Skip to content

Update MessagePack dependency to 3.1.7 or later #157

Description

@iplaylf2

Hi, MessagePipe.Interprocess 1.8.2 currently depends on MessagePack >= 3.1.4.

GitHub Advisory Database now reports GHSA-hv8m-jj95-wg3x / CVE-2026-48109 as a high-severity vulnerability affecting MessagePack v3 versions before 3.1.7. MessagePack 3.1.7 is listed as the patched v3 release.

Could you please update the MessagePack dependency to 3.1.7 or later and publish a new MessagePipe release?

This would help downstream projects keep NuGet audit enabled without suppressing NU1903.

References:

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions