Deserializing attacker-controlled bytes with bincode/rmp without validation is risky.
Validate and bound input, and prefer self-describing formats with strict schemas.