
0.7.1
0.7.2
0.7.2dev1
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.0.pre1
1.4.1
1.4.2
1.4.3
1.4.4
1.4.4.pre1
1.4.5
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.5.2
patch
1 CVE
CVE-2026-54522
GHSA-4mrv-5p47-p938
Jul 30, 2026
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
Low
Local
Low
None
None
Summary
Details
PoCSingle self-contained script (builds msgpack from rubygems with AddressSanitizer, then runs the PoC):
Expected output:
ImpactSame-process cross-buffer information disclosure and corruption: after CreditPranjali Thakur - depthfirst (depthfirst.com) Affected versions
0.0.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
+ 81 more Show less
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0pre1
0.6.1
0.6.2
0.7.0
0.7.0dev1
0.7.1
0.7.2
0.7.2dev1
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.0.pre1
1.4.1
1.4.2
1.4.3
1.4.4
1.4.4.pre1
1.4.5
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.5.1
patch
1 CVE
CVE-2026-54522
GHSA-4mrv-5p47-p938
Jul 30, 2026
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
Low
Local
Low
None
None
Summary
Details
PoCSingle self-contained script (builds msgpack from rubygems with AddressSanitizer, then runs the PoC):
Expected output:
ImpactSame-process cross-buffer information disclosure and corruption: after CreditPranjali Thakur - depthfirst (depthfirst.com) Affected versions
0.0.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
+ 81 more Show less
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0pre1
0.6.1
0.6.2
0.7.0
0.7.0dev1
0.7.1
0.7.2
0.7.2dev1
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.0.pre1
1.4.1
1.4.2
1.4.3
1.4.4
1.4.4.pre1
1.4.5
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.5.0
minor
1 CVE
CVE-2026-54522
GHSA-4mrv-5p47-p938
Jul 30, 2026
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
Low
Local
Low
None
None
Summary
Details
PoCSingle self-contained script (builds msgpack from rubygems with AddressSanitizer, then runs the PoC):
Expected output:
ImpactSame-process cross-buffer information disclosure and corruption: after CreditPranjali Thakur - depthfirst (depthfirst.com) Affected versions
0.0.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
+ 81 more Show less
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0pre1
0.6.1
0.6.2
0.7.0
0.7.0dev1
0.7.1
0.7.2
0.7.2dev1
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.0.pre1
1.4.1
1.4.2
1.4.3
1.4.4
1.4.4.pre1
1.4.5
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.4.5
patch
1 CVE
CVE-2026-54522
GHSA-4mrv-5p47-p938
Jul 30, 2026
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
Low
Local
Low
None
None
Summary
Details
PoCSingle self-contained script (builds msgpack from rubygems with AddressSanitizer, then runs the PoC):
Expected output:
ImpactSame-process cross-buffer information disclosure and corruption: after CreditPranjali Thakur - depthfirst (depthfirst.com) Affected versions
0.0.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
+ 81 more Show less
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0pre1
0.6.1
0.6.2
0.7.0
0.7.0dev1
0.7.1
0.7.2
0.7.2dev1
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.0.pre1
1.4.1
1.4.2
1.4.3
1.4.4
1.4.4.pre1
1.4.5
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.4.4
patch
1 CVE
CVE-2026-54522
GHSA-4mrv-5p47-p938
Jul 30, 2026
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
Low
Local
Low
None
None
Summary
Details
PoCSingle self-contained script (builds msgpack from rubygems with AddressSanitizer, then runs the PoC):
Expected output:
ImpactSame-process cross-buffer information disclosure and corruption: after CreditPranjali Thakur - depthfirst (depthfirst.com) Affected versions
0.0.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
+ 81 more Show less
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0pre1
0.6.1
0.6.2
0.7.0
0.7.0dev1
0.7.1
0.7.2
0.7.2dev1
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.0.pre1
1.4.1
1.4.2
1.4.3
1.4.4
1.4.4.pre1
1.4.5
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.4.4.pre1
pre
1 CVE
CVE-2026-54522
GHSA-4mrv-5p47-p938
Jul 30, 2026
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
Low
Local
Low
None
None
Summary
Details
PoCSingle self-contained script (builds msgpack from rubygems with AddressSanitizer, then runs the PoC):
Expected output:
ImpactSame-process cross-buffer information disclosure and corruption: after CreditPranjali Thakur - depthfirst (depthfirst.com) Affected versions
0.0.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
+ 81 more Show less
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0pre1
0.6.1
0.6.2
0.7.0
0.7.0dev1
0.7.1
0.7.2
0.7.2dev1
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.0.pre1
1.4.1
1.4.2
1.4.3
1.4.4
1.4.4.pre1
1.4.5
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.4.3
patch
1 CVE
CVE-2026-54522
GHSA-4mrv-5p47-p938
Jul 30, 2026
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
Low
Local
Low
None
None
Summary
Details
PoCSingle self-contained script (builds msgpack from rubygems with AddressSanitizer, then runs the PoC):
Expected output:
ImpactSame-process cross-buffer information disclosure and corruption: after CreditPranjali Thakur - depthfirst (depthfirst.com) Affected versions
0.0.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
+ 81 more Show less
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0pre1
0.6.1
0.6.2
0.7.0
0.7.0dev1
0.7.1
0.7.2
0.7.2dev1
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.0.pre1
1.4.1
1.4.2
1.4.3
1.4.4
1.4.4.pre1
1.4.5
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.4.2
patch
1 CVE
CVE-2026-54522
GHSA-4mrv-5p47-p938
Jul 30, 2026
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
Low
Local
Low
None
None
Summary
Details
PoCSingle self-contained script (builds msgpack from rubygems with AddressSanitizer, then runs the PoC):
Expected output:
ImpactSame-process cross-buffer information disclosure and corruption: after CreditPranjali Thakur - depthfirst (depthfirst.com) Affected versions
0.0.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
+ 81 more Show less
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0pre1
0.6.1
0.6.2
0.7.0
0.7.0dev1
0.7.1
0.7.2
0.7.2dev1
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.0.pre1
1.4.1
1.4.2
1.4.3
1.4.4
1.4.4.pre1
1.4.5
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.4.0
minor
1 CVE
CVE-2026-54522
GHSA-4mrv-5p47-p938
Jul 30, 2026
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
Low
Local
Low
None
None
Summary
Details
PoCSingle self-contained script (builds msgpack from rubygems with AddressSanitizer, then runs the PoC):
Expected output:
ImpactSame-process cross-buffer information disclosure and corruption: after CreditPranjali Thakur - depthfirst (depthfirst.com) Affected versions
0.0.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
+ 81 more Show less
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0pre1
0.6.1
0.6.2
0.7.0
0.7.0dev1
0.7.1
0.7.2
0.7.2dev1
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.0.pre1
1.4.1
1.4.2
1.4.3
1.4.4
1.4.4.pre1
1.4.5
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.4.1
patch
1 CVE
CVE-2026-54522
GHSA-4mrv-5p47-p938
Jul 30, 2026
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
Low
Local
Low
None
None
Summary
Details
PoCSingle self-contained script (builds msgpack from rubygems with AddressSanitizer, then runs the PoC):
Expected output:
ImpactSame-process cross-buffer information disclosure and corruption: after CreditPranjali Thakur - depthfirst (depthfirst.com) Affected versions
0.0.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
+ 81 more Show less
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0pre1
0.6.1
0.6.2
0.7.0
0.7.0dev1
0.7.1
0.7.2
0.7.2dev1
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.0.pre1
1.4.1
1.4.2
1.4.3
1.4.4
1.4.4.pre1
1.4.5
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.4.0.pre1
pre
1 CVE
CVE-2026-54522
GHSA-4mrv-5p47-p938
Jul 30, 2026
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
Low
Local
Low
None
None
Summary
Details
PoCSingle self-contained script (builds msgpack from rubygems with AddressSanitizer, then runs the PoC):
Expected output:
ImpactSame-process cross-buffer information disclosure and corruption: after CreditPranjali Thakur - depthfirst (depthfirst.com) Affected versions
0.0.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
+ 81 more Show less
