Description
msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, decoding a negative signed 64-bit integer modifies the corresponding bytes in the caller-provided input buffer while computing the value. Applications that retain or reuse encoded input for integrity checks, logging, or later processing can observe silently corrupted data, while positive integers and other MessagePack value types are unaffected. This issue is fixed in version 6.1.0.
Published: 2026-10-08
Score: 3.7 Low
EPSS: n/a
KEV: No
Impact: Silent data corruption
Action: Update
AI Analysis

Impact

msgpack5 decodes negative signed 64-bit integers by modifying the caller’s input buffer while computing the value. As a result, any data that contains such values becomes corrupted in the original buffer, which can silently break integrity checks, logging or subsequent processing. Positive integers and other data types are unaffected. The vulnerability is a data corruption flaw (CWE-471).

Affected Systems

The msgpack5 library, maintained by mcollina, is affected when used in Node.js or web browser environments. All released versions prior to 6.1.0 are vulnerable; version 6.1.0 and later contain the fix.

Risk and Exploitability

The CVSS score of 3.7 indicates low to moderate severity. No EPSS data is available and the vulnerability is not listed in CISA’s KEV catalog, suggesting a low current exploitation probability. The attack vector is likely same-user or local application code that feeds data to msgpack5, as the flaw requires the ability to supply arbitrary input containing negative int64 values. The impact is silent data corruption rather than denial of service or code execution, but for applications that rely on data integrity it can have significant operational consequences.

Generated by OpenCVE AI on October 8, 2026 at 18:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install msgpack5 version 6.1.0 or newer
  • If upgrading is not immediately possible, make a copy of any buffer to be decoded and pass the copy to msgpack5 to avoid mutating the original data
  • Audit existing code paths for usage of msgpack5 with negative int64 values and add validation or sanitization to reject such input where appropriate

Generated by OpenCVE AI on October 8, 2026 at 18:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-qw35-55vc-rhgj msgpack5: Decoding negative int64 values mutates the input buffer
History

Thu, 08 Oct 2026 17:15:00 +0000

Type Values Removed Values Added
Description msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, decoding a negative signed 64-bit integer modifies the corresponding bytes in the caller-provided input buffer while computing the value. Applications that retain or reuse encoded input for integrity checks, logging, or later processing can observe silently corrupted data, while positive integers and other MessagePack value types are unaffected. This issue is fixed in version 6.1.0.
Title msgpack5: Decoding negative int64 values mutates the input buffer
Weaknesses CWE-471
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-08T17:05:34.059Z

Reserved: 2026-10-07T15:53:23.587Z

Link: CVE-2026-107296

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-08T17:17:15.390

Modified: 2026-10-08T20:48:36.970

Link: CVE-2026-107296

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T18:45:17Z

Weaknesses
  • CWE-471

    Modification of Assumed-Immutable Data (MAID)