LOWRubyGems →
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
Affected packages
- msgpack— before 1.8.2
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- 0.12%
- EPSS percentile
- 2.1%
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs. This advisory is in the top 2%.
Sources
- https://github.com/msgpack/msgpack-ruby/security/advisories/GHSA-4mrv-5p47-p938
- https://github.com/msgpack/msgpack-ruby/commit/5627d71606b565641d2dd501b82aae862f4abe90
- https://github.com/msgpack/msgpack-ruby
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/msgpack/CVE-2026-54522.yml
- https://www.cve.org/CVERecord/SearchResults?query=CVE-2026-54522
Structured record: https://osv.dev/vulnerability/GHSA-4mrv-5p47-p938
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta