Msgpack library usage discussion
Open
- Dominant language
- Go
- Stars
- 206
- Forks
- 140
- Avg merge
- 2h 44m
- Merged PRs (30d)
- 1
Description
I got notified about this vulnerability, it claims to allow potential denial of service attacks: https://github.com/advisories/GHSA-h9q6-hc68-35rp
As of now, I don't see a patched release in the msgpack repository, but I wanted to open a discussion here. Is JSON performing significantly worse for metrics?
It seems like the vulnerability could be executed only if VMMetrics are enabled through wasmd options on chain.
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.