7.5
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Justification
Impact
The out-of-bounds read affects msgpack's compiled C extension unpacker, and the upstream fix in 1.2.1 is confined to those native sources. Only the pure-Python fallback implementation is vendored; the C extension is not shipped, so the vulnerable code is not present.
Status