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0pre1
0.6.1
0.6.2
0.7.0
0.7.0dev1
0.7.1
0.7.2
0.7.2dev1
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.0.pre1
1.4.1
1.4.2
1.4.3
1.4.4
1.4.4.pre1
1.4.5
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.3.3
patch
1 CVE
CVE-2026-54522
GHSA-4mrv-5p47-p938
Jul 30, 2026
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
Low
Local
Low
None
None
Summary
Details
PoCSingle self-contained script (builds msgpack from rubygems with AddressSanitizer, then runs the PoC):
Expected output:
ImpactSame-process cross-buffer information disclosure and corruption: after CreditPranjali Thakur - depthfirst (depthfirst.com) Affected versions
0.0.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
+ 81 more Show less
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0pre1
0.6.1
0.6.2
0.7.0
0.7.0dev1
0.7.1
0.7.2
0.7.2dev1
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.0.pre1
1.4.1
1.4.2
1.4.3
1.4.4
1.4.4.pre1
1.4.5
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.3.2
patch
1 CVE
CVE-2026-54522
GHSA-4mrv-5p47-p938
Jul 30, 2026
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
Low
Local
Low
None
None
Summary
Details
PoCSingle self-contained script (builds msgpack from rubygems with AddressSanitizer, then runs the PoC):
Expected output:
ImpactSame-process cross-buffer information disclosure and corruption: after CreditPranjali Thakur - depthfirst (depthfirst.com) Affected versions
0.0.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
+ 81 more Show less
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0pre1
0.6.1
0.6.2
0.7.0
0.7.0dev1
0.7.1
0.7.2
0.7.2dev1
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.0.pre1
1.4.1
1.4.2
1.4.3
1.4.4
1.4.4.pre1
1.4.5
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
1.3.2
patch
Dependencies (7)
Changelog
Compare changes
|
|
1.3.1
patch
1 CVE
CVE-2026-54522
GHSA-4mrv-5p47-p938
Jul 30, 2026
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
Low
Local
Low
None
None
Summary
Details
PoCSingle self-contained script (builds msgpack from rubygems with AddressSanitizer, then runs the PoC):
Expected output:
ImpactSame-process cross-buffer information disclosure and corruption: after CreditPranjali Thakur - depthfirst (depthfirst.com) Affected versions
0.0.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
+ 81 more Show less
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0pre1
0.6.1
0.6.2
0.7.0
0.7.0dev1
0.7.1
0.7.2
0.7.2dev1
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.0.pre1
1.4.1
1.4.2
1.4.3
1.4.4
1.4.4.pre1
1.4.5
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.3.0
minor
1 CVE
CVE-2026-54522
GHSA-4mrv-5p47-p938
Jul 30, 2026
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
Low
Local
Low
None
None
Summary
Details
PoCSingle self-contained script (builds msgpack from rubygems with AddressSanitizer, then runs the PoC):
Expected output:
ImpactSame-process cross-buffer information disclosure and corruption: after CreditPranjali Thakur - depthfirst (depthfirst.com) Affected versions
0.0.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
+ 81 more Show less
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0pre1
0.6.1
0.6.2
0.7.0
0.7.0dev1
0.7.1
0.7.2
0.7.2dev1
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.0.pre1
1.4.1
1.4.2
1.4.3
1.4.4
1.4.4.pre1
1.4.5
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
1.3.0
minor
Dependencies (7)
Changelog
Compare changes
|
|
1.2.10
patch
1 CVE
CVE-2026-54522
GHSA-4mrv-5p47-p938
Jul 30, 2026
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
Low
Local
Low
None
None
Summary
Details
PoCSingle self-contained script (builds msgpack from rubygems with AddressSanitizer, then runs the PoC):
Expected output:
ImpactSame-process cross-buffer information disclosure and corruption: after CreditPranjali Thakur - depthfirst (depthfirst.com) Affected versions
0.0.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
+ 81 more Show less
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0pre1
0.6.1
0.6.2
0.7.0
0.7.0dev1
0.7.1
0.7.2
0.7.2dev1
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.0.pre1
1.4.1
1.4.2
1.4.3
1.4.4
1.4.4.pre1
1.4.5
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.2.9
patch
1 CVE
CVE-2026-54522
GHSA-4mrv-5p47-p938
Jul 30, 2026
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
Low
Local
Low
None
None
Summary
Details
PoCSingle self-contained script (builds msgpack from rubygems with AddressSanitizer, then runs the PoC):
Expected output:
ImpactSame-process cross-buffer information disclosure and corruption: after CreditPranjali Thakur - depthfirst (depthfirst.com) Affected versions
0.0.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
+ 81 more Show less
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0pre1
0.6.1
0.6.2
0.7.0
0.7.0dev1
0.7.1
0.7.2
0.7.2dev1
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.0.pre1
1.4.1
1.4.2
1.4.3
1.4.4
1.4.4.pre1
1.4.5
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
1.2.9
patch
Dependencies (7)
Changelog
Compare changes
|
|
1.2.8
patch
1 CVE
CVE-2026-54522
GHSA-4mrv-5p47-p938
Jul 30, 2026
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
Low
Local
Low
None
None
Summary
Details
PoCSingle self-contained script (builds msgpack from rubygems with AddressSanitizer, then runs the PoC):
Expected output:
ImpactSame-process cross-buffer information disclosure and corruption: after CreditPranjali Thakur - depthfirst (depthfirst.com) Affected versions
0.0.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
+ 81 more Show less
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0pre1
0.6.1
0.6.2
0.7.0
0.7.0dev1
0.7.1
0.7.2
0.7.2dev1
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.0.pre1
1.4.1
1.4.2
1.4.3
1.4.4
1.4.4.pre1
1.4.5
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.2.7
patch
1 CVE
CVE-2026-54522
GHSA-4mrv-5p47-p938
Jul 30, 2026
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
Low
Local
Low
None
None
Summary
Details
PoCSingle self-contained script (builds msgpack from rubygems with AddressSanitizer, then runs the PoC):
Expected output:
ImpactSame-process cross-buffer information disclosure and corruption: after CreditPranjali Thakur - depthfirst (depthfirst.com) Affected versions
0.0.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
+ 81 more Show less
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0pre1
0.6.1
0.6.2
0.7.0
0.7.0dev1
0.7.1
0.7.2
0.7.2dev1
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.0.pre1
1.4.1
1.4.2
1.4.3
1.4.4
1.4.4.pre1
1.4.5
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
1.2.7
patch
Dependencies (7)
Changelog
Compare changes
|
|
1.2.6
patch
1 CVE
CVE-2026-54522
GHSA-4mrv-5p47-p938
Jul 30, 2026
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
Low
Local
Low
None
None
Summary
Details
PoCSingle self-contained script (builds msgpack from rubygems with AddressSanitizer, then runs the PoC):
Expected output:
ImpactSame-process cross-buffer information disclosure and corruption: after CreditPranjali Thakur - depthfirst (depthfirst.com) Affected versions
0.0.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
+ 81 more Show less
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0pre1
0.6.1
0.6.2
0.7.0
0.7.0dev1
0.7.1
0.7.2
0.7.2dev1
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.0.pre1
1.4.1
1.4.2
1.4.3
1.4.4
1.4.4.pre1
1.4.5
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.2.5
patch
1 CVE
CVE-2026-54522
GHSA-4mrv-5p47-p938
Jul 30, 2026
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
Low
Local
Low
None
None
Summary
Details
PoCSingle self-contained script (builds msgpack from rubygems with AddressSanitizer, then runs the PoC):
Expected output:
ImpactSame-process cross-buffer information disclosure and corruption: after CreditPranjali Thakur - depthfirst (depthfirst.com) Affected versions
0.0.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
+ 81 more Show less
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0pre1
0.6.1
0.6.2
0.7.0
0.7.0dev1
0.7.1
0.7.2
0.7.2dev1
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.0.pre1
1.4.1
1.4.2
1.4.3
1.4.4
1.4.4.pre1
1.4.5
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.2.4
patch
1 CVE
CVE-2026-54522
GHSA-4mrv-5p47-p938
Jul 30, 2026
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
Low
Local
Low
None
None
Summary
Details
PoCSingle self-contained script (builds msgpack from rubygems with AddressSanitizer, then runs the PoC):
Expected output:
ImpactSame-process cross-buffer information disclosure and corruption: after CreditPranjali Thakur - depthfirst (depthfirst.com) Affected versions
0.0.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
+ 81 more Show less
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0pre1
0.6.1
0.6.2
0.7.0
0.7.0dev1
0.7.1
0.7.2
0.7.2dev1
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.0.pre1
1.4.1
1.4.2
1.4.3
1.4.4
1.4.4.pre1
1.4.5
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.2.3
patch
1 CVE
CVE-2026-54522
GHSA-4mrv-5p47-p938
Jul 30, 2026
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
Low
Local
Low
None
None
Summary
Details
PoCSingle self-contained script (builds msgpack from rubygems with AddressSanitizer, then runs the PoC):
Expected output:
ImpactSame-process cross-buffer information disclosure and corruption: after CreditPranjali Thakur - depthfirst (depthfirst.com) Affected versions
0.0.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
+ 81 more Show less
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0pre1
0.6.1
0.6.2
0.7.0
0.7.0dev1
0.7.1
0.7.2
0.7.2dev1
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.0.pre1
1.4.1
1.4.2
1.4.3
1.4.4
1.4.4.pre1
1.4.5
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.2.2
patch
1 CVE
CVE-2026-54522
GHSA-4mrv-5p47-p938
Jul 30, 2026
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
Low
Local
Low
None
None
Summary
Details
PoCSingle self-contained script (builds msgpack from rubygems with AddressSanitizer, then runs the PoC):
Expected output:
ImpactSame-process cross-buffer information disclosure and corruption: after CreditPranjali Thakur - depthfirst (depthfirst.com) Affected versions
0.0.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
+ 81 more Show less
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0pre1
0.6.1
0.6.2
0.7.0
0.7.0dev1
0.7.1
0.7.2
0.7.2dev1
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.0.pre1
1.4.1
1.4.2
1.4.3
1.4.4
1.4.4.pre1
1.4.5
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.2.1
patch
1 CVE
CVE-2026-54522
GHSA-4mrv-5p47-p938
Jul 30, 2026
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
Low
Local
Low
None
None
Summary
Details
PoCSingle self-contained script (builds msgpack from rubygems with AddressSanitizer, then runs the PoC):
Expected output:
ImpactSame-process cross-buffer information disclosure and corruption: after CreditPranjali Thakur - depthfirst (depthfirst.com) Affected versions
0.0.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
+ 81 more Show less
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0pre1
0.6.1
0.6.2
0.7.0
0.7.0dev1
0.7.1
0.7.2
0.7.2dev1
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.0.pre1
1.4.1
1.4.2
1.4.3
1.4.4
1.4.4.pre1
1.4.5
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.2.0
minor
1 CVE
CVE-2026-54522
GHSA-4mrv-5p47-p938
Jul 30, 2026
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
Low
Local
Low
None
None
Summary
Details
PoCSingle self-contained script (builds msgpack from rubygems with AddressSanitizer, then runs the PoC):
Expected output:
ImpactSame-process cross-buffer information disclosure and corruption: after CreditPranjali Thakur - depthfirst (depthfirst.com) Affected versions
0.0.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
+ 81 more Show less
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0pre1
0.6.1
0.6.2
0.7.0
0.7.0dev1
0.7.1
0.7.2
0.7.2dev1
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.0.pre1
1.4.1
1.4.2
1.4.3
1.4.4
1.4.4.pre1
1.4.5
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.1.0
minor
1 CVE
CVE-2026-54522
GHSA-4mrv-5p47-p938
Jul 30, 2026
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
Low
Local
Low
None
None
Summary
Details
PoCSingle self-contained script (builds msgpack from rubygems with AddressSanitizer, then runs the PoC):
Expected output:
ImpactSame-process cross-buffer information disclosure and corruption: after CreditPranjali Thakur - depthfirst (depthfirst.com) Affected versions
0.0.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
+ 81 more Show less
