Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 25 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-190 | |
| Metrics |
cvssV3_1
|
Fri, 25 Sep 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ludocode
Ludocode mpack |
|
| Vendors & Products |
Ludocode
Ludocode mpack |
Thu, 24 Sep 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An integer overflow vulnerability exists in the MPack Node API in MPack 1.1.1 on 32-bit platforms. When parsing a specially crafted MessagePack array32 or map32 object with an excessively large element count, the page allocation size calculation in mpack_tree_parse_children() can overflow size_t and produce an undersized allocation. Subsequent parsing writes mpack_node_data_t records beyond the allocated heap buffer, resulting in heap-buffer-overflow, memory corruption, and denial of service. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-09-25T18:09:28.514Z
Reserved: 2026-09-10T00:00:00.000Z
Link: CVE-2026-88351
No data.
Status : Deferred
Published: 2026-09-24T15:17:50.423
Modified: 2026-09-25T18:17:31.257
Link: CVE-2026-88351
No data.
OpenCVE Enrichment
Updated: 2026-09-25T06:00:12Z