OSV 1.4.0 · github-reviewed · 修改于 2026-06-26 03:36
发布时间
2026-06-26 03:36
GitHub 审查时间
2026-06-26 03:36
NVD 发布时间
2026-06-23 06:16
源文件
advisories/github-reviewed/2026/06/GHSA-2x83-8g95-xh59/GHSA-2x83-8g95-xh59.json
ExpandoObjectFormatter.Deserialize populates System.Dynamic.ExpandoObject by calling IDictionary<string, object>.Add for each map entry. ExpandoObject internally maintains member names in array-like structures, so inserting many distinct keys can require repeated linear scans and array copies.
For large attacker-controlled maps, this produces quadratic CPU and allocation behavior. The issue is especially surprising because ExpandoObjectResolver.Options is configured with MessagePackSecurity.UntrustedData, but collision-resistant dictionary comparers cannot protect ExpandoObject insertion internals.
Applications are affected when they deserialize untrusted MessagePack maps into ExpandoObject using ExpandoObjectResolver or related resolver options.
A hostile payload containing many distinct keys can cause CPU exhaustion and allocation churn disproportionate to the input size. This can make a server unresponsive or exhaust memory under concurrent request load.
This is not a hash-collision attack against a configurable dictionary comparer. The super-linear behavior comes from ExpandoObject's insertion model, so MessagePackSecurity.UntrustedData does not eliminate the cost.
MessagePackExpandoObjectFormatter.Deserialize, ExpandoObjectResolverSystem.Dynamic.ExpandoObjectMESSAGEPACKCSHARP-102Fixes are prepared and will be released in coordinated patch versions.
Upgrade guidance:
MessagePack to the patched version for your release line.Potential fixes include applying a map-entry count limit for ExpandoObject under untrusted-data settings, buffering into a security-aware dictionary before materializing a bounded , or otherwise rejecting maps large enough to trigger quadratic behavior.
ExpandoObjectPatching is recommended.
Until a patched version is available, avoid deserializing untrusted payloads into ExpandoObject. Prefer strongly typed DTOs or dictionaries with security-aware comparers and explicit count limits. Enforce request-size and map-entry limits at the transport or application layer.
MESSAGEPACKCSHARP-102: ExpandoObjectFormatter quadratic insertion behavior