OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-88351

CRITICAL · CVSS 9.8 EPSS 0.31% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-24 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The vulnerability affects the MPack Node API in version 1.1.1 on 32-bit platforms, where an integer overflow can occur during the parsing of specially crafted MessagePack objects with large element counts. This flaw leads to heap buffer overflows and memory corruption, potentially resulting in denial of service. Organizations using this API, particularly those on 32-bit systems, should prioritize remediation to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-88351
Severity
CRITICAL
CVSS
9.8
EPSS
0.31%

Original NVD Description

An integer overflow vulnerability exists in the MPack Node API in MPack 1.1.1 on 32-bit platforms. When parsing a specially crafted MessagePack array32 or map32 object with an excessively large element count, the page allocation size calculation in mpack_tree_parse_children() can overflow size_t and produce an undersized allocation. Subsequent parsing writes mpack_node_data_t records beyond the allocated heap buffer, resulting in heap-buffer-overflow, memory corruption, and denial of service.