{"id":"GHSA-mx67-wv8x-hvv9","summary":"Deserialization of Untrusted Data in msgpack","details":"# Withdrawn\n\nThis advisory was withdrawn by its CNA (Snyk).\n\n## Original advisory\n\nAll versions of package `msgpack` are vulnerable to Deserialization of Untrusted Data via the unpack function. This does not affect the similarly named package `@msgpack/msgpack`.","aliases":["CVE-2021-23410"],"modified":"2026-09-10T03:49:15.474350400Z","published":"2021-07-26T21:24:09Z","withdrawn":"2021-09-15T19:12:25Z","database_specific":{"nvd_published_at":"2021-07-21T17:15:00Z","cwe_ids":["CWE-502"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2021-07-26T17:38:45Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-23410"},{"type":"WEB","url":"https://github.com/msgpack/msgpack-node"},{"type":"WEB","url":"https://github.com/msgpack/msgpack-node/blob/master/src/msgpack.cc%23L302-L335"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JS-MSGPACK-1296122"}],"affected":[{"package":{"name":"msgpack","ecosystem":"npm","purl":"pkg:npm/msgpack"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"1.0.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/07/GHSA-mx67-wv8x-hvv9/GHSA-mx67-wv8x-hvv9.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}