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0pre1
0.6.1
0.6.2
0.7.0
0.7.0dev1
0.7.1
0.7.2
0.7.2dev1
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.0.pre1
1.4.1
1.4.2
1.4.3
1.4.4
1.4.4.pre1
1.4.5
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.0.3
patch
1 CVE
CVE-2026-54522
GHSA-4mrv-5p47-p938
Jul 30, 2026
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
Low
Local
Low
None
None
Summary
Details
PoCSingle self-contained script (builds msgpack from rubygems with AddressSanitizer, then runs the PoC):
Expected output:
ImpactSame-process cross-buffer information disclosure and corruption: after CreditPranjali Thakur - depthfirst (depthfirst.com) Affected versions
0.0.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
+ 81 more Show less
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0pre1
0.6.1
0.6.2
0.7.0
0.7.0dev1
0.7.1
0.7.2
0.7.2dev1
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.0.pre1
1.4.1
1.4.2
1.4.3
1.4.4
1.4.4.pre1
1.4.5
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
1.0.3
patch
Dependencies (7)
Changelog
Compare changes
|
|
1.0.1
patch
1 CVE
CVE-2026-54522
GHSA-4mrv-5p47-p938
Jul 30, 2026
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
Low
Local
Low
None
None
Summary
Details
PoCSingle self-contained script (builds msgpack from rubygems with AddressSanitizer, then runs the PoC):
Expected output:
ImpactSame-process cross-buffer information disclosure and corruption: after CreditPranjali Thakur - depthfirst (depthfirst.com) Affected versions
0.0.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
+ 81 more Show less
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0pre1
0.6.1
0.6.2
0.7.0
0.7.0dev1
0.7.1
0.7.2
0.7.2dev1
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.0.pre1
1.4.1
1.4.2
1.4.3
1.4.4
1.4.4.pre1
1.4.5
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.0.2
patch
1 CVE
CVE-2026-54522
GHSA-4mrv-5p47-p938
Jul 30, 2026
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
Low
Local
Low
None
None
Summary
Details
PoCSingle self-contained script (builds msgpack from rubygems with AddressSanitizer, then runs the PoC):
Expected output:
ImpactSame-process cross-buffer information disclosure and corruption: after CreditPranjali Thakur - depthfirst (depthfirst.com) Affected versions
0.0.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
+ 81 more Show less
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0pre1
0.6.1
0.6.2
0.7.0
0.7.0dev1
0.7.1
0.7.2
0.7.2dev1
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.0.pre1
1.4.1
1.4.2
1.4.3
1.4.4
1.4.4.pre1
1.4.5
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.0.0
major
1 CVE
CVE-2026-54522
GHSA-4mrv-5p47-p938
Jul 30, 2026
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
Low
Local
Low
None
None
Summary
Details
PoCSingle self-contained script (builds msgpack from rubygems with AddressSanitizer, then runs the PoC):
Expected output:
ImpactSame-process cross-buffer information disclosure and corruption: after CreditPranjali Thakur - depthfirst (depthfirst.com) Affected versions
0.0.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
+ 81 more Show less
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0pre1
0.6.1
0.6.2
0.7.0
0.7.0dev1
0.7.1
0.7.2
0.7.2dev1
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.0.pre1
1.4.1
1.4.2
1.4.3
1.4.4
1.4.4.pre1
1.4.5
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.7.6
patch
1 CVE
CVE-2026-54522
GHSA-4mrv-5p47-p938
Jul 30, 2026
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
Low
Local
Low
None
None
Summary
Details
PoCSingle self-contained script (builds msgpack from rubygems with AddressSanitizer, then runs the PoC):
Expected output:
ImpactSame-process cross-buffer information disclosure and corruption: after CreditPranjali Thakur - depthfirst (depthfirst.com) Affected versions
0.0.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
+ 81 more Show less
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0pre1
0.6.1
0.6.2
0.7.0
0.7.0dev1
0.7.1
0.7.2
0.7.2dev1
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.0.pre1
1.4.1
1.4.2
1.4.3
1.4.4
1.4.4.pre1
1.4.5
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Sep 10, 2026 · Source: OSV.dev |