{"id":"CVE-2026-48511","aliases":["GHSA-2x83-8g95-xh59"],"url":"https://o3.security/vulnerability/CVE-2026-48511","summary":"MessagePack-CSharp: ExpandoObject formatter can perform quadratic insertion work on untrusted maps","details":"MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, ExpandoObjectFormatter.Deserialize populates System.Dynamic.ExpandoObject by calling IDictionary<string, object>.Add for each map entry. ExpandoObject internally maintains member names in array-like structures, so inserting many distinct keys can require repeated linear scans and array copies. For large attacker-controlled maps, this produces quadratic CPU and allocation behavior. The issue is especially surprising because ExpandoObjectResolver.Options is configured with MessagePackSecurity.UntrustedData, but collision-resistant dictionary comparers cannot protect ExpandoObject insertion internals. This vulnerability is fixed in 2.5.301 and 3.1.7.","published":"2026-06-22T21:14:54.127Z","modified":"2026-07-15T01:48:58.130788748Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"NuGet","name":"MessagePack","fixedVersion":"2.5.301"},{"ecosystem":"NuGet","name":"MessagePack","fixedVersion":"3.1.7"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/48xxx/CVE-2026-48511.json"},{"type":"ADVISORY","url":"https://github.com/MessagePack-CSharp/MessagePack-CSharp/security/advisories/GHSA-2x83-8g95-xh59"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48511"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:48:58.130788748Z"}}