Nerdbank.MessagePack has Inefficient CPU ComputationGHSA-92vj-hp7m-gwcj
MEDIUMFix: AArnott/Nerdbank.MessagePack@c5a239eGHSA-92vj-hp7m-gwcj is a medium-severity (CVSS 5.3) remote code execution vulnerability in Nerdbank.MessagePack. A fix is available for Nerdbank.MessagePack — see the affected versions and patch details below.
Real-World Exposure
Nerdbank.MessagePackReal-time download stats are indexed for npm and PyPI packages. This vulnerability affects NuGet packages — download data is not available via public APIs for these ecosystems.
Description
Impact
Applications that call OptionalConverters.WithExpandoObjectConverter and deserialize untrusted data are open to a vulnerability by which an attacker can exploit a O(n²) algorithm to burn an inordinate amount of CPU effort by adding a great many properties to an ExpandoObject, whose Add method is implemented as an O(n) algorithm.
Patches
Update to a patched version.
If a project's ExpandoObject data requires more than 128 properties, the default limit should be changed:
this.Serializer = this.Serializer with
{
StartingContext = this.Serializer.StartingContext with
{
Security = this.Serializer.StartingContext.Security with
{
ExpandoObjectMaxPropertyCount = 256, // Set this to whatever limit is required by your application
},
},
};
Workarounds
Avoid the non-default WithExpandoObjectConverter extension method when deserializing untrusted data.
If deserializing untrusted data into an ExpandoObject is required, developers should write a custom converter for their project that limits the number of properties allowed before initializing the object.
Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| .NETNuGet | Nerdbank.MessagePack | all versions | 1.2.4dotnet add package Nerdbank.MessagePack --version 1.2.4 |
Detection & mitigation playbook
Open-source dependencyDetect
Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for Nerdbank.MessagePack, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.
Fix
Update Nerdbank.MessagePack to 1.2.4 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms GHSA-92vj-hp7m-gwcj is resolved across your whole dependency graph.
Workarounds
Do not deserialise data from untrusted sources: where the format allows it, restrict deserialisation to an explicit allowlist of expected types, and prefer a data-only format (JSON, Protobuf) over one that can reconstruct arbitrary objects until you can upgrade.
Frequently Asked Questions
Is GHSA-92vj-hp7m-gwcj in your dependencies?
Find it across NuGet, including transitive dependencies.