Integer underflow in Sandstorm Cap'n Proto before 0.4.1.1 and 0.5.x before 0.5.1.1 might allow remote peers to cause a denial of service or possibly obtain sensitive information from memory or execute arbitrary code via a crafted message.
https://github.com/capnproto/capnproto/commit/26bcceda72372211063d62aab7e45665faa83633