Report IDs
- GO-2026-4513
- GO-2026-4740
Suggested edit
Please update the Go vulnerability database entries for shamaton/msgpack fixext DoS.
For GO-2026-4513:
- Add fixed version
2.4.1 for module github.com/shamaton/msgpack/v2.
- Add fixed version
3.1.1 for module github.com/shamaton/msgpack/v3.
- Keep module
github.com/shamaton/msgpack (v1) as no known fixed version, unless the Go team has contrary evidence.
- Add alias/reference
GHSA-h9q6-hc68-35rp, since GO-2026-4740 describes the same vulnerability from the GHSA source.
For GO-2026-4740:
- This appears to be a duplicate of GO-2026-4513. Please withdraw/exclude/merge it as appropriate, or apply the same fixed-version data if it must remain served.
Evidence
Current incorrect behavior
As of 2026-05-24, pkg.go.dev/vuln still shows all versions, no known fixed for v2 and v3 in both reports, which makes fixed consumers of github.com/shamaton/msgpack/v2@v2.4.1 and github.com/shamaton/msgpack/v3@v3.1.1 look vulnerable.
Thanks.
Report IDs
Suggested edit
Please update the Go vulnerability database entries for shamaton/msgpack fixext DoS.
For GO-2026-4513:
2.4.1for modulemygithub.libinneed.workers.dev/shamaton/msgpack/v2.3.1.1for modulemygithub.libinneed.workers.dev/shamaton/msgpack/v3.github.com/shamaton/msgpack(v1) as no known fixed version, unless the Go team has contrary evidence.GHSA-h9q6-hc68-35rp, since GO-2026-4740 describes the same vulnerability from the GHSA source.For GO-2026-4740:
Evidence
v3 fix PR: fix: validate ext frame bounds before byte-slice decode shamaton/msgpack#60
v2 fix release: https://github.com/shamaton/msgpack/releases/tag/v2.4.1
Original vuln report: x/vulndb: potential Go vuln in github.com/shamaton/msgpack #4513
Duplicate/generated GHSA report: x/vulndb: potential Go vuln in github.com/shamaton/msgpack/v3: GHSA-h9q6-hc68-35rp #4740
GHSA: GHSA-h9q6-hc68-35rp
Current incorrect behavior
As of 2026-05-24, pkg.go.dev/vuln still shows
all versions, no known fixedfor v2 and v3 in both reports, which makes fixed consumers ofmygithub.libinneed.workers.dev/shamaton/msgpack/v2@v2.4.1andmygithub.libinneed.workers.dev/shamaton/msgpack/v3@v3.1.1look vulnerable.Thanks.