Skip to content

The referenced MessagePack has a known vulnerability #58532

@davesmits

Description

@davesmits

In

<MessagePackVersion>2.5.108</MessagePackVersion>
the reference to MessagePack is a version (2.5.108) with a known vulnerability https://osv.dev/vulnerability/GHSA-4qm4-8hg2-g2xm

I noticed the .NET 9RC2 still links this package with vulnerability. Is the reference going to be updated to version where this is fixed? (>=
2.5.187)?

Metadata

Metadata

Assignees

Labels

area-infrastructureIncludes: MSBuild projects/targets, build scripts, CI, Installers and shared framework

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions